{
  "id": 13485,
  "title": "Dealing with Compressed Binary",
  "url": "/competitions/malware-classification/discussion/13485",
  "author_name": "",
  "post_date": "2015-04-18T11:25:05.590Z",
  "votes": null,
  "comment_count": 1,
  "views": 554,
  "content": "<p>I still find it impossible to nail down the recognition of compressed binary using packing methods (e.g. aspack, etc.). &nbsp;Wonder how the leaders are magically coping with these recognition especially in the 30% data.</p>\n<p>Are you blending features (ngram with asm opcodes?). &nbsp;opcode features would not suffice and my experiment with ngram performs poorly. &nbsp;Also are you able to unpack without the PE header? &nbsp;</p>\n<p>Some of the compressed binary files are as follows:</p>\n<p>utC4VEjyhfxJlw7ZrITF.asm (using UPX)</p>\n<p>MpZc1heaWnlgIiFQDfyV.asm (using aspack)</p>\n<p>Without unpacking the binary, can your recognition engine really uncovers the identity of the virus?</p>\n<p>Appreciate the sharing. &nbsp; Forgotten to choose the submission file and drop 100+ position... sign... &nbsp;Thanks Kaggle for the competition.</p>",
  "messages": [
    {
      "id": "72264",
      "postDate": "04/18/2015 11:25:05",
      "content": "<p>I still find it impossible to nail down the recognition of compressed binary using packing methods (e.g. aspack, etc.). &nbsp;Wonder how the leaders are magically coping with these recognition especially in the 30% data.</p>\n<p>Are you blending features (ngram with asm opcodes?). &nbsp;opcode features would not suffice and my experiment with ngram performs poorly. &nbsp;Also are you able to unpack without the PE header? &nbsp;</p>\n<p>Some of the compressed binary files are as follows:</p>\n<p>utC4VEjyhfxJlw7ZrITF.asm (using UPX)</p>\n<p>MpZc1heaWnlgIiFQDfyV.asm (using aspack)</p>\n<p>Without unpacking the binary, can your recognition engine really uncovers the identity of the virus?</p>\n<p>Appreciate the sharing. &nbsp; Forgotten to choose the submission file and drop 100+ position... sign... &nbsp;Thanks Kaggle for the competition.</p>",
      "rawMarkdown": "",
      "votes": null
    },
    {
      "id": "72290",
      "postDate": "04/18/2015 14:36:07",
      "content": "<p>&quot;Without unpacking the binary, can your recognition engine really uncovers the identity of the virus?&quot;</p>\n<p>I would think you can; even compressed/encrypted a signature remains of what was encrypted; with a sufficient large examples of what those signatures look like it should be easy to classify them.</p>\n<p>In fact my entries into this particular event was along this line of reasoning with very good results --unfortunately I was a late comer to the contest and was not able to send a fully trained system...</p>",
      "rawMarkdown": "",
      "votes": null
    }
  ],
  "comments": [
    {
      "id": 72290,
      "author_name": "spaceman",
      "author_url": "",
      "post_date": "04/18/2015 14:36:07",
      "content": "<p>&quot;Without unpacking the binary, can your recognition engine really uncovers the identity of the virus?&quot;</p>\n<p>I would think you can; even compressed/encrypted a signature remains of what was encrypted; with a sufficient large examples of what those signatures look like it should be easy to classify them.</p>\n<p>In fact my entries into this particular event was along this line of reasoning with very good results --unfortunately I was a late comer to the contest and was not able to send a fully trained system...</p>",
      "votes": null,
      "replies": []
    }
  ],
  "raw_markdown_by_id": {
    "72264": "",
    "72290": ""
  },
  "source": "meta"
}