Clustering Malware at Scale: A First Full-Benchmark Study

📅 2025-11-28
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
Existing malware clustering research suffers from three key limitations: (1) neglect of benign samples, (2) reliance on small, proprietary datasets, and (3) absence of systematic evaluation on comprehensive, publicly available benchmarks. Method: This work presents the first large-scale malware clustering study conducted on the full Bodmas and Ember benchmark datasets. It introduces benign samples to formulate a realistic mixed-cluster task and systematically evaluates prominent clustering algorithms—including K-Means, BIRCH, DBSCAN, and Hierarchical Agglomerative Clustering (HAC). Contribution/Results: Experiments show that K-Means and BIRCH significantly outperform alternatives; incorporating benign samples does not degrade clustering quality, confirming practical feasibility and robustness. Substantial performance variation across datasets necessitates redefining current best practices. This study establishes a reproducible, scalable benchmark framework and methodological guidance for unsupervised malware analysis.

Technology Category

Machine Learning: ClusteringData Mining & Knowledge Management: Anomaly/Outlier DetectionSearch and Optimization: Metareasoning and Metaheuristics

Application Category

Web Mining and Content Analysis: Normalization, clustering, classification, and summarization of Web textSecurity and Privacy: Large-scale security measurementsGraph Algorithms and Modeling for the Web: Efficient manipulation of static and dynamic Web-related graphs
📝 Abstract
Recent years have shown that malware attacks still happen with high frequency. Malware experts seek to categorize and classify incoming samples to confirm their trustworthiness or prove their maliciousness. One of the ways in which groups of malware samples can be identified is through malware clustering. Despite the efforts of the community, malware clustering which incorporates benign samples has been under-explored. Moreover, despite the availability of larger public benchmark malware datasets, malware clustering studies have avoided fully utilizing these datasets in their experiments, often resorting to small datasets with only a few families. Additionally, the current state-of-the-art solutions for malware clustering remain unclear. In our study, we evaluate malware clustering quality and establish the state-of-the-art on Bodmas and Ember - two large public benchmark malware datasets. Ours is the first study of malware clustering performed on whole malware benchmark datasets. Additionally, we extend the malware clustering task by incorporating benign samples. Our results indicate that incorporating benign samples does not significantly degrade clustering quality. We find that there are significant differences in the quality of the created clusters between Ember and Bodmas, as well as a private industry dataset. Contrary to popular opinion, our top clustering performers are K-Means and BIRCH, with DBSCAN and HAC falling behind.
Problem

Research questions and friction points this paper is trying to address.

Evaluating malware clustering quality on large public benchmark datasets
Incorporating benign samples into malware clustering analysis
Establishing state-of-the-art clustering methods for malware classification
Innovation

Methods, ideas, or system contributions that make the work stand out.

Used K-Means and BIRCH for malware clustering
Evaluated clustering on full Bodmas and Ember datasets
Incorporated benign samples into malware clustering task
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
M
Martin Mocko
Faculty of Information Technology, Brno University of Technology, Brno, Czechia
Jakub Ševcech
Jakub Ševcech
Swiss Re
Daniela Chudá
Daniela Chudá
Kempelen Institute of Intelligent Technologies
securityuser authenticationuser modellingplagiarism