基于图像分析和生成对抗网络的恶意软件检测方法

Yanhua Liu, Jiaqi Li, Baoxu Liu, Xiaoling Gao, Ximeng Liu
{"title":"基于图像分析和生成对抗网络的恶意软件检测方法","authors":"Yanhua Liu, Jiaqi Li, Baoxu Liu, Xiaoling Gao, Ximeng Liu","doi":"10.1002/cpe.7170","DOIUrl":null,"url":null,"abstract":"Malware detection is indispensable to cybersecurity. However, with the advent of new malware variants and scenarios with few and imbalanced samples, malware detection for various complex scenarios has been a very challenging problem. In this article, we propose a malware detection method based on image analysis and generative adversarial networks, named MadInG, which can improve the accuracy of malware detection for insufficient samples, sample imbalance, and new variants scenarios. Specifically, we first generate fixed‐size grayscale images of malware to reduce the workload of feature engineering or the involvement of domain expert knowledge on malware detection. Then we introduce auxiliary classifier generative adversarial networks into malware detection to enhance the generalization ability of the detector. Finally, we construct a variety of malware scenarios and compare our proposed method with existing popular detection methods. Extensive experimental results demonstrate that our method achieves high accuracy and well balance in malware detection for different scenarios, especially, the detection rate of malware variants reaches 99.5%.","PeriodicalId":10584,"journal":{"name":"Concurrency and Computation: Practice and Experience","volume":"42 1","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2022-07-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Malware detection method based on image analysis and generative adversarial networks\",\"authors\":\"Yanhua Liu, Jiaqi Li, Baoxu Liu, Xiaoling Gao, Ximeng Liu\",\"doi\":\"10.1002/cpe.7170\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Malware detection is indispensable to cybersecurity. However, with the advent of new malware variants and scenarios with few and imbalanced samples, malware detection for various complex scenarios has been a very challenging problem. In this article, we propose a malware detection method based on image analysis and generative adversarial networks, named MadInG, which can improve the accuracy of malware detection for insufficient samples, sample imbalance, and new variants scenarios. Specifically, we first generate fixed‐size grayscale images of malware to reduce the workload of feature engineering or the involvement of domain expert knowledge on malware detection. Then we introduce auxiliary classifier generative adversarial networks into malware detection to enhance the generalization ability of the detector. Finally, we construct a variety of malware scenarios and compare our proposed method with existing popular detection methods. Extensive experimental results demonstrate that our method achieves high accuracy and well balance in malware detection for different scenarios, especially, the detection rate of malware variants reaches 99.5%.\",\"PeriodicalId\":10584,\"journal\":{\"name\":\"Concurrency and Computation: Practice and Experience\",\"volume\":\"42 1\",\"pages\":\"\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-07-08\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Concurrency and Computation: Practice and Experience\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1002/cpe.7170\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Concurrency and Computation: Practice and Experience","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1002/cpe.7170","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

恶意软件检测是网络安全不可或缺的一部分。然而,随着新的恶意软件变体和样本较少且不平衡的场景的出现,各种复杂场景的恶意软件检测已经成为一个非常具有挑战性的问题。在本文中,我们提出了一种基于图像分析和生成对抗网络的恶意软件检测方法MadInG,该方法可以提高样本不足、样本失衡和新变体场景下恶意软件检测的准确性。具体来说,我们首先生成固定大小的恶意软件灰度图像,以减少特征工程的工作量或领域专家知识对恶意软件检测的参与。然后,我们将辅助分类器生成对抗网络引入恶意软件检测中,以提高检测器的泛化能力。最后,我们构建了各种恶意软件场景,并将我们提出的方法与现有流行的检测方法进行了比较。大量的实验结果表明,该方法在不同场景的恶意软件检测中具有较高的准确率和较好的平衡性,特别是对恶意软件变体的检测率达到99.5%。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Malware detection method based on image analysis and generative adversarial networks
Malware detection is indispensable to cybersecurity. However, with the advent of new malware variants and scenarios with few and imbalanced samples, malware detection for various complex scenarios has been a very challenging problem. In this article, we propose a malware detection method based on image analysis and generative adversarial networks, named MadInG, which can improve the accuracy of malware detection for insufficient samples, sample imbalance, and new variants scenarios. Specifically, we first generate fixed‐size grayscale images of malware to reduce the workload of feature engineering or the involvement of domain expert knowledge on malware detection. Then we introduce auxiliary classifier generative adversarial networks into malware detection to enhance the generalization ability of the detector. Finally, we construct a variety of malware scenarios and compare our proposed method with existing popular detection methods. Extensive experimental results demonstrate that our method achieves high accuracy and well balance in malware detection for different scenarios, especially, the detection rate of malware variants reaches 99.5%.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Time‐based DDoS attack detection through hybrid LSTM‐CNN model architectures: An investigation of many‐to‐one and many‐to‐many approaches Distributed low‐latency broadcast scheduling for multi‐channel duty‐cycled wireless IoT networks Open‐domain event schema induction via weighted attentive hypergraph neural network Fused GEMMs towards an efficient GPU implementation of the ADER‐DG method in SeisSol Simulation method for infrared radiation transmission characteristics of typical ship targets based on optical remote sensing
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1