Title: Classification of malware family in large executable files using NeASA-Net in MapReduce framework

Authors: Manoj D. Shelar; S. Srinivasa Rao

Addresses: Department of Computer Science and Engineering, Koneru Lakshmaiah Education Foundation, Greenfields, Vaddeswaram, Guntur-522502, India ' Department of Computer Science and Engineering, Koneru Lakshmaiah Education Foundation, Greenfields, Vaddeswaram, Guntur-522502, India

Abstract: This paper proposes the neuron attention stacked autoencoder (NeASA-Net) to classify the malware family from the executable files. The classification process is done in the MapReduce framework. At first, the accumulated input executable files are subjected to the mapper phase. Here, the features, like opcode 4-gram, API 4-gram, file size, and PE section size are determined. Then, the determined features are merged and subjected to malware family classification using NeASA-Net in the reducer phase. The NeASA-Net is introduced by combining deep stacked autoencoder (DSA) with a neuron attention stage-by-stage net (NASNet). Malware is finally classified as Gatak, Tracur, Obfuscator.ACY, Simda, Kelihos_ver1, Vundo, Lollipop, ramnit, and Kelihos_ver3. The performance of the NeASA-Net model is validated by comparing it with traditional detection models. Here, the NeASA-Net model achieved superior performance with an accuracy of 92.77%, a true positive rate (TPR) of 95.98%, and a false positive rate (FPR) of 6.54%.

Keywords: neuron attention stacked autoencoder; NeASA-Net; deep stacked autoencoder; DSA; fractional calculus; neuron attention stage-by-stage net; NASNet; cyber security.

DOI: 10.1504/IJAMECHS.2025.149352

International Journal of Advanced Mechatronic Systems, 2025 Vol.12 No.4, pp.245 - 257

Received: 24 Aug 2024
Accepted: 03 Jan 2025

Published online: 27 Oct 2025 *

Full-text access for editors Full-text access for subscribers Purchase this article Comment on this article