• Home
  • Search
  • ModDiff: Modularity Similarity-Based Malware Homologation Detection
  • Cite Icon5
  • https://doi.org/10.3390/electronics12102258Copy DOI Icon

ModDiff: Modularity Similarity-Based Malware Homologation Detection

Show More
  • Abstract
  • Highlights & Summary
  • PDF
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

In recent years, the number and scale of malicious codes have grown exponentially, posing an increasing threat to cybersecurity. Hence, it is of great research value to quickly identify variants of malware and master their family information. Binary code similarity detection, as a key technique in reverse analysis, plays an indispensable role in malware analysis. However, most existing methods focus on similarity at the function or basic block level, ignoring the modular composition of malware. Implementing similarity detection among malware modules would greatly improve the efficiency and accuracy of homology detection. Inspired by the successful application of deep-learning techniques in program analysis, we propose a binary code module similarity detection method called ModDiff. It abstracts malware into attribute graphs, clusters functions using graph-embedded clustering algorithms to decompose malware into function-based modules, and calculates module similarity using graph-matching algorithms and natural language processing-based function similarity detection algorithms. The experimental results indicated that ModDiff improves the accuracy of module partitioning by 10.8% compared with previous work, and the highest F1 score of 89% is achieved in malware homologation detection. These results demonstrate the effectiveness of ModDiff in detecting and analyzing malware with important application value and development prospects.

Loading PDF

Similar Papers
  • Research Article
  • Citations4

Binary Code Representation With Well-Balanced Instruction Normalization

  • Jan 01, 2023
  • IEEE Access
  • Hyungjoon Koo +3
  • Research Article
  • Citations1

MSSA: multi-stage semantic-aware neural network for binary code similarity detection

  • Jan 17, 2025
  • PeerJ Computer Science
  • Bangrui Wan +4
  • PDF
  • Research Article
  • Citations3

SROBR: Semantic Representation of Obfuscation‐Resilient Binary Code

  • Jan 01, 2022
  • Wireless Communications and Mobile Computing
  • Ke Tang +8
  • Research Article
  • Citations9

BinAIV: Semantic-enhanced vulnerability detection for Linux x86 binaries

  • Sep 27, 2023
  • Computers & Security
  • Yeming Gu +2
  • Research Article
  • Citations9

BinCola: Diversity-Sensitive Contrastive Learning for Binary Code Similarity Detection

  • Oct 01, 2024
  • IEEE Transactions on Software Engineering
  • Shuai Jiang +5
  • Research Article

Enhancing Binary Security Analysis Through Pre-Trained Semantic and Structural Feature Matching

  • Oct 30, 2025
  • Applied Sciences
  • Yi Chen +4
  • Research Article

Fus: Combining Semantic and Structural Graph Information for Binary Code Similarity Detection

  • Sep 24, 2025
  • Electronics
  • Yanlin Li +3
  • Conference Article
  • Citations8

Investigating Graph Embedding Methods for Cross-Platform Binary Code Similarity Detection

  • Jun 01, 2022
  • Victor Cochard +3
  • Research Article
  • Citations1

AAPFE: Aligned Assembly Pre-Training Function Embedding for Malware Analysis

  • Mar 17, 2022
  • Electronics
  • Hairen Gui +6
  • Conference Article
  • Citations111

Identifying Dormant Functionality in Malware Programs

  • Jan 01, 2010
  • Paolo Milani Comparetti +5
  • Research Article
  • Citations8

ASAP-MS combined with mass spectrum similarity and binary code for rapid and intelligent authentication of 78 edible flowers

  • Oct 15, 2023
  • Food Chemistry
  • Qian Meng +10
  • Research Article
  • Citations14

Multilevel Coding Scheme for Integer-Forcing MIMO Receivers With Binary Codes

  • Aug 01, 2017
  • IEEE Transactions on Wireless Communications
  • Sung Ho Chae +4
  • Research Article
  • Citations29

Compact Hash Code Learning With Binary Deep Neural Network

  • Aug 22, 2019
  • IEEE Transactions on Multimedia
  • Thanh-Toan Do +4
  • Research Article

CrossSimEmb: transformer-based embedding model for cross-compilation binary code similarity detection

  • Oct 03, 2025
  • The Journal of Supercomputing
  • Gaoqing Yu +5
  • Research Article
  • Citations2

Malware Analysis and Static Call Graph Generation with Radare2

  • Jul 20, 2023
  • Studia Universitatis Babeș-Bolyai Informatica
  • Attila Mester
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.