Papers › Classification of Malware by Using Structural Entropy on Convolutional Neural Networks

Classification of Malware by Using Structural Entropy on Convolutional Neural Networks

27 Apr 2018archive 2025-07-28

Daniel Gibert, Carles Mateu, Jordi Planes, Ramon Vicens

he number of malicious programs has grown both in number and in sophistication. Analyzing the malicious intent of vast amounts of data requires huge resources and thus, effective categorization of malware is required. In this paper, the content of a malicious program is represented as an entropy stream, where each value describes the amount of entropy of a small chunk of code in a specific location of the file. Wavelet transforms are then applied to this entropy signal to describe the variation in the entropic energy. Motivated by the visual similarity between streams of entropy of malicious software belonging to the same family, we propose a file agnostic deep learning approach for categorization of malware. Our method exploits the fact that most variants are generated by using common obfuscation techniques and that compression and encryption algorithms retain some properties present in the original code. This allows us to find discriminative patterns that almost all variants in a family share. Our method has been evaluated using the data provided by Microsoft for the BigData Innovators Gathering Anti-Malware Prediction Challenge, and achieved promising results in comparison with the State of the Art.

PaperPDFCode

Code

Repository list and official/mentioned flags are the archive's, frozen 2025-07-28. Reachability, where shown, is from one Syntology probe window (2026-09-16 to 2026-09-18); repositories not probed show nothing. GitHub stars are not tracked.

Code Syntology ran Syntology

Not run by Syntology. Nothing on this page verifies that the listed code works.

Tasks

General ClassificationMalware Classification

Results from the paper archive 2025-07-28

TaskDatasetModelMetricValueRank at snapshotLeaderboardReport
Malware Classification Microsoft Malware Classification Challenge Dynamic Time Wrapping + K-NN Accuracy (10-fold) 0.9894 #8 of 29 Archive leaderboard report
Malware Classification Microsoft Malware Classification Challenge Dynamic Time Wrapping + K-NN LogLoss 0.367724 #8 of 29 Archive leaderboard report
Malware Classification Microsoft Malware Classification Challenge Dynamic Time Wrapping + K-NN Macro F1 (10-fold) 0.9813 #8 of 29 Archive leaderboard report
Malware Classification Microsoft Malware Classification Challenge Multiresolution CNN Accuracy (10-fold) 0.9828 #11 of 29 Archive leaderboard report
Malware Classification Microsoft Malware Classification Challenge Multiresolution CNN LogLoss 0.124431 #11 of 29 Archive leaderboard report
Malware Classification Microsoft Malware Classification Challenge Multiresolution CNN Macro F1 (10-fold) 0.9636 #11 of 29 Archive leaderboard report
Malware Classification Microsoft Malware Classification Challenge Structural entropy CNN Accuracy (10-fold) 0.9708 #18 of 29 Archive leaderboard report
Malware Classification Microsoft Malware Classification Challenge Structural entropy CNN LogLoss 0.134624 #18 of 29 Archive leaderboard report
Malware Classification Microsoft Malware Classification Challenge Structural entropy CNN Macro F1 (10-fold) 0.9314 #18 of 29 Archive leaderboard report
Malware Classification Microsoft Malware Classification Challenge Multiresolution CNN + Bagging LogLoss 0.075081 #23 of 29 Archive leaderboard report

Ranks are positions in the archive's leaderboards as they stood at the 2025-07-28 snapshot. Results published since then are not among these rows, so a rank here is not a current standing.

Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections