[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-125308-en":3,"doc-seo-125308-105":30,"detail-sidebar-cat-0-en-105":95},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},125308,1374391974468,"Eden","https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0",8,"Research & Report","Malicious Game Client Detection Using Feature Extraction and Machine Learning - Master of Science Thesis","Minecraft’s popularity has attracted extensive third-party software development, but it has also become one of the most malware-infected gaming ecosystems. The thesis addresses limitations of traditional malware analysis caused by Minecraft’s client-specific nuances, including unique file types, varying code formats, and limited standardization in community-generated content. It evaluates Minecraft clients in Portable Executable and Java Archive formats, using feature correlation analysis plus machine-learning methods with both dynamic sandbox behavior and static file-based features. A dataset of 92 files achieved 77.8% classification for Portable Executable and 84.2% for Java Archive while maintaining high recall, offering a more adaptable framework for game-related malware research.","Brigham Young University  \nBYU ScholarsArchive  \nTheses and Dissertations  \n2023-11-20  \nMalicious Game Client Detection Using Feature Extraction and Machine Learning  \nSpencer J. Austad  \nBrigham Young University  \nFollow this and additional works at: [https://scholarsarchive.byu.edu/etd](https://scholarsarchive.byu.edu/etd)  \n Part of the Engineering Commons  \nBYU ScholarsArchive Citation  \nAustad, Spencer J., \"Malicious Game Client Detection Using Feature Extraction and Machine Learning\"(2023) . Theses and Dissertations. 10154.  \n[https://scholarsarchive.byu.edu/etd/10154](https://scholarsarchive.byu.edu/etd/10154)  \nThis Thesis is brought to you for free and open access by BYU ScholarsArchive. It has been accepted for inclusion in Theses and Dissertations by an authorized administrator of BYU ScholarsArchive. For more information, please [contact](contact ellen_amatangelo@byu.edu)[ ellen_amatangelo@byu.edu](contact ellen_amatangelo@byu.edu).  \nMalicious Game Client Detection Using Feature Extraction and Machine Learning  \nSpencer J. Austad  \nA thesis submitted to the faculty of Brigham Young University  \nin partial fulfillment of the requirements for the degree of  \nMaster of Science  \nJustin Giboney, Chair  \nDerek Hansen  \nAlbert Tay  \nDepartment of Electrical & Computer Engineering  \nBrigham Young University  \nCopyright © 2023 Spencer J. Austad  \nAll Rights Reserved  \nMalicious Game Client Detection Using Feature Extraction and Machine Learning  \nSpencer J. Austad  \nDepartment of Electrical & Computer Engineering Master of Science  \nAbstract  \nMinecraft, the world's best-selling video game, boasts a vast and vibrant community of users who actively develop third-party software for the game. However, it has also garnered notoriety as one of the most malware-infested gaming environments. This poses a unique challenge because Minecraft software has many community-specific nuances that make traditional malware analysis less effective. These differences include unique file types, differing code formats, and lack of standardization in user-generated content analysis. This research looks at Minecraft clients in the two most common formats: Portable Executable and Java Archive file formats. Feature correlation matrices showed that malware features are too complicated to analyze without advanced algorithms. The latest machine learning methods for malware analysis were employed to classify samples based on both behavioral features generated from running samples in a sandbox environment and static features through file-based analysis. A total sample set of 92 files was used and found that Portable Executable and Java Archive files have significantly different feature sets that are important for malware identification. This study was able to successfully classify 77.8% of all Portable Executable samples 84.2% of all Java Archive samples while maintaining high recall scores. This research, by shedding light on the intricacies of malware detection in Minecraft clients, provides a framework for a more nuanced and adaptable approach to game-related malware research.  \nKeywords: malware detection, cybersecurity, Minecraft, game mods, machine learning  \nAcknowledgments  \nI would like to express my sincere gratitude to my thesis chair, Dr. Justin Giboney, for his invaluable guidance, support, and unwavering commitment throughout this journey. I am also deeply thankful to my committee members for their insightful feedback and expertise. Additionally, I extend my appreciation to the Department of Electrical & Computer Engineering and the Information Systems Department for providing essential resources that facilitated the completion of this thesis.  \nTable of Contents  \nAbstract ............................................................................................................... iii  \nAcknowledgments............................................................................................. iv  \nTable of Contents ..................","cbCaisbSpnOS7Icf","https://ap.wps.com/l/cbCaisbSpnOS7Icf","pdf",2534750,1,67,"English","en",105,"# 1 Introduction\n# 2 Literature Review\n## 2.1 Defining Clients\n## 2.2 Malware in clients\n## 2.3 Cheat Detection\n## 2.4 Anomaly Detection\n## 2.5 Non-signature Malware Detection\n## 2.6 Behavioral Detection Summary\n## 2.7 Static Detection Summary\n# 3 Method\n## 3.1 STEP 1: Obtain Malware Samples\n## 3.2 STEP 2: Malware Sandbox\n## 3.3 STEP 3: Feature Extraction\n## 3.4 STEP 4: Data Analysis and Feature Selection\n# 4 Results","[{\"question\":\"Why is traditional malware analysis less effective for Minecraft clients?\",\"answer\":\"Minecraft clients include community-specific nuances such as unique file types, differing code formats, and limited standardization in user-generated content, reducing the effectiveness of conventional analysis approaches.\"},{\"question\":\"Which client formats are studied in this research?\",\"answer\":\"The study focuses on two common Minecraft client formats: Portable Executable (PE) and Java Archive (JAR).\"},{\"question\":\"How does the thesis perform malware classification?\",\"answer\":\"It combines dynamic behavioral features generated from sandbox execution with static, file-based features, then applies machine-learning methods for classification.\"},{\"question\":\"What classification performance is reported for the two formats?\",\"answer\":\"Using 92 samples, the model classified 77.8% of Portable Executable samples and 84.2% of Java Archive samples while maintaining high recall scores.\"}]","Malicious Game Client Detection Using Feature Extraction and Machine Learning - Master of Science Thesis | PDF",1785898090,169,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":90,"head_meta":92,"extra_data":94,"updated_unix":28},"malicious-game-client-detection-using-feature-extraction-and-machine-learning-master-of-science-thesis","",{"@graph":36,"@context":89},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/malicious-game-client-detection-using-feature-extraction-and-machine-learning-master-of-science-thesis/125308/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81,85],{"name":72,"@type":73,"acceptedAnswer":74},"Why is traditional malware analysis less effective for Minecraft clients?","Question",{"text":75,"@type":76},"Minecraft clients include community-specific nuances such as unique file types, differing code formats, and limited standardization in user-generated content, reducing the effectiveness of conventional analysis approaches.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Which client formats are studied in this research?",{"text":80,"@type":76},"The study focuses on two common Minecraft client formats: Portable Executable (PE) and Java Archive (JAR).",{"name":82,"@type":73,"acceptedAnswer":83},"How does the thesis perform malware classification?",{"text":84,"@type":76},"It combines dynamic behavioral features generated from sandbox execution with static, file-based features, then applies machine-learning methods for classification.",{"name":86,"@type":73,"acceptedAnswer":87},"What classification performance is reported for the two formats?",{"text":88,"@type":76},"Using 92 samples, the model classified 77.8% of Portable Executable samples and 84.2% of Java Archive samples while maintaining high recall scores.","https://schema.org",{"og:url":52,"og:type":91,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":93,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":96},[97,101,105,109,114,119,124,127,132,135,139],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":106,"show_sort_weight":107,"slug":108},"Exam",70,"exam",{"id":110,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},5,"Comic",60,"comic",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},6,"Technology",50,"technology",{"id":120,"doc_module":4,"doc_module_name":46,"category_name":121,"show_sort_weight":122,"slug":123},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":125,"slug":126},30,"research-report",{"id":128,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":130,"slug":131},9,"Religion & Spirituality",20,"religion-spirituality",{"id":130,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":130,"slug":134},"World Cup","world-cup",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":136,"slug":138},10,"Lifestyle","lifestyle",{"id":140,"doc_module":4,"doc_module_name":46,"category_name":141,"show_sort_weight":110,"slug":142},19,"General","general"]