Guided Malware Sample Analysis Based on Graph Neural Networks

计算机科学 恶意软件 可执行文件 恶意软件分析 人工神经网络 过程(计算) 机器学习 任务(项目管理) 样品(材料) 数据挖掘 人工智能 图形 理论计算机科学 计算机安全 操作系统 化学 管理 色谱法 经济
作者
Yi‐Hsien Chen,Si-Chen Lin,Szu-Chun Huang,Chin‐Laung Lei,Chun‐Ying Huang
出处
期刊:IEEE Transactions on Information Forensics and Security [Institute of Electrical and Electronics Engineers]
卷期号:18: 4128-4143 被引量:6
标识
DOI:10.1109/tifs.2023.3283913
摘要

Malicious binaries have caused data and monetary loss to people, and these binaries keep evolving rapidly nowadays. With tons of new unknown attack binaries, one essential daily task for security analysts and researchers is to analyze and effectively identify malicious parts and report the critical behaviors within the binaries. While manual analysis is slow and ineffective, automated malware report generation is a long-term goal for malware analysts and researchers. This study moves one step toward the goal by identifying essential functions in malicious binaries to accelerate and even automate the analyzing process. We design and implement an expert system based on our proposed graph neural network called MalwareExpert. The system pinpoints the essential functions of an analyzed sample and visualizes the relationships between involved parts. We evaluate our proposed approach using executable binaries in the Windows operating system. The evaluation results show that our approach has a competitive detection performance (97.3% accuracy and 96.5% recall rate) compared to existing malware detection models. Moreover, it gives an intuitive and easy-to-understand explanation of the model predictions by visualizing and correlating essential functions. We compare the identified essential functions reported by our system against several expert-made malware analysis reports from multiple sources. Our qualitative and quantitative analyses show that the pinpointed functions indicate accurate directions. In the best case, the top 2% of functions reported from the system can cover all expert-annotated functions in three steps. We believe that the MalwareExpert system has shed light on automated program behavior analysis.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
畅快的半仙完成签到,获得积分10
1秒前
小马甲应助寒冷的断秋采纳,获得10
1秒前
阿龙完成签到,获得积分10
1秒前
佳宝完成签到,获得积分10
1秒前
不知完成签到 ,获得积分10
2秒前
欢欢完成签到,获得积分10
2秒前
3秒前
小党完成签到,获得积分10
4秒前
清秀成威完成签到,获得积分10
4秒前
Ashao完成签到,获得积分10
4秒前
方羽发布了新的文献求助10
4秒前
拿铁不加甜甜完成签到,获得积分10
5秒前
勤恳怀梦完成签到,获得积分10
6秒前
子凡完成签到 ,获得积分10
6秒前
Nicole完成签到,获得积分10
6秒前
欢呼香芋完成签到,获得积分10
6秒前
活力的听露完成签到 ,获得积分10
6秒前
xxx完成签到,获得积分10
6秒前
李逸玄发布了新的文献求助10
6秒前
arniu2008发布了新的文献求助10
7秒前
BaiX完成签到,获得积分10
7秒前
7秒前
Mois完成签到 ,获得积分10
7秒前
朱妮妮完成签到,获得积分10
7秒前
柠静樨完成签到,获得积分10
8秒前
8秒前
Kay76完成签到,获得积分10
9秒前
9秒前
寒冷的断秋完成签到,获得积分10
10秒前
eeven完成签到 ,获得积分10
10秒前
舒心易烟完成签到,获得积分10
12秒前
李逸玄完成签到,获得积分10
12秒前
wind完成签到 ,获得积分10
13秒前
黑马的嘶鸣完成签到,获得积分10
13秒前
拉长的芷烟完成签到 ,获得积分10
13秒前
俭朴觅松完成签到 ,获得积分10
14秒前
专注寻菱完成签到,获得积分10
14秒前
SCI朝我来完成签到,获得积分10
15秒前
15秒前
阔达采白完成签到,获得积分10
16秒前
高分求助中
Malcolm Fraser : a biography 680
Signals, Systems, and Signal Processing 610
天津市智库成果选编 600
Climate change and sports: Statistics report on climate change and sports 500
Forced degradation and stability indicating LC method for Letrozole: A stress testing guide 500
Organic Reactions Volume 118 400
A Foreign Missionary on the Long March: The Unpublished Memoirs of Arnolis Hayman of the China Inland Mission 400
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6459386
求助须知:如何正确求助?哪些是违规求助? 8268465
关于积分的说明 17622373
捐赠科研通 5528716
什么是DOI,文献DOI怎么找? 2905930
邀请新用户注册赠送积分活动 1882667
关于科研通互助平台的介绍 1727870