TY - GEN
T1 - A Malware Family Classification Method Based on the Point Cloud Model DGCNN
AU - Ding, Yuxin
AU - Zhou, Zihan
AU - Qian, Wen
N1 - Publisher Copyright:
© 2021, Springer Nature Switzerland AG.
PY - 2021
Y1 - 2021
N2 - Currently the number and types of malware increase rapidly, and traditional malware family classification technologies become more and more difficult to deal with them. With the rise of deep learning technology, various malware family classification methods based on deep learning technologies have been proposed, and these methods have achieved excellent results. One problem of most deep learning based models is that they need the input data should have a fixed data relationship. However, no prior knowledge shows that there existed such fixed data relationships. Another problem is that in present the characteristics of malware are often be expressed as binary sequences, API call sequences, Opcode sequences etc. These features are low-level features, and are not easy to be understood. To solve these issues, we propose a method based on the point cloud model to detect malware families. In the point cloud model each malware behavior is mapped to a point in the high-dimensional space. The point cloud model can learn the relationships among these behaviors. The method avoids predetermining the relationships among data, which is more reasonable for malware detection. In addition, we use the behavior report to describe malware behavior features, which can be easily understand by people. We apply this method to classify malware families. The experimental results show that the average precision and recall for family classification reach 96.67%, 96.58%, surpassing traditional deep learning models such as LSTM, CNN, and LSTM with attention mechanism.
AB - Currently the number and types of malware increase rapidly, and traditional malware family classification technologies become more and more difficult to deal with them. With the rise of deep learning technology, various malware family classification methods based on deep learning technologies have been proposed, and these methods have achieved excellent results. One problem of most deep learning based models is that they need the input data should have a fixed data relationship. However, no prior knowledge shows that there existed such fixed data relationships. Another problem is that in present the characteristics of malware are often be expressed as binary sequences, API call sequences, Opcode sequences etc. These features are low-level features, and are not easy to be understood. To solve these issues, we propose a method based on the point cloud model to detect malware families. In the point cloud model each malware behavior is mapped to a point in the high-dimensional space. The point cloud model can learn the relationships among these behaviors. The method avoids predetermining the relationships among data, which is more reasonable for malware detection. In addition, we use the behavior report to describe malware behavior features, which can be easily understand by people. We apply this method to classify malware families. The experimental results show that the average precision and recall for family classification reach 96.67%, 96.58%, surpassing traditional deep learning models such as LSTM, CNN, and LSTM with attention mechanism.
KW - Deep learning
KW - Machine learning
KW - Malware
KW - Point cloud
UR - https://www.scopus.com/pages/publications/85123313325
U2 - 10.1007/978-3-030-92708-0_13
DO - 10.1007/978-3-030-92708-0_13
M3 - 会议稿件
AN - SCOPUS:85123313325
SN - 9783030927073
T3 - Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
SP - 210
EP - 221
BT - Network and System Security - 15th International Conference, NSS 2021, Proceedings
A2 - Yang, Min
A2 - Chen, Chao
A2 - Liu, Yang
PB - Springer Science and Business Media Deutschland GmbH
T2 - 15th International Conference on Network and System Security, NSS 2021
Y2 - 23 October 2021 through 23 October 2021
ER -