清晨好,您是今天最早来到科研通的研友!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您科研之路漫漫前行!

Guided Malware Sample Analysis Based on Graph Neural Networks

计算机科学 恶意软件 可执行文件 恶意软件分析 人工神经网络 过程(计算) 机器学习 任务(项目管理) 样品(材料) 数据挖掘 人工智能 图形 理论计算机科学 计算机安全 操作系统 化学 管理 色谱法 经济
作者
Yi‐Hsien Chen,Si-Chen Lin,Szu-Chun Huang,Chin‐Laung Lei,Chun‐Ying Huang
出处
期刊:IEEE Transactions on Information Forensics and Security [Institute of Electrical and Electronics Engineers]
卷期号:18: 4128-4143 被引量:6
标识
DOI:10.1109/tifs.2023.3283913
摘要

Malicious binaries have caused data and monetary loss to people, and these binaries keep evolving rapidly nowadays. With tons of new unknown attack binaries, one essential daily task for security analysts and researchers is to analyze and effectively identify malicious parts and report the critical behaviors within the binaries. While manual analysis is slow and ineffective, automated malware report generation is a long-term goal for malware analysts and researchers. This study moves one step toward the goal by identifying essential functions in malicious binaries to accelerate and even automate the analyzing process. We design and implement an expert system based on our proposed graph neural network called MalwareExpert. The system pinpoints the essential functions of an analyzed sample and visualizes the relationships between involved parts. We evaluate our proposed approach using executable binaries in the Windows operating system. The evaluation results show that our approach has a competitive detection performance (97.3% accuracy and 96.5% recall rate) compared to existing malware detection models. Moreover, it gives an intuitive and easy-to-understand explanation of the model predictions by visualizing and correlating essential functions. We compare the identified essential functions reported by our system against several expert-made malware analysis reports from multiple sources. Our qualitative and quantitative analyses show that the pinpointed functions indicate accurate directions. In the best case, the top 2% of functions reported from the system can cover all expert-annotated functions in three steps. We believe that the MalwareExpert system has shed light on automated program behavior analysis.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
4秒前
kikakaka发布了新的文献求助10
11秒前
冷静的尔竹完成签到,获得积分10
27秒前
woxinyouyou完成签到,获得积分0
28秒前
淡然的冬瓜完成签到,获得积分10
30秒前
creep2020完成签到,获得积分0
34秒前
e746700020完成签到,获得积分10
36秒前
研友_VZG7GZ应助科研通管家采纳,获得10
37秒前
56秒前
简奥斯汀完成签到 ,获得积分10
1分钟前
蓝梦诗音完成签到 ,获得积分10
2分钟前
vivideng应助科研通管家采纳,获得20
2分钟前
OsamaKareem应助科研通管家采纳,获得10
2分钟前
传奇3应助科研通管家采纳,获得10
2分钟前
FashionBoy应助kikakaka采纳,获得10
2分钟前
2分钟前
kikakaka发布了新的文献求助10
2分钟前
lijoean完成签到,获得积分10
3分钟前
guo完成签到,获得积分10
3分钟前
kikakaka完成签到,获得积分20
3分钟前
坚定蘑菇完成签到 ,获得积分10
3分钟前
Tree_QD完成签到 ,获得积分10
3分钟前
燕然都护完成签到,获得积分10
3分钟前
Camus完成签到,获得积分10
4分钟前
Tree_QD发布了新的文献求助10
4分钟前
科目三应助Tree_QD采纳,获得10
4分钟前
OsamaKareem应助科研通管家采纳,获得10
4分钟前
OsamaKareem应助科研通管家采纳,获得10
4分钟前
寻找组织完成签到,获得积分10
4分钟前
tlh完成签到 ,获得积分10
4分钟前
忘忧Aquarius完成签到,获得积分0
4分钟前
4分钟前
5分钟前
吊炸天完成签到 ,获得积分10
5分钟前
完美世界应助无敌龙傲天采纳,获得10
5分钟前
铃铛完成签到 ,获得积分10
5分钟前
小白完成签到 ,获得积分0
5分钟前
Alex-Song完成签到 ,获得积分0
5分钟前
vivideng应助科研通管家采纳,获得20
6分钟前
OsamaKareem应助科研通管家采纳,获得10
6分钟前
高分求助中
Malcolm Fraser : a biography 680
Signals, Systems, and Signal Processing 610
天津市智库成果选编 600
Climate change and sports: Statistics report on climate change and sports 500
Forced degradation and stability indicating LC method for Letrozole: A stress testing guide 500
Organic Reactions Volume 118 400
A Foreign Missionary on the Long March: The Unpublished Memoirs of Arnolis Hayman of the China Inland Mission 400
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6458640
求助须知:如何正确求助?哪些是违规求助? 8268078
关于积分的说明 17621241
捐赠科研通 5527529
什么是DOI,文献DOI怎么找? 2905750
邀请新用户注册赠送积分活动 1882502
关于科研通互助平台的介绍 1727322