[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118296-en":3,"doc-seo-118296-105":30,"detail-sidebar-cat-0-en-105":90},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118296,962084931830,"Theodore","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","Malware detection using opcodes and machine learning - HiPEAC 2024 - Preliminary results and models","Malware detection plays a critical role in modern digital systems by safeguarding sensitive information and maintaining the integrity of infrastructure under rapidly evolving cyber threats. Signature-based methods struggle with new or modified malware, including polymorphic and metamorphic variants, while machine learning offers stronger detection capability. This study uses opcodes as the main feature, performing both static and dynamic opcode-based analysis and proposing sequence and frequency datasets for model training and evaluation.","Malware detection using opcodes and machine learning  \nHiPEAC 2024-Munich  \nMartí Alonso; Andreu Gironès; David Andreu; Juan Jose Costa; Enric Morancho; Ramon Canal; Beatriz Otero; Stefano Di Carlo  \n{malonso, agirones, dandreu, jcosta, enricm, rcanal, [botero}@ac.upc.edu](botero}@ac.upc.edu); stefano.dicarlo@polito.it  \nAbstract  \nMalware detection plays and important role in modern digital systems . Protecting against the fast-paced evolving cyber attacks is critical to safeguard sensitive information and preserve the integrity of digital infrastructure .  \nTraditional signature-based detection methods are not effective when detecting new or altered versions of malware, such as polymorphic or metamorphic malware . Machine learning approaches have been proven to be much more effective at detecting such malware .  \nRuntime behavior can be captured using the most fundamental part of a program, its instructions, also referred as the opcodes. This study presents both static and dynamic analysis using opcodes as the main feature for machine learning models.  \nStatic analysis  \nStatic analysis consists of examining the characteristics of a program without executing the code.  \nFor this analysis, a dataset was generated consisting of the sequence of the opcodes for both benign and malware programs .  \nDynamic analysis  \nDynamic analysis consists of executing a program and obtain the executed instructions. For this analysis two datasets were generated:  \n• Sequence dataset:  \nFor each executed program, the sequence of the executed opcodes (up to 1 million instructions) was extracted.  \n• Frequency dataset:  \nSince gathering the executed sequence often results in very large samples with low information, an opcode frequency dataset was generated. For every 10000 executed instructions, the histogram of the opcodes executed is generated.  \nData collection  \nA comprehensive dataset is essential for training and evaluating machine learning models. Datasets were generated from a set of benign and malware programs . The benign programs were obtained from the /usr/bin folder of an Ubuntu 22.04.02. The malware programs were obtained from VirusShare, from a specific package containing only ELF files.  \nIn static analysis, the opcode sequence was extracted using the objdump tool. In dynamic analysis, the programs were executed in a safe and isolated environment using virtual machines with QEMU. Inside the virtual machine, another QEMU instance is run in user mode, which allows the capture of the executed opcodes sequence and frequency.  \nProposed models  \nFor the sequence-based datasets, for both static and dynamic analysis the following model is proposed:  \n• Word Embedding layer: using Word2Vec each opcode is transformed into a vector that is suitable for the deep learning model.  \n• LSTM/BiLSTM layers: these layers capture temporal dependencies in sequential data .  \n• Dense layer: to accomplish a binary classifier, the last layer is single-node softmax dense layer.  \nFor the dynamic frequency dataset, since each sample is represented by a simple feature vector, various classical models were tested such as Tree, KNN or SVM.  \nPreliminary results  \nInitial experiments show promising results in terms of detection accuracy. In static analysis, the model achieved a 98,3% accuracy after fine tunning the model parameters with hyperparameter optimization techniques. In dynamic analysis, the model for the sequence dataset achieved a 90% accuracy, while a weighted KNN model for the frequency dataset achieved a 97% accuracy.  \nSummary  \nThe development of robust, adaptive and effective security systems is critical for safeguarding digital systems .  \nMalware detection using opcodes and machine learning is and effective approach to malware detection and initial results prove it with great accuracy.  \nFunded by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Uni","cbCais3L1W5govpD","https://ap.wps.com/l/cbCais3L1W5govpD","pdf",756001,2,1,"English","en",105,"# Static analysis\n## Dataset construction\n# Dynamic analysis\n## Sequence dataset\n## Frequency dataset\n# Data collection and instrumentation\n## objdump and QEMU workflow\n# Proposed models\n## Word2Vec + LSTM/BiLSTM\n## Classical models for opcode frequency\n# Preliminary results\n## Accuracy highlights","[{\"question\":\"Why are traditional signature-based malware detection methods insufficient?\",\"answer\":\"They often fail to detect new or altered malware versions, including polymorphic and metamorphic families, where signatures change over time.\"},{\"question\":\"What are the main features used in this study for machine learning models?\",\"answer\":\"The study uses opcodes, captured either statically by examining program characteristics or dynamically by observing executed instructions at runtime.\"},{\"question\":\"How do the sequence and frequency datasets differ in dynamic analysis?\",\"answer\":\"The sequence dataset extracts the ordered executed opcodes up to a large instruction limit, while the frequency dataset summarizes opcode histograms over fixed instruction windows to reduce sample size and improve information density.\"}]","Malware detection using opcodes and machine learning - HiPEAC 2024 - Preliminary results and models | PDF",1785682862,3,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":85,"head_meta":87,"extra_data":89,"updated_unix":28},"malware-detection-using-opcodes-and-machine-learning-hipeac-2024-preliminary-results-and-models","",{"@graph":36,"@context":84},[37,52,67],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,49],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":29},"https://docshare.wps.com/document/research-report/",{"item":50,"name":13,"@type":43,"position":51},"https://docshare.wps.com/document/malware-detection-using-opcodes-and-machine-learning-hipeac-2024-preliminary-results-and-models/118296/",4,{"url":50,"name":13,"@type":53,"author":54,"headline":13,"publisher":56,"fileFormat":59,"inLanguage":23,"description":14,"dateModified":60,"datePublished":61,"encodingFormat":59,"isAccessibleForFree":62,"interactionStatistic":63},"DigitalDocument",{"name":9,"@type":55},"Person",{"url":41,"name":57,"@type":58},"DocShare","Organization","application/pdf","2026-09-05","2026-08-02",true,{"@type":64,"interactionType":65,"userInteractionCount":20},"InteractionCounter",{"@type":66},"ViewAction",{"@type":68,"mainEntity":69},"FAQPage",[70,76,80],{"name":71,"@type":72,"acceptedAnswer":73},"Why are traditional signature-based malware detection methods insufficient?","Question",{"text":74,"@type":75},"They often fail to detect new or altered malware versions, including polymorphic and metamorphic families, where signatures change over time.","Answer",{"name":77,"@type":72,"acceptedAnswer":78},"What are the main features used in this study for machine learning models?",{"text":79,"@type":75},"The study uses opcodes, captured either statically by examining program characteristics or dynamically by observing executed instructions at runtime.",{"name":81,"@type":72,"acceptedAnswer":82},"How do the sequence and frequency datasets differ in dynamic analysis?",{"text":83,"@type":75},"The sequence dataset extracts the ordered executed opcodes up to a large instruction limit, while the frequency dataset summarizes opcode histograms over fixed instruction windows to reduce sample size and improve information density.","https://schema.org",{"og:url":50,"og:type":86,"og:title":13,"og:site_name":57,"og:description":14},"article",{"robots":88,"canonical":50},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":91},[92,96,100,104,109,114,119,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":93,"show_sort_weight":94,"slug":95},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":97,"show_sort_weight":98,"slug":99},"Literature",80,"literature",{"id":51,"doc_module":4,"doc_module_name":46,"category_name":101,"show_sort_weight":102,"slug":103},"Exam",70,"exam",{"id":105,"doc_module":4,"doc_module_name":46,"category_name":106,"show_sort_weight":107,"slug":108},5,"Comic",60,"comic",{"id":110,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},6,"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":105,"slug":137},19,"General","general"]