Nonnegative matrix factorization and metamorphic malware detection

Metamorphic malware change their internal code structure by adopting code obfuscation technique while maintaining their malicious functionality during each infection. This causes change of their signature pattern across each infection and makes signature based detection particularly difficult. In th...

Full description

Bibliographic Details
Main Authors: Ling, Yeong Tyng, Mohd Sani, Nor Fazlida, Abdullah, Mohd Taufik, Abdul Hamid, Nor Asilah Wati
Format: Article
Language:English
Published: Springer Nature Switzerland AG 2019
Online Access:http://psasir.upm.edu.my/id/eprint/81487/
http://psasir.upm.edu.my/id/eprint/81487/1/Nonnegative%20matrix%20factorization%20and%20metamorphic%20malware%20detection.pdf
_version_ 1848859115857641472
author Ling, Yeong Tyng
Mohd Sani, Nor Fazlida
Abdullah, Mohd Taufik
Abdul Hamid, Nor Asilah Wati
author_facet Ling, Yeong Tyng
Mohd Sani, Nor Fazlida
Abdullah, Mohd Taufik
Abdul Hamid, Nor Asilah Wati
author_sort Ling, Yeong Tyng
building UPM Institutional Repository
collection Online Access
description Metamorphic malware change their internal code structure by adopting code obfuscation technique while maintaining their malicious functionality during each infection. This causes change of their signature pattern across each infection and makes signature based detection particularly difficult. In this paper, through static analysis, we use similarity score from matrix factorization technique called Nonnegative Matrix Factorization for detecting challenging metamorphic malware. We apply this technique using structural compression ratio and entropy features and compare our results with previous eigenvector-based techniques. Experimental results from three malware datasets show this is a promising technique as the accuracy detection is more than 95%.
first_indexed 2025-11-15T12:24:13Z
format Article
id upm-81487
institution Universiti Putra Malaysia
institution_category Local University
language English
last_indexed 2025-11-15T12:24:13Z
publishDate 2019
publisher Springer Nature Switzerland AG
recordtype eprints
repository_type Digital Repository
spelling upm-814872021-01-29T10:08:37Z http://psasir.upm.edu.my/id/eprint/81487/ Nonnegative matrix factorization and metamorphic malware detection Ling, Yeong Tyng Mohd Sani, Nor Fazlida Abdullah, Mohd Taufik Abdul Hamid, Nor Asilah Wati Metamorphic malware change their internal code structure by adopting code obfuscation technique while maintaining their malicious functionality during each infection. This causes change of their signature pattern across each infection and makes signature based detection particularly difficult. In this paper, through static analysis, we use similarity score from matrix factorization technique called Nonnegative Matrix Factorization for detecting challenging metamorphic malware. We apply this technique using structural compression ratio and entropy features and compare our results with previous eigenvector-based techniques. Experimental results from three malware datasets show this is a promising technique as the accuracy detection is more than 95%. Springer Nature Switzerland AG 2019 Article PeerReviewed text en http://psasir.upm.edu.my/id/eprint/81487/1/Nonnegative%20matrix%20factorization%20and%20metamorphic%20malware%20detection.pdf Ling, Yeong Tyng and Mohd Sani, Nor Fazlida and Abdullah, Mohd Taufik and Abdul Hamid, Nor Asilah Wati (2019) Nonnegative matrix factorization and metamorphic malware detection. Journal of Computer Virology and Hacking Techniques, 15. pp. 195-208. ISSN 2274-2042; ESSN: 2263-8733 https://link.springer.com/article/10.1007/s11416-019-00331-0 10.1007/s11416-019-00331-0
spellingShingle Ling, Yeong Tyng
Mohd Sani, Nor Fazlida
Abdullah, Mohd Taufik
Abdul Hamid, Nor Asilah Wati
Nonnegative matrix factorization and metamorphic malware detection
title Nonnegative matrix factorization and metamorphic malware detection
title_full Nonnegative matrix factorization and metamorphic malware detection
title_fullStr Nonnegative matrix factorization and metamorphic malware detection
title_full_unstemmed Nonnegative matrix factorization and metamorphic malware detection
title_short Nonnegative matrix factorization and metamorphic malware detection
title_sort nonnegative matrix factorization and metamorphic malware detection
url http://psasir.upm.edu.my/id/eprint/81487/
http://psasir.upm.edu.my/id/eprint/81487/
http://psasir.upm.edu.my/id/eprint/81487/
http://psasir.upm.edu.my/id/eprint/81487/1/Nonnegative%20matrix%20factorization%20and%20metamorphic%20malware%20detection.pdf