Detection of Malicious Code Variants Based on Deep Learning

Detection of Malicious Code Variants Based on Deep Learning
复制标题

DOI:
10.1109/tii.2018.2822680
复制
发表时间:
2018-07-01
影响因子:
12.3
通讯作者:
Chen, Jinjun
Chen, Jinjun
中科院分区:
计算机科学1区
文献类型:
--
作者:
Cui, Zhihua;Xue, Fei;Chen, Jinjun

文献摘要

被引文献

相似文献

随着互联网的发展,恶意代码攻击呈指数级增长,恶意代码变体已成为互联网安全的主要威胁。检测恶意代码变体的能力对于防止安全漏洞、数据盗窃和其他危险至关重要。目前的恶意代码识别方法检测精度差,检测速度慢。本文提出了一种利用深度学习改进恶意软件变体检测的新方法。在之前的研究中,深度学习在图像识别方面表现出优异的性能。为了实现我们提出的检测方法,我们将恶意代码转换为灰度图像。然后,使用卷积神经网络(CNN)对图像进行识别和分类,该网络可以自动提取恶意图像的特征。此外,我们利用bat算法来解决不同恶意软件家族之间的数据不平衡问题。为了测试我们的方法,我们对视觉研究实验室的恶意软件图像数据进行了一系列实验。实验结果表明,与其他恶意软件检测模型相比,我们的模型具有良好的准确性和速度。
With the development of the Internet, malicious code attacks have increased exponentially, with malicious code variants ranking as a key threat to Internet security. The ability to detect variants of malicious code is critical for protection against security breaches, data theft, and other dangers. Current methods for recognizing malicious code have demonstrated poor detection accuracy and low detection speeds. This paper proposed a novel method that used deep learning to improve the detection of malware variants. In prior research, deep learning demonstrated excellent performance in image recognition. To implement our proposed detection method, we converted the malicious code into grayscale images. Then, the images were identified and classified using a convolutional neural network (CNN) that could extract the features of the malware images automatically. In addition, we utilized a bat algorithm to address the data imbalance among different malware families. To test our approach, we conducted a series of experiments on malware image data from Vision Research Lab. The experimental results demonstrated that our model achieved good accuracy and speed as compared with other malware detection models.