Towards Light-Weight Deep Learning Based Malware Detection

Towards Light-Weight Deep Learning Based Malware Detection
复制标题

DOI:
10.1109/compsac.2018.00092
复制
发表时间:
2018-07
期刊:
2018 IEEE 42nd Annual Computer Software and Applications Conference (COMPSAC)
影响因子:
--
通讯作者:
Zeliang Kan;Haoyu Wang;Guoai Xu;Yao Guo;Xiangqun Chen
Zeliang Kan;Haoyu Wang;Guoai Xu;Yao Guo;Xiangqun Chen
中科院分区:
其他
文献类型:
--
作者:
Zeliang Kan;Haoyu Wang;Guoai Xu;Yao Guo;Xiangqun Chen

文献摘要

被引文献

相似文献

大量的恶意软件继续威胁着操作系统和网络的安全。传统的恶意软件检测方法无法满足检测多态和新样本的要求。现有的基于神经网络的检测方法性能较好,但在特征提取和训练方面花费的时间较多。本文提出了一种基于深度卷积神经网络(CNN)的轻型PC恶意软件检测系统。我们系统的原始输入是由指令分析器根据指令的不同功能生成的分组指令序列。该网络将自动从分组指令序列中学习恶意软件的特征。实验结果表明,在包含大约7万个样本的大型数据集中,我们的检测系统可以达到95%的总体准确率。我们的单卷积层系统的训练时间仅为10小时左右,比传统方法减少了一个数量级。
The explosive amount of malware continues threating the security of operating systems and networks. Traditional malware detection approaches fail to meet the requirements of detecting polymorphic and new samples. Existing neural network based detection approaches performs better, but consuming much more time in both feature extraction and training. In this paper, we propose a light-weight PC malware detection system which is based on deep convolutional neural network (CNN). The raw inputs of our system are sequences of grouped instructions, which were generated by our Instruction Analyzer in according to different functionalities of the instructions. The network will automatically learn features of malware from the grouped instruction sequences. The experiment results suggest that in a large dataset which contains roughly 70,000 samples, our detection system can achieve an overall accuracy of 95\%. The training time of our system with single convolutional layer was only about 10 hours, which is one order of magnitude less than traditional methods.