{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/deepsign-deep-learning-for-automatic-malware","title":"DeepSign: Deep Learning for Automatic Malware Signature Generation and Classification","arxiv_id":"1711.08336","date":"2017-11-21","proceeding":null,"authors":["Eli David","Nathan S. Netanyahu"],"abstract":"This paper presents a novel deep learning based method for automatic malware\nsignature generation and classification. The method uses a deep belief network\n(DBN), implemented with a deep stack of denoising autoencoders, generating an\ninvariant compact representation of the malware behavior. While conventional\nsignature and token based methods for malware detection do not detect a\nmajority of new variants for existing malware, the results presented in this\npaper show that signatures generated by the DBN allow for an accurate\nclassification of new malware variants. Using a dataset containing hundreds of\nvariants for several major malware families, our method achieves 98.6%\nclassification accuracy using the signatures generated by the DBN. The\npresented method is completely agnostic to the type of malware behavior that is\nlogged (e.g., API calls and their parameters, registry entries, websites and\nports accessed, etc.), and can use any raw input from a sandbox to successfully\ntrain the deep neural network which is used to generate malware signatures.","url_abs":"http://arxiv.org/abs/1711.08336v2","url_pdf":"http://arxiv.org/pdf/1711.08336v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"deepsign-deep-learning-for-automatic-malware","repo_url":"https://github.com/nahmiasd/DeepSign","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"none","reach":null},{"paper_slug":"deepsign-deep-learning-for-automatic-malware","repo_url":"https://github.com/tychen5/sportslottery","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"none","reach":null}],"tasks":[{"task_slug":"classification-1","task_name":"Classification"},{"task_slug":"deep-learning","task_name":"Deep Learning"},{"task_slug":"denoising","task_name":"Denoising"},{"task_slug":"classification","task_name":"General Classification"},{"task_slug":"malware-detection","task_name":"Malware Detection"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}