A Comparative Analysis of Malware Classification Based on Visualization Techniques

Authors

  • Wisam Jummar Center for Continuing Education, University of Anbar Author
  • Ismail Ahmed Author
  • Khattab Alheeti Author

DOI:

https://doi.org/10.65204/djes.v3i3.861

Keywords:

Malware Detection and Classification; Malware Visualization; Cybersecurity

Abstract

Malware identification and classification is an important research direction due to the increasing number of electronic devices, which has led to the proliferation of malware that makes it difficult to contain. This is a significant risk in the digital world. Malware identification and classification using traditional methods suffer from several limitations. Obfuscation techniques in static methods are a problem that hinders feature extraction, while the time required for dynamic methods is a barrier, in addition to the problems posed by evasion techniques. In this paper, we examine methods that use a new approach based on malware visualization, which helps overcome the problems faced by traditional methods. Research in this area is divided into three groups. The first group relies on hand crafted features, the second group relies on deep learning algorithms, and the third group adopts hybrid methods that combine both techniques. Through a careful analysis of these works, the methods and algorithms used, the strengths and weaknesses of each method were identified, and a set of solutions were proposed for developing robust classification systems.

References

D. Gibert, C. Mateu, J. Planes, and R. Vicens, “Using convolutional neural networks for classification of malware represented as images,” J. Comput. Virol. Hacking Tech., vol. 15, no. 1, pp. 15–28, 2019, doi: 10.1007/s11416-018-0323-0.

S. Ni, Q. Qian, and R. Zhang, “Malware identification using visualization images and deep learning,” Comput. Secur., vol. 77, pp. 871–885, 2018, doi: 10.1016/j.cose.2018.04.005.

J. Jeon, J. H. Park, and Y. S. Jeong, “Dynamic Analysis for IoT Malware Detection with Convolution Neural Network Model,” IEEE Access, vol. 8, pp. 96899–96911, 2020, doi: 10.1109/ACCESS.2020.2995887.

H. Panchariya and S. Bharkad, “Comparative Analysis of Feature Extraction Methods for Optic Disc Detection,” IOSR J. Comput. Eng., vol. 16, no. 3, pp. 49–54, 2014, doi: 10.9790/0661-16334954.

J. Lee and J. Lee, “A Classification System for Visualized Malware Based on Multiple Autoencoder Models,” IEEE Access, vol. 9, pp. 144786–144795, 2021, doi: 10.1109/ACCESS.2021.3122083.

L. Nataraj, S. Karthikeyan, G. Jacob, and B. S. Manjunath, “Malware images: Visualization and automatic classification,” in ACM International Conference Proceeding Series, 2011, pp. 1–7. doi: https://doi.org/10.1145/2016904.20169.

A. S. Bozkir, A. O. Cankaya, and M. Aydos, “Utilization and comparision of convolutional neural networks in malware recognition [Kötücül Yazilimlarin Taninmasinda Evrişimsel Sinir Aǧlarinin Kullanimi ve Karşilaştirilmasi],” in 27th Signal Processing and Communications Applications Conference, SIU 2019, IEEE, 2019, pp. 1–4. doi: 10.1109/SIU.2019.8806511.

Microsoft, “Microsoft Malware Classification Challenge (BIG 2015),” Kaggle. [Online]. Available: https://www.kaggle.com/c/malware-classification

M. Ahmadi, D. Ulyanov, S. Semenov, M. Trofimov, and G. Giacinto, “Microsoft malware classification challenge,” arXiv Prepr. arXiv1802.10135, pp. 183–194, 2018, doi: https://doi.org/10.48550/arXiv.1802.10135.

A. Makandar and A. Patrot, “Malware class recognition using image processing techniques,” in 2017 International Conference on Data Management, Analytics and Innovation, ICDMAI 2017, IEEE, 2017, pp. 76–80. doi: 10.1109/ICDMAI.2017.8073489.

A. Makandar and A. Patrot, “Wavelet Statistical Feature based Malware Class Recognition and Classification using Supervised Learning Classifier,” Orient. J. Comput. Sci. Technol., vol. 10, no. 2, pp. 400–406, 2017, doi: 10.13005/ojcst/10.02.20.

