[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-151512-en":3,"doc-seo-151512-105":31,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},151512,2336475104362,"Mali","https://ap-avatar.wpscdn.com/avatar/22000c4c46a41b752dd?x-image-process=image/resize,m_fixed,w_180,h_180&k=1786595829695023868",8,"Research & Report","Gotcha-Sly Malware! Scorpion - A Metagraph2vec Based Malware Detection System","Malware detection addresses long-standing and escalating threats to Internet and computing devices. The study models malware using both content- and relation-based features across multiple entity types (files, archives, machines, APIs, DLLs) and their semantic links (e.g., file-archive, file-machine, API-DLL, file-API). It builds a structural heterogeneous information network and introduces meta-graph representations. Using metagraph2vec, the method learns efficient low-dimensional node embeddings that preserve structure and semantics. Experiments on real Comodo Cloud Security Center samples show Scorpion outperforms alternative techniques and is integrated into Comodo Antivirus scanning.","Gotcha-Sly Malware!  \nScorpion: A Metagraph2vec Based Malware Detection System  \nYujie Fan, Shifu Hou  \nDepartment ofCSEE West Virginia Univerisity, WV, USA {yf0004, [shhou}@mix.wvu.edu](shhou}@mix.wvu.edu)  \nYiming Zhang, Yanfang Ye ∗ Department ofCSEE West Virginia Univerisity, WV, USA [yanfang.ye@mail.wvu.edu](yanfang.ye@mail.wvu.edu)  \nMelih Abdulhayoglu  \nComodo Security Solutions, Inc. Clifton, NJ, USA  \nmelih@comodo.com  \nABSTRACT  \nDue to its severe damages and threats to the security of the Internet and computing devices, malware detection has caught the attention of both anti-malware industry and researchers for decades. To combat the evolving malware attacks, in this paper, we first study how to utilize both content-and relation-based features to characterizesly malware; to model different types of entities (i.e., file, archive, machine, API, DLL) and the rich semantic relationships among them (i.e., file-archive, file-machine, file-file, API-DLL, file-API relations), we then construct a structural heterogeneous information network (HIN) and present meta-graph based approach to depict the relatedness over files. To measure the relatedness over files on the constructed HIN, since malware detection is a cost-sensitive task, it calls for efficient methods to learn latent representations for HIN. To address this challenge, based on the built meta-graph schemes, we propose a new HIN embedding model metagraph2vec on the first attempt to learn the low-dimensional representations for the nodes in HIN, where both the HIN structures and semantics are maximally preserved for malware detection. A comprehensive experimental study on the real sample collections from Comodo Cloud Security Center is performed to compare various malware detection approaches. The promising experimental results demonstrate that our developed system Scorpion which integrate our proposed method outperforms other alternative malware detection techniques. The developed system has already been incorporated into the scanning tool of Comodo Antivirus product.  \nCCS CONCEPTS  \n• Artifficial Intelligence → General; • Database applications → Data mining; • Security and Protection → Invasive Software;  \nKEYWORDS  \nMalware Detection; Heterogeneous Information Network; Network Embedding; Metagraph2vec.  \nACM Reference Format:  \nYujie Fan, Shifu Hou, Yiming Zhang, Yanfang Ye ∗ , and Melih Abdulhayoglu.  \n2018. Gotcha-Sly Malware! Scorpion: A Metagraph2vec Based Malware  \nPermission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions [from permissions@acm.org](from permissions@acm.org).  \nKDD’18, August 19–23, 2018, London, United Kingdom © 2018 Association for Computing Machinery.  \nACM ISBN 978-1-4503-5552-0/18/08. . . $15.00 [https://doi.org/10.1145/3219819.3219862](https://doi.org/10.1145/3219819.3219862)  \nDetection System. In KDD’18: The 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, August 19–23, 2018, London, United Kingdom. ACM, New York, NY, USA, 10 pages. [https://doi.org/10](https://doi.org/10) . 1145/3219819.3219862  \n1 INTRODUCTION  \nAs the Internet and computing devices become increasingly ubiquitous, their security has become more and more important. Malware (short for malicious software) is software designed to infiltrate or damage a computing system without the owner’s informed consent [40], such as viruses, worms, trojans, bots, and ransomware. Malware has been used as a major weapon by cybercriminals to launch a wide range of security at","cbCaiebUdKFhFdrR","https://ap.wps.com/l/cbCaiebUdKFhFdrR","pdf",5357008,2,1,10,"English","en",105,"# Introduction\n## Background and threat motivation\n## Limitations of signature-based and dynamic detection\n## Cloud-based intelligent malware detection","[{\"question\":\"What entities and relationships does the malware detection approach model?\",\"answer\":\"It models multiple entity types including files, archives, machines, APIs, and DLLs, and captures semantic relations such as file-archive, file-machine, file-file, API-DLL, and file-API links.\"},{\"question\":\"How does the paper build its representation for malware-related files?\",\"answer\":\"It constructs a structural heterogeneous information network (HIN) and uses a meta-graph based approach to depict relatedness over files.\"},{\"question\":\"What is metagraph2vec, and why is it suitable for malware detection?\",\"answer\":\"Metagraph2vec learns low-dimensional embeddings for HIN nodes while maximizing preservation of both HIN structure and semantics, supporting efficient learning for this cost-sensitive task.\"}]","Gotcha-Sly Malware! Scorpion - A Metagraph2vec Based Malware Detection System | PDF",1787841940,25,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":29},"gotcha-sly-malware-scorpion-a-metagraph2vec-based-malware-detection-system","",{"@graph":37,"@context":86},[38,54,69],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,48,51],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":20},"https://docshare.wps.com/document/","Document",{"item":49,"name":12,"@type":44,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":44,"position":53},"https://docshare.wps.com/document/gotcha-sly-malware-scorpion-a-metagraph2vec-based-malware-detection-system/151512/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":42,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-09-05","2026-08-27",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What entities and relationships does the malware detection approach model?","Question",{"text":76,"@type":77},"It models multiple entity types including files, archives, machines, APIs, and DLLs, and captures semantic relations such as file-archive, file-machine, file-file, API-DLL, and file-API links.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the paper build its representation for malware-related files?",{"text":81,"@type":77},"It constructs a structural heterogeneous information network (HIN) and uses a meta-graph based approach to depict relatedness over files.",{"name":83,"@type":74,"acceptedAnswer":84},"What is metagraph2vec, and why is it suitable for malware detection?",{"text":85,"@type":77},"Metagraph2vec learns low-dimensional embeddings for HIN nodes while maximizing preservation of both HIN structure and semantics, supporting efficient learning for this cost-sensitive task.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,135],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":47,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":47,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":47,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":47,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":22,"doc_module":4,"doc_module_name":47,"category_name":133,"show_sort_weight":22,"slug":134},"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":47,"category_name":137,"show_sort_weight":107,"slug":138},19,"General","general"]