返回
Malicious Code Detection: Run Trace Output Analysis by LSTM
DOI:10.1109/ACCESS.2021.3049200.png)
摘要
En 中文
Malicious software threats and their detection have been gaining importance as a subdomain of information security due to the expansion of ICT applications in daily settings. A major challenge in designing and developing anti-malware systems is the coverage of the detection, particularly the development of dynamic analysis methods that can detect polymorphic and metamorphic malware efficiently. In the present study, we propose a methodological framework for detecting malicious code by analyzing run trace outputs by Long Short-Term Memory (LSTM). We developed models of run traces of malicious and benign Portable Executable (PE) files. We created our dataset from run trace outputs obtained from dynamic analysis of PE files. The obtained dataset was in the instruction format as a sequence and was called Instruction as a Sequence Model (ISM). By splitting the first dataset into basic blocks, we obtained the second one called Basic Block as a Sequence Model (BSM). The experiments showed that the ISM achieved an accuracy of 87.51% and a false positive rate of 18.34%, while BSM achieved an accuracy of 99.26% and a false positive rate of 2.62%.
Keyword:
Malware
Machine learning
Feature extraction
Static analysis
Semantics
Operating systems
Natural language processing
Dynamic analysis
LSTM
malware detection
natural language processing
run trace
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
3.6
论文数:
9.8W
被引数:
29.4W
机构
引用论文
An Enhanced Stacked LSTM Method With No Random Initialization for Malware Threat Hunting in Safety and Time-Critical Systems一种增强的无随机初始化的堆叠LSTM方法,用于安全和时间关键系统中的恶意软件威胁搜索
A six-direction absolute displacement sensor for time-delayed control based on quasi-zero-stiffness property一种基于准零刚度特性的时滞控制六方向绝对位移传感器