A. Makandar and A. Patrot, “Trojan malware image pattern classification,” in In Proceedings of International Conference on Cognition and Recognition: ICCR, 2018, pp. 253–262. doi: 10.1007/978-981-10-5146-3_24.

J. Fu, J. Xue, Y. Wang, Z. Liu, and C. Shan, “Malware Visualization for Fine-Grained Classification,” IEEE Access, vol. 6, pp. 14510–14523, 2018, doi: 10.1109/ACCESS.2018.2805301.

H. Naeem, B. Guo, and M. R. Naeem, “A light-weight malware static visual analysis for IoT infrastructure,” in 2018 International Conference on Artificial Intelligence and Big Data, ICAIBD 2018, IEEE, 2018, pp. 240–244. doi: 10.1109/ICAIBD.2018.8396202.

Y. S. Liu, Y. K. Lai, Z. H. Wang, and H. B. Yan, “A New Learning Approach to Malware Classification Using Discriminative Feature Extraction,” IEEE Access, vol. 7, pp. 13015–13023, 2019, doi: 10.1109/ACCESS.2019.2892500.

H. Naeem, B. Guo, M. R. Naeem, F. Ullah, H. Aldabbas, and M. S. Javed, “Identification of malicious code variants based on image visualization,” Comput. Electr. Eng., vol. 76, pp. 225–237, 2019, doi: 10.1016/j.compeleceng.2019.03.015.

I. Baptista, S. Shiaeles, and N. Kolokotronis, “A novel malware detection system based on machine learning and binary visualization,” in 2019 IEEE International Conference on Communications Workshops, ICC Workshops 2019 - Proceedings, IEEE, 2019, pp. 1–6. doi: 10.1109/ICCW.2019.8757060.

V. Verma, S. K. Muttoo, and V. B. Singh, “Multiclass malware classification via first- and second-order texture statistics,” Comput. Secur., vol. 97, p. 101895, 2020, doi: 10.1016/j.cose.2020.101895.

V. Moussas and A. Andreatos, “Malware detection based on code visualization and two-level classification,” Inf., vol. 12, no. 3, pp. 1–14, 2021, doi: 10.3390/info12030118.

T. Gao, L. Zhao, X. Li, and W. Chen, “Malware detection based on semi-supervised learning with malware visualization,” Math. Biosci. Eng., vol. 18, no. 5, pp. 5955–6011, 2021, doi: 10.3934/MBE.2021300.

I. T. Ahmed, N. Jamil, M. M. Din, and B. T. Hammad, “Binary and Multi-Class Malware Threads Classification,” Appl. Sci., vol. 12, no. 24, 2022, doi: 10.3390/app122412528.

S. O’Shaughnessy and S. Sheridan, “Image-based malware classification hybrid framework based on space-filling curves,” Comput. Secur., vol. 116, p. 102660, 2022, doi: 10.1016/j.cose.2022.102660.

M. Benchadi Djafer Yahia, B. Batalo, and K. Fukui, “Efficient Malware Analysis Using Subspace-Based Methods on Representative Image Patterns,” IEEE Access, vol. 11, pp. 102492–102507, 2023, doi: 10.1109/ACCESS.2023.3313409.

I. T. Ahmed, B. T. Hammad, and N. Jamil, “A Comparative Performance Analysis of Malware Detection Algorithms Based on Various Texture Features and Classifiers,” IEEE Access, vol. 12, no. January, pp. 11500–11519, 2024, doi: 10.1109/ACCESS.2024.3354959.

R. Chauhan, K. K. Ghanshala, and R. C. Joshi, “Convolutional Neural Network (CNN) for Image Detection and Recognition,” in ICSCCC 2018 - 1st International Conference on Secure Cyber Computing and Communications, IEEE, 2018, pp. 278–282. doi: 10.1109/ICSCCC.2018.8703316.

A. Darem, J. Abawajy, A. Makkar, A. Alhashmi, and S. Alanazi, “Visualization and deep-learning-based malware variant detection using OpCode-level features,” Futur. Gener. Comput. Syst., vol. 125, pp. 314–323, 2021, doi: 10.1016/j.future.2021.06.032.

R. Vinayakumar, M. Alazab, K. P. Soman, P. Poornachandran, and S. Venkatraman, “Robust Intelligent Malware Detection Using Deep Learning,” IEEE Access, vol. 7, pp. 46717–46738, 2019, doi: 10.1109/ACCESS.2019.2906934.

