Converting HMM hidden-state sequences into images and classifying them with a CNN yields 0.9781 accuracy on a 7-family Malicia subset, a 0.0023 gain over the authors' HMM-RF baseline.
Malware Classification with GMM-HMM Models
1 Pith paper cite this work. Polarity classification is still indexing.
abstract
Discrete hidden Markov models (HMM) are often applied to malware detection and classification problems. However, the continuous analog of discrete HMMs, that is, Gaussian mixture model-HMMs (GMM-HMM), are rarely considered in the field of cybersecurity. In this paper, we use GMM-HMMs for malware classification and we compare our results to those obtained using discrete HMMs. As features, we consider opcode sequences and entropy-based sequences. For our opcode features, GMM-HMMs produce results that are comparable to those obtained using discrete HMMs, whereas for our entropy-based features, GMM-HMMs generally improve significantly on the classification results that we have achieved with discrete HMMs.
citation-role summary
citation-polarity summary
fields
cs.LG 1years
2024 1verdicts
CONDITIONAL 1roles
background 1polarities
background 1representative citing papers
citing papers explorer
-
Malware Classification using a Hybrid Hidden Markov Model-Convolutional Neural Network
Converting HMM hidden-state sequences into images and classifying them with a CNN yields 0.9781 accuracy on a 7-family Malicia subset, a 0.0023 gain over the authors' HMM-RF baseline.