MALDC: a depth detection method for malware based on behavior chains

被引:9
|
作者
Zhang, Hao [1 ,2 ]
Zhang, Wenjun [1 ,2 ]
Lv, Zhihan [3 ]
Sangaiah, Arun Kumar [4 ]
Huang, Tao [1 ,2 ]
Chilamkurti, Naveen [5 ]
机构
[1] Cent China Normal Univ, Natl Engn Lab Educ Big Data, Wuhan, Peoples R China
[2] Cent China Normal Univ, Natl Engn Res Ctr E Learning, Wuhan, Peoples R China
[3] Qingdao Univ, Sch Data Sci & Software Engn, Qingdao 266071, Peoples R China
[4] Vellore Inst Technol, Sch Comp Sci & Engn, Vellore 632014, Tamil Nadu, India
[5] La Trobe Univ, Dept Comp Sci & Comp Engn, Melbourne, Vic, Australia
基金
中国国家自然科学基金;
关键词
Malicious behavior; API call sequence; Behavior chain; LSTM;
D O I
10.1007/s11280-019-00675-z
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Malicious behavior detection is a key topic that has been a focus in the field of intrusion detection. Current intrusion detection systems are primarily based on single-point monitoring and detection and cannot detect attack modes with a hidden attack frequency. The idea presented in this paper is the incorporation of API call sequence software into the analysis and the construction of behavior chains to express the behavior patterns in software. This paper introduces related definitions of behavioral points and behaviors and proposes a depth-detection method for malware based on behavior chains (MALDC). The method monitors behavior points based on API calls and then uses the calling sequence of those behavior points at runtime to construct a behavior chain. Finally, we use depth detection method based on long short-term memory(LSTM) to detect malicious behavior from the behavior chains. To verify the performance of the proposed model, we conducted a large experiment on 54,324 malware and 53,361 benign samples collected from Windows systems and used those samples to train and test the model. Comparative verification by using various classifiers showed that the behavior points extracted based on the above method and the constructed behavior chains can be used to recognize malicious behavior at a high recognition rate. The method achieved an accuracy of 98.64% with a false positive rate of less than 2% in the best case, which is a satisfactory recognition rate for detecting malicious software behavior.
引用
收藏
页码:991 / 1010
页数:20
相关论文
共 50 条
  • [21] An in-depth review of machine learning based Android malware detection
    Muzaffar, Ali
    Hassen, Hani Ragab
    Lones, Michael A.
    Zantout, Hind
    [J]. COMPUTERS & SECURITY, 2022, 121
  • [22] A Novel Malware Classification Method Based on Crucial Behavior
    Xiao, Fei
    Sun, Yi
    Du, Donggao
    Li, Xuelei
    Luo, Min
    [J]. MATHEMATICAL PROBLEMS IN ENGINEERING, 2020, 2020
  • [23] A Malware Behavior Analysis Method based on Coupling Degree
    Guo Gang
    Wei Sheng-jun
    [J]. PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON ADVANCES IN MECHANICAL ENGINEERING AND INDUSTRIAL INFORMATICS, 2015, 15 : 582 - 590
  • [24] A Method for Windows Malware Detection Based on Deep Learning
    Xiang Huang
    Li Ma
    Wenyin Yang
    Yong Zhong
    [J]. Journal of Signal Processing Systems, 2021, 93 : 265 - 273
  • [25] A Self-Relocation based Method for Malware Detection
    Zhang, Yu
    Xia, Feng
    [J]. ADVANCES IN MANUFACTURING TECHNOLOGY, PTS 1-4, 2012, 220-223 : 2688 - 2693
  • [26] A NEW MALWARE DETECTION METHOD BASED ON RAW INFORMATION
    Han, Qiao-Ling
    Hao, Yu-Jie
    Zhang, Yan
    Lu, Zhi-Peng
    Zhang, Rui
    [J]. 2008 INTERNATIONAL CONFERENCE ON APPERCEIVING COMPUTING AND INTELLIGENCE ANALYSIS (ICACIA 2008), 2008, : 307 - +
  • [27] An Android Malware Detection Method Based on Feature Codes
    Li, Yiran
    Jin, Zhengping
    [J]. PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON MECHATRONICS, MATERIALS, CHEMISTRY AND COMPUTER ENGINEERING 2015 (ICMMCCE 2015), 2015, 39 : 2690 - 2694
  • [28] A Method for Windows Malware Detection Based on Deep Learning
    Huang, Xiang
    Ma, Li
    Yang, Wenyin
    Zhong, Yong
    [J]. JOURNAL OF SIGNAL PROCESSING SYSTEMS FOR SIGNAL IMAGE AND VIDEO TECHNOLOGY, 2021, 93 (2-3): : 265 - 273
  • [29] A new method of malware detection based on genetic perspective
    Zhao, B. L.
    Wang, Y.
    Liu, F. D.
    Chen, Y. H.
    [J]. BASIC & CLINICAL PHARMACOLOGY & TOXICOLOGY, 2018, 123 : 56 - 56
  • [30] Malware detection method based on enhanced code images
    Sun, Bowen
    Zhang, Peng
    Cheng, Mingyu
    Li, Xintong
    Li, Qi
    [J]. Qinghua Daxue Xuebao/Journal of Tsinghua University, 2020, 60 (05): : 386 - 392