已入深夜,您辛苦了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!祝你早点完成任务,早点休息,好梦!

Enhancing Malware Classification via Self-Similarity Techniques

计算机科学 恶意软件 自相似性 相似性(几何) 人工智能 数据挖掘 模式识别(心理学) 计算机安全 数学 几何学 图像(数学)
作者
Fangtian Zhong,Qin Hu,Yili Jiang,Jiaqi Huang,Cheng Zhang,Dinghao Wu
出处
期刊:IEEE Transactions on Information Forensics and Security [Institute of Electrical and Electronics Engineers]
卷期号:19: 7232-7244 被引量:11
标识
DOI:10.1109/tifs.2024.3433372
摘要

Despite continuous advancements in defense mechanisms, attackers often find ways to circumvent security measures. Windows operating systems, in particular, are vulnerable due to fewer restrictions on downloading software from unknown sources, facilitating the spread of malware. To address this challenge, researchers have focused on developing techniques to identify Windows malware, crucial for mitigating potential damage. Traditional approaches typically categorize threats into broad classes such as trojans or adware, often failing to capture the full spectrum of malicious behaviors exhibited by diverse malware variants. In response, we propose a novel approach to malware categorization that incorporates both the general malware family and subfamily for each sample. Our method leverages self-similarity techniques to extract local semantics and similarities within the blocks of malware binaries while preserving correlations between these blocks. We utilize a VGG11 model to capture these features, enabling accurate classification. Central to our approach is the conversion of malware binaries into self-similarity descriptors, facilitating space savings while capturing essential semantics within blocks. By focusing on local self-similarities and their geometric layouts across malware, our method effectively identifies repetitive patterns indicative of malware behavior. Our proof-of-concept implementation demonstrates the effectiveness of our framework, achieving an impressive average precision of 98.2% on a newly gathered dataset with over 25,000 samples. Moreover, our method offers significant space savings, outperforming recent research efforts by a factor of over 96. These results underscore the efficacy of incorporating self-similarities and correlations within blocks for robust malware classification, making our approach a promising solution for real-world malware detection and prevention.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
陈先生完成签到,获得积分10
3秒前
谦让的沛芹完成签到,获得积分10
4秒前
4秒前
FadedTulips完成签到 ,获得积分10
5秒前
10秒前
wsf2023完成签到,获得积分10
20秒前
半夏夏完成签到,获得积分10
23秒前
25秒前
26秒前
Criminology34完成签到,获得积分0
26秒前
汉堡包应助搞怪的思卉采纳,获得10
27秒前
123完成签到,获得积分10
27秒前
28秒前
落后鸭子完成签到,获得积分10
30秒前
杨y123发布了新的文献求助10
31秒前
32秒前
BENRONG发布了新的文献求助10
37秒前
wsf2023发布了新的文献求助20
42秒前
聪慧哈密瓜完成签到 ,获得积分10
48秒前
49秒前
55秒前
Owen应助科研通管家采纳,获得10
1分钟前
Nole应助科研通管家采纳,获得10
1分钟前
1分钟前
CodeCraft应助科研通管家采纳,获得10
1分钟前
复杂月饼完成签到,获得积分10
1分钟前
1分钟前
1分钟前
欢呼宛秋完成签到,获得积分10
1分钟前
奋斗的薯条完成签到,获得积分10
1分钟前
酷酷从蕾完成签到 ,获得积分10
1分钟前
科研小白Z完成签到 ,获得积分10
1分钟前
1分钟前
兆兆发布了新的文献求助10
1分钟前
1分钟前
科研通AI6.4应助是锦锦呀采纳,获得10
1分钟前
田様应助jmy1995采纳,获得10
1分钟前
1分钟前
1分钟前
Lucas应助liuzishan采纳,获得10
1分钟前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
China Pluperfect I: Epistemology of Past and Outside in Chinese Art 520
Matrix Methods in Data Mining and Pattern Recognition Second Edition 510
Cosmos as Art Object: Studies in Plato's Timaeus and Other Dialogues 500
What is the Future of Psychotherapy in Digital Age? Technology, AI Bots, and Psychotherapy after Covid 444
Management and the Arts 310
Teaching Social and Emotional Learning in Physical Education 300
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7633366
求助须知:如何正确求助?哪些是违规求助? 9207538
关于积分的说明 19747722
捐赠科研通 7202171
什么是DOI,文献DOI怎么找? 3274916
关于科研通互助平台的介绍 2436843
邀请新用户注册赠送积分活动 2271761