Understanding uses and misuses of similarity hashing functions for malware detection and family clustering in actual scenarios.
Marcus BotacinVitor Hugo Galhardo MoiaFabricio CeschinMarco Aurélio Amaral HenriquesAndré GrégioPublished in: Digit. Investig. (2021)
Keyphrases
- malware detection
- similarity function
- anomaly detection
- similarity calculation
- distance metric
- malicious executables
- clustering method
- clustering algorithm
- dissimilarity measure
- k means
- similarity matrix
- application programming interface
- distance measure
- binary codes
- distance function
- unsupervised learning
- similarity measure
- source code
- spectral clustering
- hamming distance
- euclidean distance
- similar objects
- object oriented