返回
A novel deep framework for dynamic malware detection based on API sequence intrinsic features
DOI:10.1016/j.cose.2022.102686.png)
摘要
En 中文
Dynamic malware detection executes the software in a secured virtual environment and monitors its runtime behavior. This technique widely uses API sequence analysis to identify whether the running software is malicious or not. However, existing solutions typically only consider the API name or frequency of API usage, and the feature mining of API sequence is not sufficient, which leads some malware to escape from being detected. In this paper, we propose a novel malware detection framework using deep learning models to capture and combine more meaningful features which are called intrinsic features of the API sequence. Specifically, we first apply embedding and convolutional layers to conduct a joint representation of multiple APIs to represent the software behavior. Secondly, we use the category, action, and operation object of the API to represent the semantic information of each API call. Finally, we use the Bi-LSTM module to mine the relationship information between APIs. Our proposed model achieves an accuracy of 0.9731 and an F1-score of 0.9724 on a large real dataset, which outperforms baselines significantly. We also conduct ablation studies to prove the effectiveness of our intrinsic features.(c) 2022 Elsevier Ltd. All rights reserved.
Keyword:
Malware detection
API sequence
Deep learning
Intrinsic features
Feature fusion
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
引用论文
Image-Based malware classification using ensemble of CNN architectures (IMCEC)
COMPUTERS & SECURITY
IF5.4
Android Malware Familial Classification and Representative Sample Selection via Frequent Subgraph Analysis基于频繁子图分析的Android恶意软件家族分类及代表性样本选择
Blood Pressure and Anthropometric Differences in Regularly Exercising and Nonexercising Black Adults
Challenge of Ziehl-Neelsen stain for Basidiobolomycosis diagnosis in Indonesia: A unique case report
MalDAE: Detecting and explaining malware based on correlation and fusion of static and dynamic characteristicsMalDAE: 基于静态和动态特征的相关性和融合的恶意软件检测和解释
COMPUTERS & SECURITY
IF5.4

