{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:40:09Z","timestamp":1750293609701,"version":"3.41.0"},"reference-count":60,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2024,12,27]],"date-time":"2024-12-27T00:00:00Z","timestamp":1735257600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62172168"],"award-info":[{"award-number":["62172168"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2025,1,31]]},"abstract":"<jats:p>\n            Driven by the substantial profits, the evolution of Portable Executable (PE) malware has posed persistent threats. PE malware classification has been an important research field, and numerous classification methods have been proposed. With the development of machine learning, learning-based static classification methods achieve excellent performance. However, most existing methods cannot meet the requirements of industrial applications due to the limited resource consumption and concept drift. In this article, we propose a fast, high-accuracy, and robust FCG-based PE malware classification method. We first extract precise function call relationships through code and data cross-referencing analysis. Then we normalize function names to construct a concise and accurate function call graph. Furthermore, we perform topological analysis of the function call graph using social network analysis techniques, thereby enhancing the program function call features. Finally, we use a series of machine learning algorithms for classification. We implement a prototype system named\n            <jats:italic>MalSensor<\/jats:italic>\n            and compare it with nine state-of-the-art static PE malware classification methods. The experimental results show that\n            <jats:italic>MalSensor<\/jats:italic>\n            is capable of classifying a malicious file in 0.7 seconds on average with up to 98.35% accuracy, which represents a significant advantage over existing methods.\n          <\/jats:p>","DOI":"10.1145\/3688833","type":"journal-article","created":{"date-parts":[[2024,8,24]],"date-time":"2024-08-24T10:26:53Z","timestamp":1724495213000},"page":"1-28","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["MalSensor: Fast and Robust Windows Malware Classification"],"prefix":"10.1145","volume":"34","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0848-9528","authenticated-orcid":false,"given":"Haojun","family":"Zhao","sequence":"first","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1515-3558","authenticated-orcid":false,"given":"Yueming","family":"Wu","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8534-5048","authenticated-orcid":false,"given":"Deqing","family":"Zou","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7300-9215","authenticated-orcid":false,"given":"Yang","family":"Liu","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3934-7605","authenticated-orcid":false,"given":"Hai","family":"Jin","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,12,27]]},"reference":[{"unstructured":"010editor. 2023. 010editor. Retrieved from https:\/\/www.sweetscape.com\/010editor\/","key":"e_1_3_2_2_2"},{"unstructured":"IDA7.0. 2023. IDA7.0. Retrieved from https:\/\/www.hex-rays.com\/products\/ida\/news\/","key":"e_1_3_2_3_2"},{"unstructured":"MalwareBazaar. 2023. MalwareBazaar Homepage. Retrieved from https:\/\/bazaar.abuse.ch\/","key":"e_1_3_2_4_2"},{"unstructured":"Virbox. 2023. Virbox Protector. Retrieved from https:\/\/shell.virbox.com\/","key":"e_1_3_2_5_2"},{"unstructured":"VirusShare. 