• Home
  • Search
  • Functions-based CFG Embedding for Malware Homology Analysis
  • Cite Icon14
  • https://doi.org/10.1109/ict.2019.8798769Copy DOI Icon

Functions-based CFG Embedding for Malware Homology Analysis

  • Apr 1, 2019
  • Jieran Liu +2 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Malware homology analysis aims at detecting whether different malicious code originates from the same set of malicious code or is written by the same author or team, and whether it has intrinsic relevance and similarity. At the same time, the homology analysis of malicious code is also an important part of studying the groups behind different APT (Advanced Persistent Threat) attacks. At present, homology identification still relies on manual analysis and security experts' experience in the anti-malware industry. In addition, research on large-scale malicious code automated homology analysis is still insufficient. The method proposed in this paper is to solve the problem of large-scale malicious code homology automatic analysis, and hope to provide auxiliary information for discovering the group behind the APT attack. In this paper, we collected samples of different APT groups from public threat intelligence and proposed a novel approach to classify these samples into different APT groups to further analyze the homology of malware. We combined the CFG (Control Flow Graph) of the malicious code function and the disassembled code of the stripped malware to generate the embedding, i.e., a numeric vector, which formed a function feature database of the APT group, and presented a neural network model used for APT group classification. We have implemented our approach in a prototype system called MCrab. Our extensive evaluation showed that MCrab could produce high accuracy results, with few to no false positives. Our research also showed that deep learning can be successfully applied to malware homology analysis.

Similar Papers
  • Conference Article
  • Citations6

Research on Prevention Solution of Advanced Persistent Threat

  • Jan 01, 2014
  • Xiaomei Liu
  • Research Article
  • Citations76

A novel approach for APT attack detection based on combined deep learning model

  • Apr 11, 2021
  • Neural Computing and Applications
  • Cho Do Xuan +1
  • Book Chapter
  • Citations5

Evolution of Advanced Persistent Threat (APT) Attacks and Actors

  • Jan 01, 2019
  • Chia-Mei Chen +2
  • Research Article
  • Citations55

APT attack detection based on flow network analysis techniques using deep learning

  • Jul 07, 2020
  • Journal of Intelligent & Fuzzy Systems
  • Cho Do Xuan +2
  • Research Article
  • Citations9

A Hybrid Intelligent Approach to Attribute Advanced Persistent Threat Organization Using PSO-MSVM Algorithm

  • Dec 01, 2022
  • IEEE Transactions on Network and Service Management
  • Yangyang Mei +4
  • Research Article
  • Citations18

A new framework for APT attack detection based on network traffic

  • Mar 09, 2023
  • Journal of Intelligent & Fuzzy Systems
  • Hoa Cuong Nguyen +3
  • Conference Article
  • Citations5

APT Attack Detection Method Based on Traffic Log Features

  • Sep 23, 2022
  • Xingjie Huang +5
  • Research Article
  • Citations1

APT Attack Detection Method Based on Traceability Graph

  • Jun 01, 2024
  • Journal of Intelligence and Knowledge Engineering
  • Yihan Yin +2
  • Research Article
  • Citations128

Conan: A Practical Real-Time APT Detection System With High Accuracy and Efficiency

  • Feb 04, 2020
  • IEEE Transactions on Dependable and Secure Computing
  • Chunlin Xiong +8
  • Book Chapter
  • Citations31

Proposed Approach for Targeted Attacks Detection

  • Dec 29, 2015
  • Ibrahim Ghafir +1
  • Book Chapter
  • Citations1

Attacks on Android-Based Smartphones and Impact of Vendor Customization on Android OS Security

  • Jan 01, 2020
  • Sudesh Kumar +2
  • Conference Article
  • Citations20

Ctracer: Uncover C&C in Advanced Persistent Threats Based on Scalable Framework for Enterprise Log Data

  • Jun 01, 2015
  • Kai-Fong Hong +3
  • Research Article
  • Citations20

Detecting mobile advanced persistent threats based on large-scale DNS logs

  • Jun 12, 2020
  • Computers & Security
  • Zongyuan Xiang +2
  • Research Article
  • Citations286

Detection of advanced persistent threat using machine-learning correlation analysis

  • Jul 06, 2018
  • Future Generation Computer Systems
  • Ibrahim Ghafir +6
  • Research Article

A Trustworthy Dataset for APT Intelligence with an Auto-Annotation Framework

  • Aug 15, 2025
  • Electronics
  • Rui Qi +8
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.