{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,12]],"date-time":"2025-10-12T03:25:18Z","timestamp":1760239518118,"version":"build-2065373602"},"reference-count":35,"publisher":"MDPI AG","issue":"12","license":[{"start":{"date-parts":[[2020,12,2]],"date-time":"2020-12-02T00:00:00Z","timestamp":1606867200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>The emergence of a large number of new malicious code poses a serious threat to network security, and most of them are derivative versions of existing malicious code. The classification of malicious code is helpful to analyze the evolutionary trend of malicious code families and trace the source of cybercrime. The existing methods of malware classification emphasize the depth of the neural network, which has the problems of a long training time and large computational cost. In this work, we propose the shallow neural network-based malware classifier (SNNMAC), a malware classification model based on shallow neural networks and static analysis. Our approach bridges the gap between precise but slow methods and fast but less precise methods in existing works. For each sample, we first generate n-grams from their opcode sequences of the binary file with a decompiler. An improved n-gram algorithm based on control transfer instructions is designed to reduce the n-gram dataset. Then, the SNNMAC exploits a shallow neural network, replacing the full connection layer and softmax with the average pooling layer and hierarchical softmax, to learn from the dataset and perform classification. We perform experiments on the Microsoft malware dataset. The evaluation result shows that the SNNMAC outperforms most of the related works with 99.21% classification precision and reduces the training time by more than half when compared with the methods using DNN (Deep Neural Networks).<\/jats:p>","DOI":"10.3390\/fi12120219","type":"journal-article","created":{"date-parts":[[2020,12,2]],"date-time":"2020-12-02T07:49:54Z","timestamp":1606895394000},"page":"219","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Malware Classification Based on Shallow Neural Network"],"prefix":"10.3390","volume":"12","author":[{"given":"Pin","family":"Yang","sequence":"first","affiliation":[{"name":"College of Cybersecurity, Sichuan University, Chengdu 610065, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Huiyu","family":"Zhou","sequence":"additional","affiliation":[{"name":"College of Cybersecurity, Sichuan University, Chengdu 610065, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yue","family":"Zhu","sequence":"additional","affiliation":[{"name":"College of Cybersecurity, Sichuan University, Chengdu 610065, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Liang","family":"Liu","sequence":"additional","affiliation":[{"name":"College of Cybersecurity, Sichuan University, Chengdu 610065, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lei","family":"Zhang","sequence":"additional","affiliation":[{"name":"College of Cybersecurity, Sichuan University, Chengdu 610065, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2020,12,2]]},"reference":[{"key":"ref_1","unstructured":"(2019, November 10). New Malware. Available online: https:\/\/www.av-test.org\/en\/statistics\/malware."},{"key":"ref_2","unstructured":"(2019, November 10). The Future of Mobile Malware. Available online: http:\/\/www.symantec.com\/connect\/blogs\/future-mobile-malware."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Rafique, M.Z., Chen, P., Huygens, C., and Joosen, W. (2014, January 12\u201316). Evolutionary algorithms for classification of malware families through different network behaviors. Proceedings of the 2014 Annual Conference on Genetic and Evolutionary Computation, Vancouver, BC, Canada.","DOI":"10.1145\/2576768.2598238"},{"key":"ref_4","unstructured":"(2019, November 10). Avast Reports on WanaCrypt0r 2.0 Ransomware that Infected NHS and Telefonica. Available online: https:\/\/blog.avast.com\/ransomware-that-infected-telefonica-and-nhs-hospitals-isspreading-aggressively-withover-50000-attacks-so-far-today."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s11416-015-0261-z","article-title":"A comparison of static, dynamic, and hybrid analysis for malware detection","volume":"13","author":"Damodaran","year":"2017","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"33","DOI":"10.1016\/j.cose.2015.03.007","article-title":"Hypervisor-based malware protection with Access Miner","volume":"52","author":"Fattori","year":"2015","journal-title":"Comput. Secur."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"251","DOI":"10.1016\/j.cose.2015.04.001","article-title":"AMAL: High-fidelity, behavior-based automated malware analysis and classification","volume":"52","author":"Mohaisen","year":"2015","journal-title":"Comput. Secur."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"4147","DOI":"10.1007\/s00521-016-2708-7","article-title":"An improved Android malware detection scheme based on an evolving hybrid neuro-fuzzy classifier (EHNFC) and permission-based features","volume":"28","author":"Altaher","year":"2016","journal-title":"Neural Comput. Appl."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"153","DOI":"10.1007\/s11416-016-0278-y","article-title":"Graph embedding as a new approach for unknown malware detection","volume":"13","author":"Hashemi","year":"2016","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"ref_10","first-page":"91","article-title":"Classification of malware families based on runtime behaviors","volume":"37","author":"Acarman","year":"2017","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Fan, C.-I., Hsiao, H.-W., Chou, C.-H., and Tseng, Y.-F. (2015, January 1\u20135). Malware Detection Systems Based on API Log Data Mining. Proceedings of the 2015 IEEE 39th Annual Computer Software and Applications Conference, Taichung, Taiwan.","DOI":"10.1109\/COMPSAC.2015.241"},{"key":"ref_12","first-page":"227","article-title":"Entropy analysis to classify unknown packing algorithms for malware detection","volume":"16","author":"Park","year":"2016","journal-title":"Int. J. Inf. Secur."