Analysis of Machine Learning Approaches to Packing Detection

Packing is an obfuscation technique widely used by malware to hide the content and behavior of a program. Much prior research has explored how to detect whether a program is packed. This research includes a broad variety of approaches such as entropy analysis, syntactic signatures and more recently machine learning classifiers using various features. However, no robust results have indicated which algorithms perform best, or which features are most significant. This is complicated by considering how to evaluate the results since accuracy, cost, generalization capabilities, and other measures are all reasonable. This work explores eleven different machine learning approaches using 119 features to understand: which features are most significant for packing detection; which algorithms offer the best performance; and which algorithms are most economical.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/18/2023

Experimental Toolkit for Manipulating Executable Packing

Be it for a malicious or legitimate purpose, packing, a transformation t...
research
05/25/2020

Malware Detection at the Microarchitecture Level using Machine Learning Techniques

Detection of malware cyber-attacks at the processor microarchitecture le...
research
05/18/2021

Online bin packing of squares and cubes

In the d-dimensional online bin packing problem, d-dimensional cubes of ...
research
11/03/2021

A Survey of Machine Learning Algorithms for Detecting Malware in IoT Firmware

This work explores the use of machine learning techniques on an Internet...
research
08/17/2022

An Efficient Multi-Step Framework for Malware Packing Identification

Malware developers use combinations of techniques such as compression, e...
research
02/18/2022

Predicting Sex and Stroke Success – Computer-aided Player Grunt Analysis in Tennis Matches

Professional athletes increasingly use automated analysis of meta- and s...

Please sign up or login with your details

Forgot password? Click here to reset