A Malware Detection System Based on Heterogeneous Information Network

被引:2
|
作者
Yin, Shang-Nan [1 ]
Kang, Ho-Seok [2 ]
Chen, Zhi-Guo [1 ]
Kim, Sung-Ryul [3 ]
机构
[1] Konkuk Univ, Div Internet & Multimedia Engn, Seoul, South Korea
[2] Konkuk Univ, Inst Ubiquitous Informat Technol & Applicat, Seoul, South Korea
[3] Konkuk Univ, Div Software, Seoul, South Korea
基金
新加坡国家研究基金会;
关键词
Malware Detection; Heterogeneous Information Network; Multi-kernel Learning; Relation Analysis;
D O I
10.1145/3264746.3264784
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
In this era of information networks, more and more malware (malicious software) poses a serious threat to security. How to detect malware attacks in a timely and effective manner becomes particularly important. The increasingly sophisticated malware calls for new defense technologies to detect and combat novelty attack and threats. In this paper, we propose a novel malware detection method that not only depends on API calls, further analyze the relationship between them and creates higher-level semantics to avoid attackers evading detection. We construct a heterogeneous information network (HIN) through their rich relationships between software and related APIs, and then use meta-path-based methods to describe the semantic relevance to software and APIs. We use each meta-path to calculate similarities between software and aggregate different similarities with Multi-kernel Learning (MKL) to construct a malware detection system. We collected real sample data and conducted a comprehensive experiment. Through experiments we have obtained a relatively high detection rate and a relatively low false detection rate, shows the effectiveness of our proposed method.
引用
收藏
页码:154 / 159
页数:6
相关论文
共 50 条
  • [1] HinDroid: An Intelligent Android Malware Detection System Based on Structured Heterogeneous Information Network
    Hou, Shifu
    Ye, Yanfang
    Song, Yangqiu
    Abdulhayoglu, Melih
    [J]. KDD'17: PROCEEDINGS OF THE 23RD ACM SIGKDD INTERNATIONAL CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING, 2017, : 1507 - 1515
  • [2] ANDROID MALWARE DETECTION BASED ON HETEROGENEOUS INFORMATION NETWORK WITH CROSS-LAYER FEATURES
    Ren Xixuan
    Zhao Lirui
    Wang Kai
    Xue Zhixing
    Hou Anran
    Shao Qiao
    [J]. 2022 19TH INTERNATIONAL COMPUTER CONFERENCE ON WAVELET ACTIVE MEDIA TECHNOLOGY AND INFORMATION PROCESSING (ICCWAMTIP), 2022,
  • [3] Android Malware Detection Based on Heterogeneous Information Network with Cross-Layer Features
    Xixuan, Ren
    Lirui, Zhao
    Kai, Wang
    Zhixing, Xue
    Anran, Hou
    Qiao, Shao
    [J]. 2022 19th International Computer Conference on Wavelet Active Media Technology and Information Processing, ICCWAMTIP 2022, 2022,
  • [4] Noa: An information retrieval based malware detection system
    [J]. Santos, I. (isantos@deusto.es), 1600, Slovak Academy of Sciences (32):
  • [5] NOA: AN INFORMATION RETRIEVAL BASED MALWARE DETECTION SYSTEM
    Santos, Igor
    Ugarte-Pedrero, Xabier
    Brezo, Felix
    Bringas, Pablo G.
    Maria Gomez-Hidalgo, Jose
    [J]. COMPUTING AND INFORMATICS, 2013, 32 (01) : 145 - 174
  • [6] Design and implementation of a malware detection system based on network behavior
    Xue, L.
    Sun, G.
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (03) : 459 - 470
  • [7] A Lightweight Network-based Android Malware Detection System
    Sanz, Igor Jochem
    Lopez, Martin Andreoni
    Viegas, Eduardo Kugler
    Sanches, Vinicius Rodrigues
    [J]. 2020 IFIP NETWORKING CONFERENCE AND WORKSHOPS (NETWORKING), 2020, : 695 - 703
  • [8] Malicious code detection based on heterogeneous information network
    Liu, Yashu
    Hou, Yueran
    Yan, Hanbing
    [J]. Beijing Hangkong Hangtian Daxue Xuebao/Journal of Beijing University of Aeronautics and Astronautics, 2022, 48 (02): : 258 - 265
  • [9] Opinion Spam Detection Based on Heterogeneous Information Network
    Sun, Yingcheng
    Loparo, Kenneth
    [J]. 2019 IEEE 31ST INTERNATIONAL CONFERENCE ON TOOLS WITH ARTIFICIAL INTELLIGENCE (ICTAI 2019), 2019, : 1156 - 1163
  • [10] A Design of Network Behavior-Based Malware Detection System for Android
    Qi, Yincheng
    Cao, Mingjing
    Zhang, Can
    Wu, Ruping
    [J]. ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2014, PT II, 2014, 8631 : 590 - 600