APT Attribution for Malware Based on Time Series Shapelets

被引:3
|
作者
Wang, Qinqin [1 ,2 ]
Yan, Hanbing [3 ]
Zhao, Chang [4 ]
Mei, Rui [1 ,2 ]
Han, Zhihui [3 ]
Zhou, Yu [3 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Beijing, Peoples R China
[3] Coordinat Ctr China, Natl Comp Network Emergency Response Tech Team, Beijing, Peoples R China
[4] Beijing ChaitinTechnol Co Ltd, Beijing, Peoples R China
基金
国家重点研发计划;
关键词
D O I
10.1109/TrustCom56396.2022.00108
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
To discover and defend against APT attacks more efficiently, we need to conduct binary analysis and source tracing research on APT malicious codes. This paper attributes APT groups for malicious codes from the perspective of binary similarity. First, we innovatively select the local features of the binary functions for classification and apply time series mining techniques to the mining of sequences of basic blocks (called paths). The Shapelet model selects path shapelets, which are path fragments that can best represent paths and are used to distinguish paths. Path shapelets can provide path-level interpretability for classification. Second, we use API calls to filter functions and generate paths of interest to reduce resource consumption. To evaluate the proposed method, we collect APT malicious codes based on publicly available threat intelligence reports. Our method filters 92.82% of functions and generates an average of 1.37 paths per function. The classification effect has obvious advantages over other methods.
引用
收藏
页码:769 / 777
页数:9
相关论文
共 50 条
  • [21] Research on a method of fault identification of rolling bearings based on time series shapelets
    Song, Zhi-kun
    Xu, Li-cheng
    Hu, Xiao-yi
    Liu, Yuan-fu
    Liu, Wei
    Li, Qiang
    MEASUREMENT & CONTROL, 2025,
  • [22] Information gain Aggregation-based Approach for Time Series Shapelets Discovery
    Kramakum, Chutimol
    Rakthanmanon, Thanawin
    Waiyamai, Kitsana
    PROCEEDINGS OF 2018 10TH INTERNATIONAL CONFERENCE ON KNOWLEDGE AND SYSTEMS ENGINEERING (KSE), 2018, : 97 - 101
  • [23] Learning-based shapelets discovery by feature selection for time series classification
    Jiahui Chen
    Yuan Wan
    Xiaoyu Wang
    Yinglv Xuan
    Applied Intelligence, 2022, 52 : 9460 - 9475
  • [24] RLS: An efficient time series clustering method based on u-shapelets
    Meng, Qinghong
    Pu, Peng
    INTELLIGENT DATA ANALYSIS, 2018, 22 (04) : 767 - 785
  • [25] Frobenius correlation based u-shapelets discovery for time series clustering
    Fotso, Vanel Steve Siyou
    Nguifo, Engelbert Mephu
    Vaslin, Philippe
    PATTERN RECOGNITION, 2020, 103
  • [26] A Novel Key-Points Based Shapelets Transform for Time Series Classification
    Peng, Manman
    Luo, Jun
    2017 13TH INTERNATIONAL CONFERENCE ON NATURAL COMPUTATION, FUZZY SYSTEMS AND KNOWLEDGE DISCOVERY (ICNC-FSKD), 2017, : 2268 - 2273
  • [27] Improving ELM-Based Time Series Classification by Diversified Shapelets Selection
    Sun, Qifa
    Yan, Qiuyan
    Yan, Xinming
    Chen, Wei
    Li, Wenxiang
    QUALITY, RELIABILITY, SECURITY AND ROBUSTNESS IN HETEROGENEOUS NETWORKS, 2017, 199 : 446 - 456
  • [28] Learning-based shapelets discovery by feature selection for time series classification
    Chen, Jiahui
    Wan, Yuan
    Wang, Xiaoyu
    Xuan, Yinglv
    APPLIED INTELLIGENCE, 2022, 52 (08) : 9460 - 9475
  • [29] RLTS: Robust Learning Time-Series Shapelets
    Yamaguchi, Akihiro
    Maya, Shigeru
    Ueno, Ken
    MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES, ECML PKDD 2020, PT I, 2021, 12457 : 595 - 611
  • [30] Time Series Shapelets: A New Primitive for Data Mining
    Ye, Lexiang
    Keogh, Eamonn
    KDD-09: 15TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING, 2009, : 947 - 955