Automated malware identification method using image descriptors and singular value decomposition

dc.contributor.authorTuncer, Turker
dc.contributor.authorErtam, Fatih
dc.contributor.authorDogan, Sengul
dc.date.accessioned2026-08-12T16:42:24Z
dc.date.issued2021
dc.departmentFırat Üniversitesi
dc.description.abstractCyber-attacks have become a significant problem worldwide. Therefore, many methods, networks, and applications have been suggested for providing information security in the literature. Automated malware classification has become one of the hot-topic research areas in information security and digital forensics. Image processing methods have been used to solve malware detection and recognition problem. Three effective feature extractors are used to propose an automated malware classification method in this work. The proposed method uses local binary pattern (LBP), singular value decomposition (SVD), and a novel local ternary pattern network (LTPNet) to extract features. The extracted features using the hybrid feature extractor are reduced using principal component analysis (PCA). The final features are forwarded to linear discriminant analysis (LDA) classifier. A commonly used heterogonous and big malware dataset (Maligm) is used to obtain the success of the proposed LBP, LTPNet, and SVD based malware classification method. There are 9339 malwares with 25 classes in the Maligm dataset. The proposed LBP-SVD-LTPNet based method achieved an 88.08% success rate using this dataset. The obtained accuracy rate of the proposed LBP-SVD-LTPNet based method is higher than the selected deep learning methods. These methods are convolutional neural network (CNN), multi-layer perceptron (MLP), gated recurrent units (GRU), GoogleNet, VGG16, and ResNet. These results openly demonstrated that the proposed LBP-SVD-LTPNet based malware classification method is successful.
dc.identifier.doi10.1007/s11042-020-10317-6
dc.identifier.endpage10900
dc.identifier.issn1380-7501
dc.identifier.issn1573-7721
dc.identifier.issue7
dc.identifier.orcid0000-0002-9736-8068
dc.identifier.orcid0000-0001-9677-5684
dc.identifier.scopus2-s2.0-85098637034
dc.identifier.scopusqualityQ1
dc.identifier.startpage10881
dc.identifier.urihttps://doi.org/10.1007/s11042-020-10317-6
dc.identifier.urihttps://hdl.handle.net/11508/46249
dc.identifier.volume80
dc.identifier.wosWOS:000604479100009
dc.identifier.wosqualityN/A
dc.indekslendigikaynakWeb of Science
dc.indekslendigikaynakScopus
dc.language.isoen
dc.publisherSpringer
dc.relation.ispartofMultimedia Tools and Applications
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/closedAccess
dc.snmzKA_WoS_20260511
dc.subjectMalware identification
dc.subjectLocal ternary pattern network
dc.subjectLocal binary pattern
dc.subjectSingular value decomposition
dc.titleAutomated malware identification method using image descriptors and singular value decomposition
dc.typeArticle

Dosyalar