2023. VirusShare. Retrieved from https:\/\/virusshare.com\/","key":"e_1_3_2_6_2"},{"doi-asserted-by":"publisher","key":"e_1_3_2_7_2","DOI":"10.1145\/2857705.2857713"},{"doi-asserted-by":"publisher","key":"e_1_3_2_8_2","DOI":"10.1109\/ICC.2018.8422083"},{"key":"e_1_3_2_9_2","doi-asserted-by":"crossref","first-page":"90","DOI":"10.1109\/CSCI49370.2019.00022","volume-title":"2019 International Conference on Computational Science and Computational Intelligence (CSCI)","author":"Balram Neil","year":"2019","unstructured":"Neil Balram, George Hsieh, and Christian McFall. 2019. Static malware analysis using machine learning algorithms on APT1 dataset with string and PE header features. In 2019 International Conference on Computational Science and Computational Intelligence (CSCI). IEEE, 90\u201395."},{"doi-asserted-by":"publisher","key":"e_1_3_2_10_2","DOI":"10.1007\/978-3-030-30215-3_19"},{"doi-asserted-by":"publisher","key":"e_1_3_2_11_2","DOI":"10.5220\/0007701407190726"},{"key":"e_1_3_2_12_2","first-page":"21","volume-title":"Compression and Complexity of Sequences 1997","author":"Broder Andrei Z.","year":"1997","unstructured":"Andrei Z. Broder. 1997. On the resemblance and containment of documents. In Compression and Complexity of Sequences 1997. Bruno Carpentieri, Alfredo De Santis, Ugo Vaccaro, and James A. Storer (Eds.), IEEE, 21\u201329."},{"doi-asserted-by":"crossref","unstructured":"Aniket Chandak Wendy Lee and Mark Stamp. 2021. A comparison of Word2Vec HMM2Vec and PCA2Vec for malware classification. arXiv:2103.05763. Retrieved from https:\/\/arxiv.org\/abs\/2103.05763","key":"e_1_3_2_13_2","DOI":"10.1007\/978-3-030-62582-5_11"},{"doi-asserted-by":"publisher","key":"e_1_3_2_14_2","DOI":"10.1007\/978-3-319-26190-4_28"},{"doi-asserted-by":"publisher","key":"e_1_3_2_15_2","DOI":"10.1093\/bjc\/41.4.580"},{"unstructured":"ENISA. 2021. ENISA Threat Landscape 2021. Retrieved from https:\/\/www.enisa.europa.eu\/publications\/enisa-threat-landscape-2021","key":"e_1_3_2_16_2"},{"doi-asserted-by":"publisher","key":"e_1_3_2_17_2","DOI":"10.1109\/TC.2021.3082002"},{"doi-asserted-by":"publisher","key":"e_1_3_2_18_2","DOI":"10.2307\/3033543"},{"key":"e_1_3_2_19_2","first-page":"238","article-title":"Centrality in social networks: Conceptual clarification","author":"Freeman Linton C.","year":"2002","unstructured":"Linton C. Freeman. 2002. Centrality in social networks: Conceptual clarification. In Social Network: Critical Concepts in Sociology. Routledge, Londres, 238\u2013263.","journal-title":"Social Network: Critical Concepts in Sociology"},{"doi-asserted-by":"publisher","key":"e_1_3_2_20_2","DOI":"10.1016\/J.JNCA.2019.102526"},{"doi-asserted-by":"publisher","key":"e_1_3_2_21_2","DOI":"10.1007\/S11416-018-0323-0"},{"key":"e_1_3_2_22_2","first-page":"7794","volume-title":"Proc. Natl. Acad. Sci.","volume":"102","author":"Guimera Roger","year":"2005","unstructured":"Roger Guimera, Stefano Mossa, Adrian Turtschi, and L. A. Nunes Amaral. 2005. The worldwide air transportation network: Anomalous centrality, community structure, and cities\u2019 global roles. Proc. Natl. Acad. Sci. 102, 22 (2005), 7794\u20137799."},{"key":"e_1_3_2_23_2","first-page":"239","volume-title":"7th ACM Conference on Data and Application Security and Privacy, CODASPY 2017","author":"Hassen Mehadi","year":"2017","unstructured":"Mehadi Hassen and Philip K. Chan. 2017. Scalable function call graph-based malware classification. In 7th ACM Conference on Data and Application Security and Privacy, CODASPY 2017. Gail-Joon Ahn, Alexander Pretschner, and Gabriel Ghinita (Eds.), ACM, 239\u2013248."