Skip to main content
Kent Academic Repository

Packer Identification using Grayscale Images of Binaries

Mondon, Pierre, de Lemos, Rogério (2026) Packer Identification using Grayscale Images of Binaries. In: 2026 International Conference on Cyber Security and Resilience. (In press) (KAR id:114271)

Abstract

Malware frequently uses packing techniques, making the analysis of packed executables essential for developing robust malware defences. This paper focuses on the identification of packers used in MS Windows binaries. Our approach first converts these binaries into grayscale images of 128 pixels in width and arbitrary height, and then applies convolutional neural networks (CNN), as a sliding window, along the vertical dimension of the image for extracting a sequence of high-level features. Finally, this sequence is fed into a recurrent neural network (RNN) that classifies the binary image. Using a CNN to extract features eliminates the need for manual feature engineering, which is time-consuming and resource-intensive. An advantage of our approach is that we do not rely on code analysis, hence removing dependencies on third-party software, which results in our method being able to handle all files. Another advantage of our approach, compared with traditional CNNs, is that it does not require image resizing, which prevents information loss. Overall, our results can improve the state-of-the-art by up to 23.506\% while removing third-party dependencies on external software to analyse code.

Item Type: Conference proceeding
Uncontrolled keywords: malware, packer, binary analysis, obfuscation, deep learning
Subjects: Q Science > QA Mathematics (inc Computing science) > QA 76 Software, computer programming, > QA76.76 Computer software
Institutional Unit: Schools > School of Computing
Institutes > Institute of Cyber Security for Society
Former Institutional Unit:
There are no former institutional units.
Depositing User: Rogerio De Lemos
Date Deposited: 01 May 2026 09:41 UTC
Last Modified: 05 May 2026 18:51 UTC
Resource URI: https://kar.kent.ac.uk/id/eprint/114271 (The current URI for this page, for reference purposes)

University of Kent Author Information

Mondon, Pierre.

Creator's ORCID:
CReDIT Contributor Roles:

de Lemos, Rogério.

Creator's ORCID: https://orcid.org/0000-0002-0281-6308
CReDIT Contributor Roles:
  • Depositors only (login required):

Total unique views of this page since July 2020. For more details click on the image.