On the Limitations of Fuzzy Hashing for Malware Similarity: An Analysis of Vulnerable Code Detection in Malware
Nathan Ross, Oluwafemi Olukoya, Jesús Martínez del Rincón · 2025
As malware variants continue to increase, the risk of evading detection also grows. While fuzzy hashing has traditionally been successful at clustering malware samples based on their structural similarities, its potential as an active defense tool remains largely unexplored. This study investigates the application of fuzzy hashing for the static analysis of malware binaries to identify common vulnerabilities prevalent in malware, serving as a proactive security measure. We utilized a labeled dataset comprising real-world and synthetic Windows binaries to evaluate six fuzzy hashing algorithms for full binary classification and two for function-level matching. Our results indicate that, while fuzzy hashing is effective in simpler tasks such as malware classification and binary-level vulnerability detection, its performance decreases in more complex scenarios, including multi-class vulnerability identification and matching functions from real-world malware. Moreover, we observed a significant drop in performance, by up to 50%, when transitioning from synthetic to actual malware functions. These findings highlight both the potential and limitations of fuzzy hashing in vulnerability analysis, emphasizing the necessity for more robust techniques to detect vulnerable patterns in real-world malware.