| 本文已被:浏览 2155次 下载 4380次 |
 码上扫一扫! |
|
|
| 基于多重异质图的恶意软件相似性度量方法 |
|
谷勇浩1,2,3, 王翼翡1,2, 刘威歆4, 吴铁军4, 孟国柱5,6
|
|
1.智能通信软件与多媒体北京市重点实验室(北京邮电大学), 北京 100876;2.北京邮电大学 计算机学院, 北京 100876;3.广东省信息安全技术重点实验室(中山大学), 广东 广州 510006;4.绿盟科技集团股份有限公司, 北京 100089;5.信息安全国家重点实验室(中国科学院 信息工程研究所), 北京 100093;6.中国科学院大学 网络空间安全学院, 北京 100049
|
|
| 摘要: |
| 现有恶意软件相似性度量易受混淆技术影响,同时缺少恶意软件间复杂关系的表征能力,提出一种基于多重异质图的恶意软件相似性度量方法RG-MHPE (API relation graph enhanced multiple heterogeneous ProxEmbed)解决上述问题.方法首先利用恶意软件动静态特征构建多重异质图,然后提出基于关系路径的增强型邻近嵌入方法,解决邻近嵌入无法应用于多重异质图相似性度量的问题.此外,从MSDN网站的API文档中提取知识,构建API关系图,学习Windows API间的相似关系,有效减缓相似性度量模型老化速度.最后,通过对比实验验证所提方法RG-MHPE在相似性度量性能和模型抗老化能力等方面表现最好. |
| 关键词: 恶意软件相似性 多重异质图 邻近嵌入 API关系图 模型老化 |
| DOI:10.13328/j.cnki.jos.006538 |
| 分类号:TP311 |
| 基金项目:北京邮电大学中央高校基本科研业务费行动计划(2021XD-A11-1);国家自然科学基金(U20B2045,U1936216);广东省信息安全技术重点实验室开放基金(2020B1212060078) |
|
| Malware Similarity Measurement Method Based on Multiplex Heterogeneous Graph |
|
GU Yong-Hao1,2,3, WANG Yi-Fei1,2, LIU Wei-Xin4, WU Tie-Jun4, MENG Guo-Zhu5,6
|
|
1.Beijing Key Laboratory of Intelligent Telecommunications Software and Multimedia (Beijing University of Posts and Telecommunications), Beijing 100876, China;2.School of Computer Science, Beijing University of Posts and Telecommunications, Beijing 100876, China;3.Guangdong Provincial Key Laboratory of Information Security Technology (Sun Yat-sen University), Guangzhou 510006, China;4.Nsfocus Technologies Group Co. Ltd., Beijing 100089, China;5.State Key Laboratory of Information Security (Institute of Information Engineering, Chinese Academy of Sciences), Beijing 100093, China;6.School of Cyber Security, University of Chinese Academy of Sciences, Beijing 100049, China
|
| Abstract: |
| Existing malware similarity measurement methods cannot accommodate code obfuscation technology and lack the ability to model the complex relationships between malware. This study proposes a malware similarity measurement method called API relation graph enhanced multiple heterogeneous proxembed (RG-MHPE) based on multiplex heterogeneous graph to solve the above problems. This method first uses the dynamic and static feature of malware to construct the multiplex heterogeneous graph and then proposes an enhanced proximity embedding method based on relational paths to solve the problem that proximity embedding cannot be applied to the similarity measurement of the multiplex heterogeneous graph. In addition, this study extracts knowledge from API documents on the MSDN website, builds an API relation graph, learns the similarity between Windows APIs, and effectively slows down the aging speed of similarity measurement models. Finally, the experimental results show that RG-MHPE has the best performance in similarity measurement performance and model anti-aging ability. |
| Key words: malware similarity multiplex heterogeneous graph proximity embedding API relation graph model aging |