An Attention Mechanism for Visualizing Word Weights in Source Code of PowerShell Samples: Experimental Results and Analysis

An Attention Mechanism for Visualizing Word Weights in Source Code of PowerShell Samples: Experimental Results and Analysis
复制标题

PowerShell示例源代码中词权重可视化的注意力机制:实验结果与分析

DOI:
10.1007/978-3-031-20029-8_11
复制
发表时间:
2022
期刊:
Advances on Broad-Band Wireless Computing, Communication and Applications
影响因子:
--
通讯作者:
Mimura Mamoru
Mimura Mamoru
中科院分区:
--
文献类型:
--
作者:
Mezawa Yuki;Mimura Mamoru

文献摘要

相似文献

已经研究了利用AI作为恶意软件检测技术的方法,这对于恶意PowerShell脚本的检测也是如此。以前的研究提出了使用深度学习和机器学习来检测恶意PowerShell脚本的模型,并取得了很高的检测率。然而,这些研究都集中在提高恶意PowerShell脚本的检测率。因此,检测模型确定恶意和良性PowerShell样本的原因尚不清楚。在这项研究中,我们使用的注意力机制,可视化的话是重要的恶意PowerShell脚本检测模型。然后,我们分析了每个样本分类结果的重要词的分布。实验结果表明,分类良性或恶意PowerShell脚本的单词存在显着差异。此外,错误分类的样本通常包含在相反类别中被强调的单词。
Methods that utilize AI as a detection technique for malware have been studied, and this is also true for the detection of malicious PowerShell scripts. Previous studies have proposed models that use deep learning and machine learning to detect malicious PowerShell scripts and have achieved high detection rates. However, these studies have focused on improving the detection rate of malicious PowerShell scripts. Therefore, the reasons why the detection models are determining malicious and benign PowerShell samples are unclear. In this study, we use the attention mechanism to visualize the words that are important to the malicious PowerShell scripts detection model. Then, we analyze the distribution of important words for each sample classification result. The experimental results show that there were significant differences in the words that classify benign or malicious PowerShell scripts. In addition, the misclassified samples often contain words that were emphasized in the opposite class.