},{"key":"e_1_3_2_24_2","first-page":"187","volume-title":"2013 USENIX Annual Technical Conference","author":"Hu Xin","year":"2013","unstructured":"Xin Hu, Kang G. Shin, Sandeep Bhatkar, and Kent Griffin. 2013. MutantX-S: Scalable malware clustering based on static features. In 2013 USENIX Annual Technical Conference. Andrew Birrell and Emin G\u00fcn Sirer (Eds.), USENIX Association, 187\u2013198."},{"doi-asserted-by":"publisher","key":"e_1_3_2_25_2","DOI":"10.1007\/s11416-020-00354-y"},{"key":"e_1_3_2_26_2","first-page":"51","volume-title":"International Conference on Information Processing","author":"Jain Sachin","year":"2011","unstructured":"Sachin Jain and Yogesh Kumar Meena. 2011. Byte level n-gram analysis for malware detection. In International Conference on Information Processing. Springer, 51\u201359."},{"doi-asserted-by":"publisher","key":"e_1_3_2_27_2","DOI":"10.1007\/S11432-021-3567-Y"},{"doi-asserted-by":"publisher","key":"e_1_3_2_28_2","DOI":"10.1109\/GCIS.2013.28"},{"key":"e_1_3_2_29_2","first-page":"625","volume-title":"26th USENIX Security Symposium, USENIX Security 2017","author":"Jordaney Roberto","year":"2017","unstructured":"Roberto Jordaney, Kumar Sharad, Santanu Kumar Dash, Zhi Wang, Davide Papini, Ilia Nouretdinov, and Lorenzo Cavallaro. 2017. Transcend: Detecting concept drift in malware classification models. In 26th USENIX Security Symposium, USENIX Security 2017. Engin Kirda and Thomas Ristenpart (Eds.), USENIX Association, 625\u2013642. DOI: https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/jordaney"},{"doi-asserted-by":"publisher","key":"e_1_3_2_30_2","DOI":"10.1109\/NTMS.2018.8328749"},{"key":"e_1_3_2_31_2","first-page":"40","volume-title":"2013 IEEE Symposium on Computational Intelligence in Cyber Security, CICS 2013, IEEE Symposium Series on Computational Intelligence (SSCI)","author":"Kancherla Kesav","year":"2013","unstructured":"Kesav Kancherla and Srinivas Mukkamala. 2013. Image visualization based malware detection. In 2013 IEEE Symposium on Computational Intelligence in Cyber Security, CICS 2013, IEEE Symposium Series on Computational Intelligence (SSCI). IEEE, 40\u201344."},{"doi-asserted-by":"publisher","key":"e_1_3_2_32_2","DOI":"10.1007\/BF02289026"},{"doi-asserted-by":"publisher","key":"e_1_3_2_33_2","DOI":"10.1007\/s11416-011-0151-y"},{"key":"e_1_3_2_34_2","first-page":"1357","volume-title":"the 19th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, KDD 2013","author":"Kong Deguang","year":"2013","unstructured":"Deguang Kong and Guanhua Yan. 2013. Discriminant malware distance learning on structural information for automated malware classification. In the 19th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, KDD 2013. Inderjit S. Dhillon, Yehuda Koren, Rayid Ghani, Ted E. Senator, Paul Bradley, Rajesh Parekh, Jingrui He, Robert L. Grossman, and Ramasamy Uthurusamy (Eds.), ACM, 1357\u20131365."},{"key":"e_1_3_2_35_2","series-title":"Workshop Track Proceedings","volume-title":"6th International Conference on Learning Representations, ICLR 2018","author":"Krc\u00e1l Marek","year":"2018","unstructured":"Marek Krc\u00e1l, Ondrej Svec, Martin B\u00e1lek, and Otakar Jasek. 