Pith. sign in

REVIEW 1 cited by

Malware Classification with GMM-HMM Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2103.02753 v1 pith:WUFDF3AA submitted 2021-03-03 cs.CR cs.LGstat.ML

classification cs.CRcs.LGstat.ML
keywords discreteclassificationhmmsfeaturesgmm-hmmsmalwareresultsentropy-based
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Discrete hidden Markov models (HMM) are often applied to malware detection and classification problems. However, the continuous analog of discrete HMMs, that is, Gaussian mixture model-HMMs (GMM-HMM), are rarely considered in the field of cybersecurity. In this paper, we use GMM-HMMs for malware classification and we compare our results to those obtained using discrete HMMs. As features, we consider opcode sequences and entropy-based sequences. For our opcode features, GMM-HMMs produce results that are comparable to those obtained using discrete HMMs, whereas for our entropy-based features, GMM-HMMs generally improve significantly on the classification results that we have achieved with discrete HMMs.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Malware Classification using a Hybrid Hidden Markov Model-Convolutional Neural Network

    cs.LG 2024-12 conditional novelty 3.0 of 10

    Converting HMM hidden-state sequences into images and classifying them with a CNN yields 0.9781 accuracy on a 7-family Malicia subset, a 0.0023 gain over the authors' HMM-RF baseline.

Pith tools