PackHero: A Scalable Graph-based Approach for Efficient Packer Identification

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Di Gennaro, Marco, D'Onghia, Mario, Polino, Mario, Zanero, Stefano, Carminati, Michele
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912472662802432
author Di Gennaro, Marco
D'Onghia, Mario
Polino, Mario
Zanero, Stefano
Carminati, Michele
author_facet Di Gennaro, Marco
D'Onghia, Mario
Polino, Mario
Zanero, Stefano
Carminati, Michele
contents Anti-analysis techniques, particularly packing, challenge malware analysts, making packer identification fundamental. Existing packer identifiers have significant limitations: signature-based methods lack flexibility and struggle against dynamic evasion, while Machine Learning approaches require extensive training data, limiting scalability and adaptability. Consequently, achieving accurate and adaptable packer identification remains an open problem. This paper presents PackHero, a scalable and efficient methodology for identifying packers using a novel static approach. PackHero employs a Graph Matching Network and clustering to match and group Call Graphs from programs packed with known packers. We evaluate our approach on a public dataset of malware and benign samples packed with various packers, demonstrating its effectiveness and scalability across varying sample sizes. PackHero achieves a macro-average F1-score of 93.7% with just 10 samples per packer, improving to 98.3% with 100 samples. Notably, PackHero requires fewer samples to achieve stable performance compared to other Machine Learning-based tools. Overall, PackHero matches the performance of State-of-the-art signature-based tools, outperforming them in handling Virtualization-based packers such as Themida/Winlicense, with a recall of 100%.
format Preprint
id arxiv_https___arxiv_org_abs_2506_00659
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle PackHero: A Scalable Graph-based Approach for Efficient Packer Identification
Di Gennaro, Marco
D'Onghia, Mario
Polino, Mario
Zanero, Stefano
Carminati, Michele
Cryptography and Security
Machine Learning
Anti-analysis techniques, particularly packing, challenge malware analysts, making packer identification fundamental. Existing packer identifiers have significant limitations: signature-based methods lack flexibility and struggle against dynamic evasion, while Machine Learning approaches require extensive training data, limiting scalability and adaptability. Consequently, achieving accurate and adaptable packer identification remains an open problem. This paper presents PackHero, a scalable and efficient methodology for identifying packers using a novel static approach. PackHero employs a Graph Matching Network and clustering to match and group Call Graphs from programs packed with known packers. We evaluate our approach on a public dataset of malware and benign samples packed with various packers, demonstrating its effectiveness and scalability across varying sample sizes. PackHero achieves a macro-average F1-score of 93.7% with just 10 samples per packer, improving to 98.3% with 100 samples. Notably, PackHero requires fewer samples to achieve stable performance compared to other Machine Learning-based tools. Overall, PackHero matches the performance of State-of-the-art signature-based tools, outperforming them in handling Virtualization-based packers such as Themida/Winlicense, with a recall of 100%.
title PackHero: A Scalable Graph-based Approach for Efficient Packer Identification
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2506.00659