2018. Deep convolutional malware classifiers can learn from raw executables and labels only. In 6th International Conference on Learning Representations, ICLR 2018, Workshop Track Proceedings. OpenReview.net. DOI: https:\/\/openreview.net\/forum?id=HkHrmM1PM"},{"key":"e_1_3_2_36_2","series-title":"JMLR Workshop and Conference Proceedings","first-page":"957","volume-title":"32nd International Conference on Machine Learning, ICML 2015","volume":"37","author":"Kusner Matt J.","year":"2015","unstructured":"Matt J. Kusner, Yu Sun, Nicholas I. Kolkin, and Kilian Q. Weinberger. 2015. From word embeddings to document distances. In 32nd International Conference on Machine Learning, ICML 2015. Francis R. Bach and David M. Blei (Eds.), JMLR Workshop and Conference Proceedings, Vol. 37, JMLR.org, 957\u2013966. DOI: http:\/\/proceedings.mlr.press\/v37\/kusnerb15.html"},{"doi-asserted-by":"publisher","key":"e_1_3_2_37_2","DOI":"10.3390\/sym12050830"},{"doi-asserted-by":"publisher","key":"e_1_3_2_38_2","DOI":"10.1016\/j.ipm.2005.03.012"},{"unstructured":"Joe Security LLC. 2022. Joe Security. Retrieved from https:\/\/www.joesecurity.org\/","key":"e_1_3_2_39_2"},{"doi-asserted-by":"publisher","key":"e_1_3_2_40_2","DOI":"10.1145\/3468264.3473925"},{"doi-asserted-by":"publisher","key":"e_1_3_2_41_2","DOI":"10.1145\/1242572.1242592"},{"doi-asserted-by":"publisher","key":"e_1_3_2_42_2","DOI":"10.1016\/S0378-4371(00)00311-3"},{"key":"e_1_3_2_43_2","series-title":"Workshop Track Proceedings","volume-title":"1st International Conference on Learning Representations, ICLR 2013","author":"Mikolov Tom\u00e1s","year":"2013","unstructured":"Tom\u00e1s Mikolov, Kai Chen, Greg Corrado, and Jeffrey Dean. 2013. Efficient estimation of word representations in vector space. In 1st International Conference on Learning Representations, ICLR 2013. Yoshua B engio and Yann LeCun (Eds.), Workshop Track Proceedings. arXiv:1301.3781. Retrieved from http:\/\/arxiv.org\/abs\/1301.3781"},{"doi-asserted-by":"publisher","key":"e_1_3_2_44_2","DOI":"10.1109\/ACSAC.2007.21"},{"key":"e_1_3_2_45_2","first-page":"156","volume-title":"IEEE International Conference on Intelligence and Security Informatics, ISI 2008","author":"Moskovitch Robert","year":"2008","unstructured":"Robert Moskovitch, Dima Stopel, Clint Feher, Nir Nissim, and Yuval Elovici. 2008. Unknown malcode detection via text categorization and the imbalance problem. In IEEE International Conference on Intelligence and Security Informatics, ISI 2008. IEEE, 156\u2013161."},{"key":"e_1_3_2_46_2","first-page":"4","article-title":"Malware images: Visualization and automatic classification","author":"Nataraj Lakshmanan","year":"2011","unstructured":"Lakshmanan Nataraj, S. Karthikeyan, G. Jacob, and B. S. Manjunath. 2011. Malware images: Visualization and automatic classification. In 8th International Symposium on Visualization for Cyber Security, VizSec 2011. ACM, 4.","journal-title":"8th International Symposium on Visualization for Cyber Security, VizSec 2011"},{"doi-asserted-by":"publisher","key":"e_1_3_2_47_2","DOI":"10.1016\/j.cose.2018.04.005"},{"unstructured":"Nickcano. 2018. PyPackerDetect. Retrieved from https:\/\/github.com\/cylance\/PyPackerDetect","key":"e_1_3_2_48_2"},{"doi-asserted-by":"publisher","key":"e_1_3_2_49_2","DOI":"10.1109\/ICC40277.2020.9149143"},{"doi-asserted-by":"publisher","key":"e_1_3_2_50_2","DOI":"10.1145\/3427228.3427242"},{"key":"e_1_3_2_51_2","first-page":"268","volume-title":"32nd AAAI Conference on Artificial Intelligence","volume":"18","author":"Raff Edward","year":"2018","unstructured":"Edward Raff, Jon Barker, Jared Sylvester, Robert Brandon, Bryan Catanzaro, and Charles K. Nicholas. 