FindMal: A file-to-file social network based malware detection framework

FindMal: A file-to-file social network based malware detection framework
复制标题

DOI:
10.1016/j.knosys.2016.09.004
复制
发表时间:
2016-11
期刊:
Knowl. Based Syst.
影响因子:
--
通讯作者:
Ming Ni;Tao Li;Qianmu Li;Hong Zhang;Yanfang Ye
Ming Ni;Tao Li;Qianmu Li;Hong Zhang;Yanfang Ye
中科院分区:
其他
文献类型:
--
作者:
Ming Ni;Tao Li;Qianmu Li;Hong Zhang;Yanfang Ye

文献摘要

被引文献

相似文献

恶意软件程序的快速发展对计算机和互联网安全构成了严重威胁。因此,它激励反恶意软件供应商和研究人员开发能够保护用户免受新威胁的新方法。现有的恶意软件检测器大多使用监督学习算法单独处理文件样本。然而,忽略文件样本之间的关系限制了恶意软件检测器的能力。本文基于文件到文件社交网络,提出了一种新的恶意软件检测框架FindMal(基于文件到文件社交网络的恶意软件检测框架),包括基于图的特征提取、标签传播算法和主动学习策略。首先为每个文件节点选择最近邻作为相邻节点,构建kNN文件关系图。提出了三种文件关系图特征来对代表性文件样本进行采样以进行标记。然后,应用标签传播算法将标签信息从标记的文件样本传播到未标记的文件,以了解一个未知文件被分类为恶意或良性的概率。采用批量模式主动学习方法来降低标签成本并提高标签传播的性能。对从反恶意软件公司获得的真实大规模数据集进行了综合实验。结果表明,我们提出的 FindMal 在对文件样本进行分类方面优于其他现有检测模型。
The rapid development of malicious software programs has posed severe threats to Computer and Internet security. Therefore, it motivates anti-malware vendors and researchers to develop novel methods which are capable of protecting users against new threats. Existing malware detectors mostly treat the file samples separately using supervised learning algorithms. However, ignoring the relationship among file samples limits the capability of malware detectors. In this paper, based on the file-to-file social network, we present a new malware detection framework, FindMal(File-to-File SocialNetwork basedMalware Detection Framework), including graph-based features extraction, Label Propagation algorithm, and active learning strategy. Nearest neighbors are first chosen as adjacent nodes for each file node to constructkNN file relation graph. Three file relation graph features are proposed to sample the representative file samples for labeling. Then, Label Propagation algorithm, which propagates the label information from labeled file samples to unlabeled files, is applied to learn the probability that one unknown file is classified as malicious or benign. A batch mode active learning method is employed to reduce the labeling cost and improve the performance of Label Propagation. Comprehensive experiments on real and large scale dataset obtained from an anti-malware company are performed. The results demonstrate that our proposed FindMal outperforms other existing detection models in classifying file samples.