Idea
A 1D CNN-based malware classification model improving detection accuracy for cybersecurity teams and antivirus vendors.
Research Paper
Core Innovation
This paper introduces a novel method of converting malware binaries into 1D signals rather than 2D images, avoiding heuristic reshaping and quantisation noise. It adapts existing 2D CNNs and designs a custom 1D CNN architecture with ResNet and squeeze-and-excitation layers to enhance classification performance. This approach preserves more signal information and achieves superior results on the MalNet dataset compared to prior image-based methods.
Market Size (TAM)
$2–10B TAM, $1–2B SAM; assumption: growing cybersecurity market with increasing malware threats and demand for scalable detection solutions.
Potential Customers & Pain Points
- Cybersecurity Firms Needing Improved Malware Detection
- Antivirus Vendors Seeking Better Obfuscation Handling
- Enterprises Requiring Scalable Malware Classification
- Security Researchers Facing Limitations of Static and Dynamic Analysis
Business Model
Licensing the 1D CNN malware classification model as an API or SDK to cybersecurity companies and antivirus vendors.
Competitive Landscape
- CrowdStrike
- Symantec
- McAfee
Implementation Challenges
- Integration with existing security infrastructure
- Need for large labeled malware datasets
- Competition from established cybersecurity vendors
Validation Strategy
- Benchmark model on additional malware datasets
- Pilot integration with cybersecurity firms
- Collect feedback and improve model robustness
Research Paper Overview
Signal-Based Malware Classification Using 1D CNNs
Summary
This paper proposes resizing malware binaries into 1D signals instead of 2D images to reduce information loss and quantisation noise. It adapts 2D CNN architectures and develops a bespoke 1D CNN based on ResNet and squeeze-and-excitation layers to classify malware more effectively. Evaluated on the MalNet dataset, the approach achieves state-of-the-art F1 scores for binary, type, and family level malware classification, improving detection of obfuscated malware.