返回
DawnGNN: Documentation augmented windows malware detection using graph neural network
DOI:10.1016/j.cose.2024.103788.png)
摘要
En 中文
Application Program Interface (API) calls are widely used in dynamic Windows malware analysis to characterize the run-time behavior of malware. Researchers have proposed various approaches to mine semantic information from API calls to improve the performance of malware analysis. However, with increasingly sophisticated malware, the exploration of new semantic dimensions for API calls is never-ending. In this paper, we find that the official Windows API documentation is an unexplored information source in malware detection. Therefore, we propose a novel documentation -augmented Windows malware detection framework DawnGNN using the pre -trained semantic enhanced mechanism and graph neural network. First, it converts the API sequences into API graphs for further contextual information extraction. Next, we crawl API documentation from the official website and employ the pre -trained Bidirectional Encoder Representations from Transformers (BERT) model to encode functionality descriptions as API embeddings. Finally, it feeds the API graphs with API node attributes into the Graph Attention Network (GAT) classifier to perform Windows malware detection. Moreover, we verify the effectiveness of DawnGNN on three public datasets. Experimental results demonstrate the effectiveness of DawnGNN. Semantic information from the official API documentation is promising in the Windows malware detection domain.
Keyword:
Windows malware detection
Graph neural network
BERT-based embedding
Dynamic API call
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
引用论文
Android Malware Familial Classification and Representative Sample Selection via Frequent Subgraph Analysis基于频繁子图分析的Android恶意软件家族分类及代表性样本选择
DMalNet: Dynamic malware analysis based on API feature engineering and graph learningDMalNet: 基于API特征工程和图学习的动态恶意软件分析
COMPUTERS & SECURITY
IF5.4
Challenge of Ziehl-Neelsen stain for Basidiobolomycosis diagnosis in Indonesia: A unique case report
GDroid: Android malware detection and classification with graph convolutional networkGDroid: 使用图卷积网络进行Android恶意软件检测和分类
COMPUTERS & SECURITY
IF5.4
A novel deep framework for dynamic malware detection based on API sequence intrinsic features一种基于API序列内在特征的深度动态恶意软件检测框架
COMPUTERS & SECURITY
IF5.4
ENIMANAL: Augmented cross-architecture IoT malware analysis using graph neural networksENIMANAL: 使用图神经网络进行增强的跨架构IoT恶意软件分析
COMPUTERS & SECURITY
IF5.4

