An Efficient Transformer Encoder-Based Classification of Malware Using API Calls

An Efficient Transformer Encoder-Based Classification of Malware Using API Calls
复制标题

DOI:
10.1109/hpcc-dss-smartcity-dependsys57074.2022.00137
复制
发表时间:
2022-12
期刊:
2022 IEEE 24th Int Conf on High Performance Computing & Communications; 8th Int Conf on Data Science & Systems; 20th Int Conf on Smart City; 8th Int Conf on Dependability in Sensor, Cloud & Big Data Systems & Application (HPCC/DSS/SmartCity/DependSys)
影响因子:
--
通讯作者:
Chen Li;Zheng Chen;Junjun Zheng
Chen Li;Zheng Chen;Junjun Zheng
中科院分区:
其他
文献类型:
--
作者:
Chen Li;Zheng Chen;Junjun Zheng

文献摘要

相似文献

恶意软件是计算机系统的主要安全威胁,并严重影响系统的可靠性。基于递归神经网络(RNN)的方法在近几十年来基于API调用的恶意软件检测中引起了广泛的关注。然而,传统的RNN在处理长API调用序列时存在梯度消失问题。本文提出了一种基于Transformer编码器的模型MalTransEn,以解决RNN的局限性。特别地,提出了一种新的基于Transformer编码器的分类器,通过学习API调用序列中的交互特征来对恶意软件进行分类。实验结果表明,该架构表现良好,优于其他基于深度学习的基线。
Malware is a major security threat to computer systems and significantly impacts system reliability. Recurrent neural network (RNN)-based methods have attracted much attention in API call-based malware detection in recent decades. However, traditional RNNs have a gradient vanishing problem when processing long API call sequences. This paper proposes a transformer encoder-based model, called MalTransEn, to solve the limitations of RNN. In particular, a novel transformer encoder-based classifier is proposed to classify malware by learning interaction features in sequences of API calls. Experimental results showed that the proposed architecture performed well and outperformed other deep learning-based baselines.