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"64","DOI":"10.1016\/j.ins.2011.08.020","article-title":"Opcode sequences as representation of executables for data-mining-based unknown malware detection","volume":"231","author":"Santos","year":"2013","journal-title":"Inf. Sci."},{"key":"ref_14","unstructured":"Rong, F., Fang, Y., and Zuo, Z. (2018). Macspmd: Malware Detection Based on API Call Pattern. Comput. Sci., 131\u2013138. Available online: http:\/\/www.jsjkx.com\/CN\/article\/openArticlePDF.jsp?id=133."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"213","DOI":"10.1007\/s11416-017-0307-5","article-title":"Intelligent OS X malware threat detection with code inspection","volume":"14","author":"Pajouh","year":"2017","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"266","DOI":"10.1016\/j.compeleceng.2017.02.013","article-title":"Machine learning aided Android malware classification","volume":"61","author":"Milosevic","year":"2017","journal-title":"Comput. Electr. Eng."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"76796","DOI":"10.1109\/ACCESS.2020.2986014","article-title":"Comparative Analysis of Low-Dimensional Features and Tree-Based Ensembles for Malware Detection Systems","volume":"8","author":"Euh","year":"2020","journal-title":"IEEE Access"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"88","DOI":"10.1016\/j.future.2018.03.007","article-title":"A deep Recurrent Neural Network based approach for Internet of Things malware threat hunting","volume":"85","author":"HaddadPajouh","year":"2018","journal-title":"Futur. Gener. Comput. Syst."},{"key":"ref_19","first-page":"1","article-title":"Detecting Malware with an Ensemble Method Based on Deep Neural Network","volume":"2018","author":"Yan","year":"2018","journal-title":"Secur. Commun. Netw."},{"key":"ref_20","first-page":"654","article-title":"Malicious Code Clustering Based on Graph Convolution Network","volume":"56","author":"Liu","year":"2019","journal-title":"J. Sichuan Univ."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Dahl, G.E., Stokes, J.W., Deng, L., and Yu, D. (2013, January 26\u201331). Large-scale malware classification using random projections and neural networks. Proceedings of the 2013 IEEE International Conference on Acoustics, Speech and Signal Processing, Vancouver, BC, Canada.","DOI":"10.1109\/ICASSP.2013.6638293"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"383","DOI":"10.1007\/s10846-006-9089-6","article-title":"UAVs in Urban Operations: Target Interception and Containment","volume":"47","author":"Reimann","year":"2006","journal-title":"J. Intell. Robot. Syst."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Raff, E., Sylvester, J., and Nicholas, C. (2017, January 3). Learning the PE Header, Malware Detection with Minimal Domain Knowledge. Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, Dallas Texas USA.","DOI":"10.1145\/3128572.3140442"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"6249","DOI":"10.1109\/ACCESS.2019.2963724","article-title":"A Comprehensive Review on Malware Detection Approaches","volume":"8","author":"Aslan","year":"2020","journal-title":"IEEE Access"},{"key":"ref_25","unstructured":"Raff, E., Barker, J., Sylvester, J., Brandon, R., Catanzaro, B., and Nicholas, C. (2017). Malware detection by eating a whole exe. Malware detection by eating a whole exe. arXiv."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"101748","DOI":"10.1016\/j.cose.2020.101748","article-title":"Image-Based malware classification using ensemble of CNN architectures (IMCEC)","volume":"92","author":"Vasan","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_27","unstructured":"Wang, J., Baoxin, X.U., Liu, D., Li, F., and Zhang, X. (2018). Detection Method for Linux Platform Malware. (No. 15\/645767), U.S. Patent."},{"key":"ref_28","unstructured":"Xin, H. (2013, January 26\u201328). MutantX-S: Scalable Malware Clustering Based on Static Features. Proceedings of the 2013 {USENIX} Annual Technical Conference ({USENIX}{ATC} 13), San Jose, CA, USA."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/505282.505283","article-title":"Machine learning in automated text categorization","volume":"34","author":"Sebastiani","year":"2002","journal-title":"ACM Comput. Surv."},{"key":"ref_30","first-page":"1113","article-title":"Feature hashing for large scale multitask learning","volume":"Volume 7","author":"Weinberger","year":"2009","journal-title":"Proceedings of the International Conference of Machine Learning (ICML)"},{"key":"ref_31","unstructured":"Lin, M., Chen, Q., and Yan, S. (2013). Network in Network. arXiv."},{"key":"ref_32","unstructured":"Mikolov, T., Chen, K., Corrado, G., and Dean, J. (2013). Efficient estimation of word representations in vector space. arXiv."},{"key":"ref_33","unstructured":"Ronen, R., Radu, M., Feuerstein, C., and Yom-Tov, E. (2018). Microsoft Malware Classification Challenge. arXiv."},{"key":"ref_34","unstructured":"(2019, November 10). Microsoft Malware Classification Challenge (BIG 2015) First Place Team: Say No to Overfitting. Available online: http:\/\/blog.kaggle.com\/2015\/05\/26\/microsoft-malware-winners-interview-1st-place-no-to-overfitting."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1016\/j.future.2018.07.052","article-title":"Classification of ransomware families with machine learning based on N-gram of opcodes","volume":"90","author":"Zhang","year":"2019","journal-title":"Futur. Gener. Comput. Syst."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/12\/12\/219\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T10:40:37Z","timestamp":1760179237000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/12\/12\/219"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,12,2]]},"references-count":35,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2020,12]]}},"alternative-id":["fi12120219"],"URL":"https:\/\/doi.org\/10.3390\/fi12120219","relation":{},"ISSN":["1999-5903"],"issn-type":[{"type":"electronic","value":"1999-5903"}],"subject":[],"published":{"date-parts":[[2020,12,2]]}}}