2018. Malware detection by eating a whole EXE. In 32nd AAAI Conference on Artificial Intelligence, (AAAI Technical Report, Vol. WS-18), AAAI Press, 268\u2013276. Retrieved from https:\/\/aaai.org\/ocs\/index.php\/WS\/AAAIW18\/paper\/view\/16422"},{"doi-asserted-by":"publisher","key":"e_1_3_2_52_2","DOI":"10.1109\/ICMLA.2017.00-19"},{"key":"e_1_3_2_53_2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"230","DOI":"10.1007\/978-3-319-45719-2_11","volume-title":"Research in Attacks, Intrusions, and Defenses - 19th International Symposium, RAID 2016","volume":"9854","author":"Sebasti\u00e1n Marcos","year":"2016","unstructured":"Marcos Sebasti\u00e1n, Richard Rivera, Platon Kotzias, and Juan Caballero. 2016. AVclass: A tool for massive malware labeling. In Research in Attacks, Intrusions, and Defenses - 19th International Symposium, RAID 2016. Fabian Monrose, Marc Dacier, Gregory Blanc, and Joaqu\u00edn Garc\u00eda-Alfaro (Eds.), Lecture Notes in Computer Science, Vol. 9854, Springer, 230\u2013253."},{"doi-asserted-by":"crossref","unstructured":"Andrii Shalaginov Sergii Banin Ali Dehghantanha and Katrin Franke. 2018. Machine learning aided static malware analysis: A survey and tutorial. arXiv:1808.01201. Retrieved from http:\/\/arxiv.org\/abs\/1808.01201","key":"e_1_3_2_54_2","DOI":"10.1007\/978-3-319-73951-9_2"},{"doi-asserted-by":"publisher","key":"e_1_3_2_55_2","DOI":"10.1109\/TDSC.2018.2884928"},{"doi-asserted-by":"publisher","key":"e_1_3_2_56_2","DOI":"10.1016\/J.COMNET.2020.107138"},{"doi-asserted-by":"publisher","key":"e_1_3_2_57_2","DOI":"10.1016\/j.cose.2020.101748"},{"doi-asserted-by":"publisher","key":"e_1_3_2_58_2","DOI":"10.1016\/j.eswa.2019.113022"},{"doi-asserted-by":"publisher","key":"e_1_3_2_59_2","DOI":"10.1109\/DSN.2019.00020"},{"key":"e_1_3_2_60_2","first-page":"793","volume-title":"2017 IEEE International Conference on Computational Science and Engineering, CSE 2017, and IEEE International Conference on Embedded and Ubiquitous Computing, EUC 2017","author":"Zhang FuYong","year":"2017","unstructured":"FuYong Zhang and Tiezhu Zhao. 2017. Malware detection and classification based on N-grams attribute similarity. In 2017 IEEE International Conference on Computational Science and Engineering, CSE 2017, and IEEE International Conference on Embedded and Ubiquitous Computing, EUC 2017. IEEE Computer Society, 793\u2013796."},{"doi-asserted-by":"publisher","key":"e_1_3_2_61_2","DOI":"10.1609\/AAAI.V32I1.11782"}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3688833","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3688833","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:04:10Z","timestamp":1750291450000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3688833"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,27]]},"references-count":60,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,1,31]]}},"alternative-id":["10.1145\/3688833"],"URL":"https:\/\/doi.org\/10.1145\/3688833","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"type":"print","value":"1049-331X"},{"type":"electronic","value":"1557-7392"}],"subject":[],"published":{"date-parts":[[2024,12,27]]},"assertion":[{"value":"2023-08-25","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-07-11","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-12-27","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}