MalPro: Learning on Process-Aware Behaviors for Malware Detection

被引:4
|
作者
Chen, Xiaohui [1 ,2 ]
Tong, Ying [3 ]
Du, Chunlai [4 ]
Liu, Yongji [1 ]
Ding, Zhenquan [1 ]
Ran, Qingyun [3 ]
Zhang, Yi [3 ]
Cui, Lei [1 ]
Hao, Zhiyu [1 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
[3] Jiangsu Prov Publ Secur Dept, Nanjing, Peoples R China
[4] North China Univ Technol, Sch Informat Sci & Technol, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
malware detection; API sequence; run-time argument; process graph; process-aware behavior; deep learning;
D O I
10.1109/ISCC55528.2022.9913030
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Malware continuously evolve and become more and more sophisticated. Learning on execution behavior is proven to be effective for malware detection. In this paper, we present MalPro, a DNN based malware detection approach that performs learning on process-aware behaviors for Windows programs. It first employs logistic regression-based weighting method to assess the sensitivity of an API to malicious behavior, and weights the API following run-time arguments with varying degrees of sensitivities. Then, it constructs the process graph of inter-process interactions from which a set of attributes are extracted, for characterizing the relationship of various processes in term of invoke actions. Finally, it feeds the weighted API sequences and the process graph attributes into the DNN for training a binary classifier to detect malware. Moreover, we have implemented and evaluated MalPro on two datasets. The results demonstrate that our method outperforms naive models, verifying the effectiveness of MalPro.
引用
收藏
页数:7
相关论文
共 50 条
  • [41] Workflow Time Patterns for Process-Aware Information Systems
    Lanz, Andreas
    Weber, Barbara
    Reichert, Manfred
    [J]. ENTERPRISE, BUSINESS-PROCESS AND INFORMATION SYSTEMS MODELING, 2010, 50 : 94 - +
  • [42] Process-aware FMEA framework for failure analysis in maintenance
    Battirola Filho, Julio Cesar
    Piechnicki, Flavio
    Rocha Loures, Eduardo de Freitas
    Portela Santos, Eduardo Alves
    [J]. JOURNAL OF MANUFACTURING TECHNOLOGY MANAGEMENT, 2017, 28 (06) : 822 - 848
  • [43] Specifying process-aware access control rules in SBVR
    Goedertier, Stijn
    Mues, Christophe
    Vanthienen, Jan
    [J]. ADVANCES IN RULE INTERCHANGE AND APPLICATIONS, PROCEEDINGS, 2007, 4824 : 39 - +
  • [44] Detecting Process-Aware Attacks in Sequential Control Systems
    Koucham, Oualid
    Mocanu, Stephane
    Hiet, Guillaume
    Thiriet, Jean-Marc
    Majorczyk, Frederic
    [J]. SECURE IT SYSTEMS, NORDSEC 2016, 2016, 10014 : 20 - 36
  • [45] A process-aware framework to support Process Mining from blockchain applications
    Alzhrani, Fouzia
    Saeedi, Kawther
    Zhao, Liping
    [J]. JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2024, 36 (02)
  • [46] Process mapping and anomaly detection in laser wire directed energy deposition additive manufacturing using in-situ imaging and process-aware machine learning
    Assad, Anis
    Bevans, Benjamin D.
    Potter, Willem
    Rao, Prahalada
    Cormier, Denis
    Deschamps, Fernando
    Hamilton, Jakob D.
    Rivero, Iris, V
    [J]. MATERIALS & DESIGN, 2024, 245
  • [47] Process-Aware Accounting Information System Based on Business Process Management
    Li, Feifeng
    Fang, Gang
    [J]. Wireless Communications and Mobile Computing, 2022, 2022
  • [48] An Approach for Consistent Delegation in Process-Aware Information Systems
    Schefer-Wenzl, Sigrid
    Strembeck, Mark
    Baumgrass, Anne
    [J]. BUSINESS INFORMATION SYSTEMS, BIS 2012, 2012, 117 : 60 - 71
  • [49] A Process-Aware Decision Support System for Business Processes
    Agarwal, Prerna
    Gao, Buyu
    Huo, Siyu
    Reddy, Prabhat
    Dechu, Sampath
    Obeidi, Yazan
    Muthusamy, Vinod
    Isahagian, Vatche
    Carbajales, Sebastian
    [J]. PROCEEDINGS OF THE 28TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING, KDD 2022, 2022, : 2673 - 2681
  • [50] Process-Aware Accounting Information System Based on Business Process Management
    Li, Feifeng
    Fang, Gang
    [J]. WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2022, 2022