A. Azab and M. Khasawneh, “MSIC: Malware Spectrogram Image Classification,” IEEE Access, vol. 8, pp. 102007–102021, 2020, doi: 10.1109/ACCESS.2020.2999320.

Y. Zhao, W. Cui, S. Geng, B. Bo, Y. Feng, and W. Zhang, “A malware detection method of code texture visualization based on an improved faster RCNN combining transfer learning,” IEEE Access, vol. 8, pp. 166630–166641, 2020, doi: 10.1109/ACCESS.2020.3022722.

M. Xiao, C. Guo, G. Shen, Y. Cui, and C. Jiang, “Image-based malware classification using section distribution information,” Comput. Secur., vol. 110, p. 102420, 2021, doi: 10.1016/j.cose.2021.102420.

G. Sun and Q. Qian, “Deep Learning and Visualization for Identifying Malware Families,” IEEE Trans. Dependable Secur. Comput., vol. 18, no. 1, pp. 283–295, 2021, doi: 10.1109/TDSC.2018.2884928.

O. Aslan and A. A. Yilmaz, “A New Malware Classification Framework Based on Deep Learning Algorithms,” IEEE Access, vol. 9, pp. 87936–87951, 2021, doi: 10.1109/ACCESS.2021.3089586.

T. M. Mohammed, L. Nataraj, S. Chikkagoudar, S. Chandrasekaran, and B. S. Manjunath, “Malware detection using frequency domain-based image visualization and deep learning,” arXiv Prepr. arXiv2101.10578, 2021, doi: 10.24251/hicss.2021.858.

S. Kumar and B. Janet, “DTMIC: Deep transfer learning for malware image classification,” J. Inf. Secur. Appl., vol. 64, no. December 2021, p. 103063, 2022, doi: 10.1016/j.jisa.2021.103063.

T. T. Son, C. Lee, H. Le-Minh, N. Aslam, and V. C. Dat, “An enhancement for image-based malware classification using machine learning with low dimension normalized input images,” J. Inf. Secur. Appl., vol. 69, no. August, p. 103308, 2022, doi: 10.1016/j.jisa.2022.103308.

A. Bensaoud and J. Kalita, “Deep multi-task learning for malware image classification,” J. Inf. Secur. Appl., vol. 64, 2022, doi: 10.1016/j.jisa.2021.103057.

R. Chaganti, V. Ravi, and T. D. Pham, “Image-based malware representation approach with EfficientNet convolutional neural networks for effective malware classification,” J. Inf. Secur. Appl., vol. 69, no. August, p. 103306, 2022, doi: 10.1016/j.jisa.2022.103306.

T. Van Dao, H. Sato, and M. Kubo, “An Attention Mechanism for Combination of CNN and VAE for Image-Based Malware Classification,” IEEE Access, vol. 10, no. June, pp. 85127–85136, 2022, doi: 10.1109/ACCESS.2022.3198072.

O. J. Falana, A. S. Sodiya, S. A. Onashoga, and B. S. Badmus, “Mal-Detect: An intelligent visualization approach for malware detection,” J. King Saud Univ. - Comput. Inf. Sci., vol. 34, no. 5, pp. 1968–1983, 2022, doi: 10.1016/j.jksuci.2022.02.026.

F. Zhong, Z. Chen, M. Xu, G. Zhang, D. Yu, and X. Cheng, “Malware-on-the-Brain: Illuminating Malware Byte Codes With Images for Malware Classification,” IEEE Trans. Comput., vol. 72, no. 2, pp. 438–451, 2023, doi: 10.1109/TC.2022.3160357.

F. Rustam, I. Ashraf, A. D. Jurcut, A. K. Bashir, and Y. Bin Zikria, “Malware detection using image representation of malware data and transfer learning,” J. Parallel Distrib. Comput., vol. 172, no. 2023, pp. 32–50, 2023, doi: 10.1016/j.jpdc.2022.10.001.

X. Qi, W. Liu, R. Lou, Q. Li, L. Jiang, and Y. Tang, “MC-ISA: A Multi-Channel Code Visualization Method for Malware Detection,” Electron., vol. 12, no. 10, 2023, doi: 10.3390/electronics12102272.

