arrow
返回

A feature-hybrid malware variants detection using CNN based opcode embedding and BPNN based API embedding

delete2019-07-01
delete71
PRE
AI
张
张继信 (Jixin Zhang)
Z
Zheng Qin *
H
Hui Yin
L
Lu Ou
K
Kehuan Zhang
DOI:10.1016/j.cose.2019.04.005delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Being able to detect malware variants is a critical problem due to the potential damages and the fast paces of new malware variations. According to surveys from McAfee and Symantec, there is about 69 new instances of malware detected in every minutes, and more than 50% of them are variants of existing ones. Such a large volume of diversified malware variants has forced researches to investigate new methods based on common behavior patterns using machine learning. However, such methods only use single type of features such as opcode, system call, etc., which faces several drawbacks: Firstly, the methods lose a part of useful information since different types of features show different characteristics of malware. This severely limits detection precision and recall. Secondly, the accuracy and the speed (as a trade-off) of such methods fail to meet users' expectation. Thirdly, the precise classification of malware families is still a hard problem and is also important in malware analysis. In this work, we propose a feature-hybrid malware variants detection approach which integrates multi-types of features to address these challenges. We first represent opcodes by a bi-gram model and represent API calls by a vector of frequency, then we use principal component analysis to optimize the representations to improve the convergence speed, the next we adopt a convolutional neural network and a back-propagation neural network for opcode based feature embedding and API based feature embedding respectively, and finally we embed these features to train a detection model by using softmax. Theoretical analysis and real-life experimental results show the efficiency and optimization of our approach which achieves more than 95% malware detection accuracy and almost 90% classification accuracy of malware families. The detection speed of our approach is less than 0.1 s. (C) 2019 Elsevier Ltd. All rights reserved.
Keyword:
API call
Back-propagation neural network
Convolutional neural network
Feature-hybrid
Malware variants detection
Malware family classification
Opcode
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

C
Chinese University of Hong Kong
学者数:
3.4W
论文数: 3.2W
被引数: 5.6W
H
hunan university
学者数:
4.5W
论文数: 3.3W
被引数: 70
引用论文

引用论文

err
IF0
err
err0
PREAI
err
err分享
err收藏
Multifrequency EPR Study of Metallofullerenes:  Eu@C82 and Eu@C74
err2004-08-20
err0
PREAI
errHideto Matsuoka; Norio Ozawa; Takeshi Kodama; Hiroyuki Nishikawa; Isao Ikemoto; Koichi Kikuchi; Ko Furukawa; Kazunobu Sato; Daisuke Shiomi; Takeji Takui; Tatsuhisa Kato
err分享
err收藏
Privacy Risk Analysis and Mitigation of Analytics Libraries in the Android Ecosystem
err2020-05-01
err83
errOAAI
errLiu, Xing; Liu, Jiqiang; Zhu, Sencun; Wang, Wei; Zhang, Xiangliang
err分享
err收藏
err分享
err收藏
学者 查看更多内容