基于机器学习的Windows恶意软件分析与检测关键技术研究
批准号:
62102190
项目类别:
青年科学基金项目(C类)
资助金额:
30.0 万元
负责人:
陈治国
依托单位:
学科分类:
网络与系统安全
结题年份:
2024
批准年份:
2021
项目状态:
已结题
项目参与者:
陈治国
中文摘要
机器学习技术的发展,为恶意软件的准确检测提供了一条非常具有发展前景的途径。然而,多态及变形等技术的流行极大地挑战了基于此类技术的静态检测效果。同时,动态检测方案需要大量的时间开销,无法解决检测的实时性问题。为此,本项目拟以恶意软件的动、静态特征为基础,通过将机器学习与特征工程等技术应用于Windows恶意软件检测领域,注重兼顾检测模型的复杂度、可解释性、精度及时间效率等设计需求,形成一套动、静态检测的集成方案。重点研究:(1)基于恶意软件检测动、静态特征提取的特征目录构建;(2)基于特征工程技术的特征预处理、特征选择与降维;(3)基于具有模型可解释特性的树结构算法的动、静态检测集成方案的分析、实现及检测效果评价等内容。本项目的实施将推动恶意软件检测朝着更加实用化的方向发展,使理论成果更好地满足实际应用需求。
英文摘要
The development of machine learning technology provides a very promising way for the malware detection system to accurately detect malware. However, the popularity of technologies such as polymorphism and metamorphic has challenged the effectiveness of static malware detection. Meanwhile, dynamic detection is costly and cannot solve the real-time detection problem. Therefore, based on the dynamic and static features of malware, this project intends to apply machine learning and feature engineering technology to the field of Windows malware detection, and to pay attention to the complexity, interpretability, accuracy, and time efficiency of the detection model, to build a dynamic and static integration detection scheme. The key research of this project will focus on (1) The construction of feature directory based on the dynamic and static feature extraction; (2) Feature engineering technology-based feature preprocessing, feature selection, and dimension reduction; (3) Analysis, implementation, and evaluation of the detection effect of the dynamic and static detection integration scheme based on tree structure algorithms with model interpretable characteristics. The implementation of this project will promote the development of malware detection in a more practical direction so that the theoretical results can better meet the needs of practical applications.
随着新型恶意软件及潜在恶意程序的快速增长,恶意软件检测对速度与精度的需求愈发迫切。然而,现有检测技术面临诸多挑战:多态、变形及代码混淆等技术对静态检测精度构成极大挑战,而动态检测依赖于生成和处理复杂程序行为报告,导致时间开销巨大,难以满足快速检测的实际需求。针对上述问题,本项目从以下几个方面提出解决方案:首先,通过静态分析方法提取恶意软件二进制和汇编中的有效特征,构建标准化的静态特征信息目录。同时,采用静态恶意软件可视化表征的方法,克服数据匿名化和混淆技术对静态分析精度的影响。其次,在动态分析中,聚焦API调用的行为特征,构建动态特征的行为语义表示,以简化对复杂行为的建模需求,提高动态检测方案的实际部署效率。最后,利用特征工程技术对提取的特征进行预处理、选择和降维,以优化检测方法的复杂度、精度和时间效率。本课题通过研究并集成动态与静态检测模块,弥补现有方法的不足,兼顾检测模型的复杂度、可解释性、精度和效率等关键需求。所提出的方案在公开标准数据集上进行了详尽的实验和测试,并与当前先进方法进行了对比,实验结果充分验证了其有效性。此外,在相关信息安全竞赛中,本课题构建的静态与动态检测相结合的集成方案,在检测速度、系统安全和检测覆盖率之间取得平衡,形成一种系统化的威胁响应机制,使理论成果能够更有效地满足实际应用需求。项目资助发表论文共计7篇,其中SCI期刊论文5篇,国际会议论文2篇;获得授权发明专利2项;开发的2套原型系统均荣获国家级竞赛三等奖。项目投入经费共计30万元,支出27.48171万元,各项支出基本与预算相符,剩余经费2.51829万元,将继续用于项目后续研究和论文版面费支出。
国内基金
海外基金