H. Deng, C. Guo, G. Shen, Y. Cui, and Y. Ping, “MCTVD: A malware classification method based on three-channel visualization and deep learning,” Comput. Secur., vol. 126, p. 103084, 2023, doi: 10.1016/j.cose.2022.103084.

Z. Chen and J. Cao, “VMCTE: Visualization-Based Malware Classification Using Transfer and Ensemble Learning,” Comput. Mater. Contin., vol. 75, no. 2, pp. 4445–4465, 2023, doi: 10.32604/cmc.2023.038639.

O. Sharma, A. Sharma, and A. Kalia, “MIGAN: GAN for facilitating malware image synthesis with improved malware classification on novel dataset,” Expert Syst. Appl., vol. 241, no. November 2022, p. 122678, 2024, doi: 10.1016/j.eswa.2023.122678.

F. Wang et al., “MalSort: Lightweight and efficient image-based malware classification using masked self-supervised framework with Swin Transformer,” J. Inf. Secur. Appl., vol. 83, no. May, p. 103784, 2024, doi: 10.1016/j.jisa.2024.103784.

M. Alshomrani, A. Albeshri, and A. A. Alsulami, “An Explainable Hybrid CNN – Transformer Architecture for Visual Malware Classification,” Sensors, vol. 25, no. 15, p. 4581, 2025, [Online]. Available: https://doi.org/10.3390/s25154581

T. Messay-kebede, B. N. Narayanan, and O. D.-B. Djaneye-boundjou, “Combination of Traditional and Deep Learning based Architectures to Overcome Class Imbalance and its Application to,” in NAECON 2018 - IEEE National Aerospace and Electronics Conference, IEEE, 2018, pp. 73–77. doi: 10.1109/NAECON.2018.8556722.

D. V. T. Nguyen and T. N. Nguyen, “HIT4Mal : Hybrid image transformation for malware classification,” no. October, pp. 1–15, 2019, doi: 10.1002/ett.3789.

M. Nisa, J. H. Shah, S. Kanwal, M. Raza, and T. Blažauskas, “applied sciences Hybrid Malware Classification Method Using Segmentation-Based Fractal Texture Analysis and Deep Convolution Neural Network Features,” Appl. Sci., vol. 10, no. 14, p. 4966, 2020, [Online]. Available: https://www.mdpi.com/2076-3417/10/14/4966

Z. Ren, G. Chen, and W. Lu, “Malware visualization methods based on deep convolution neural networks,” Multimed. Tools Appl., vol. 79, no. 15–16, pp. 10975–10993, 2020, doi: 10.1007/s11042-019-08310-9.

A. Pinhero et al., “Malware detection employed by visualization and deep neural network,” Comput. Secur., vol. 105, p. 102247, 2021, doi: 10.1016/j.cose.2021.102247.

M. Conti, S. Khandhar, and P. Vinod, “Computers & Security A few-shot malware classification approach for unknown family recognition using malware feature visualization,” vol. 122, 2022, doi: 10.1016/j.cose.2022.102887.

O. Sharma, A. Sharma, and A. Kalia, “Windows and IoT malware visualization and classification with deep CNN and Xception CNN using Markov images,” J. Intell. Inf. Syst., vol. 60, no. 2, pp. 349–375, 2023, doi: 10.1007/s10844-022-00734-4.

V. Anandhi, P. Vinod, and V. G. Menon, “Malware visualization and detection using DenseNets,” Pers. Ubiquitous Comput., vol. 28, no. 1, pp. 153–169, 2024, doi: 10.1007/s00779-021-01581-w.

W. Al-Khater and S. Al-Madeed, “Using 3D-VGG-16 and 3D-Resnet-18 deep learning models and FABEMD techniques in the detection of malware,” Alexandria Eng. J., vol. 89, no. December 2023, pp. 39–52, 2024, doi: 10.1016/j.aej.2023.12.061.

Q. M. Yaseen, E. Oudat, and M. Aldwairi, “Efficient Image-Based Memory Forensics for Fileless Malware Detection Using Texture Descriptors and LIME-Guided Deep Learning,” Computers, vol. 14, no. 11, p. 467, 2025, [Online]. Available: https://doi.org/10.3390/computers14110467

Downloads

Published

2026-08-26