Next Article in Journal
M-Polynomial and Degree Based Topological Indices of Some Nanostructures
Next Article in Special Issue
Symmetry-Adapted Machine Learning for Information Security
Previous Article in Journal
A Parametric Study of Trailing Edge Flap Implementation on Three Different Airfoils Through an Artificial Neuronal Network
Previous Article in Special Issue
Hierarchical Intrusion Detection Using Machine Learning and Knowledge Model
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Malware Classification Using Simhash Encoding and PCA (MCSP)

1
Department of Medical IT, Eulji University, Seongnam 13135, Korea
2
School of Software, Soongsil University, Seoul 06978, Korea
*
Authors to whom correspondence should be addressed.
Symmetry 2020, 12(5), 830; https://doi.org/10.3390/sym12050830
Submission received: 25 March 2020 / Revised: 17 April 2020 / Accepted: 1 May 2020 / Published: 19 May 2020
(This article belongs to the Special Issue Symmetry-Adapted Machine Learning for Information Security)

Abstract

Malware is any malicious program that can attack the security of other computer systems for various purposes. The threat of malware has significantly increased in recent years. To protect our computer systems, we need to analyze an executable file to decide whether it is malicious or not. In this paper, we propose two malware classification methods: malware classification using Simhash and PCA (MCSP), and malware classification using Simhash and linear transform (MCSLT). PCA uses the symmetrical covariance matrix. The former method combines Simhash encoding and PCA, and the latter combines Simhash encoding and linear transform layer. To verify the performance of our methods, we compared them with basic malware classification using Simhash and CNN (MCSC) using tanh and relu activation. We used a highly imbalanced dataset with 10,736 samples. As a result, our MCSP method showed the best performance with a maximum accuracy of 98.74% and an average accuracy of 98.59%. It showed an average F1 score of 99.2%. In addition, the MCSLT method showed better performance than MCSC in accuracy and F1 score.
Keywords: malware detection; deep learning; CNN; PCA; dimension reduction; linear transform; Simhash encoding; LSH; symmetrical covariance matrix malware detection; deep learning; CNN; PCA; dimension reduction; linear transform; Simhash encoding; LSH; symmetrical covariance matrix
Graphical Abstract

Share and Cite

MDPI and ACS Style

Kwon, Y.-M.; An, J.-J.; Lim, M.-J.; Cho, S.; Gal, W.-M. Malware Classification Using Simhash Encoding and PCA (MCSP). Symmetry 2020, 12, 830. https://doi.org/10.3390/sym12050830

AMA Style

Kwon Y-M, An J-J, Lim M-J, Cho S, Gal W-M. Malware Classification Using Simhash Encoding and PCA (MCSP). Symmetry. 2020; 12(5):830. https://doi.org/10.3390/sym12050830

Chicago/Turabian Style

Kwon, Young-Man, Jae-Ju An, Myung-Jae Lim, Seongsoo Cho, and Won-Mo Gal. 2020. "Malware Classification Using Simhash Encoding and PCA (MCSP)" Symmetry 12, no. 5: 830. https://doi.org/10.3390/sym12050830

APA Style

Kwon, Y.-M., An, J.-J., Lim, M.-J., Cho, S., & Gal, W.-M. (2020). Malware Classification Using Simhash Encoding and PCA (MCSP). Symmetry, 12(5), 830. https://doi.org/10.3390/sym12050830

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop