引用本文:陈永威,谷勇浩,谢玉奇,吴铁军.基于异质图匹配网络的恶意软件相似性度量方法.软件学报,2026,37(6):2510-2526
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 612次   下载 1350 本文二维码信息
码上扫一扫!
分享到: 微信 更多
基于异质图匹配网络的恶意软件相似性度量方法
陈永威1,2, 谷勇浩1,2, 谢玉奇1,2, 吴铁军3
1.北京邮电大学 计算机学院(国家示范性软件学院), 北京 100876;2.智能通信软件与多媒体北京市重点实验室(北京邮电大学), 北京 100876;3.绿盟科技集团股份有限公司, 北京 100089
摘要:
现有静态恶意软件相似性度量方法受到静态免杀技术影响, 模型使用的特征易被混淆或者恶意软件语义未被充分挖掘. 提出一种基于异质图匹配网络的恶意软件相似性度量方法HGMSim (heterogeneous graph matching network-based similarity)解决上述问题, 该方法首先利用反汇编工具IDA Pro提取恶意软件的函数调用图, 将函数调用图抽象为异质图, 充分挖掘函数调用图中不同类型函数节点和函数调用关系的异质语义. 同时, 为了挖掘不同函数调用图节点之间的隐式邻居语义, 对两个函数调用图中相似的同类型函数节点建立跨图边, 构建异质图匹配网络. 然后, 提出基于局部点图匹配的异质图嵌入方法并实现恶意软件相似性度量, 解决现有方法对不同家族之间图结构高度相似恶意软件难区分的问题. 最后, 通过对比实验验证HGMSim在恶意软件相似性度量方面具有最佳的性能表现.
关键词:  恶意软件相似性  函数调用图  异质图匹配网络  跨图交互
DOI:10.13328/j.cnki.jos.007487
分类号:TP311
基金项目:CCF-绿盟科技“鲲鹏”科研基金(CCF-NSFOCUS202213); 工业信息安全感知与评估技术工业和信息化部重点实验室开放课题(202406); 北京邮电大学数智北邮融创项目(RCXM-2025-029)
Malware Similarity Measurement Method Based on Heterogeneous Graph Matching Network
CHEN Yong-Wei1,2, GU Yong-Hao1,2, XIE Yu-Qi1,2, WU Tie-Jun3
1.School of Computer Science (National Pilot Software Engineering School), Beijing University of Posts and Telecommunications, Beijing 100876, China;2.Beijing Key Laboratory of Intelligent Telecommunications Software and Multimedia (Beijing University of Posts and Telecommunications), Beijing 100876, China;3.Nsfocus Technologies Group Co. Ltd., Beijing 100089, China
Abstract:
Existing static malware similarity measurement methods are affected by static anti-antivirus techniques, and the model features are either easily confused or fail to fully capture malware semantics. This study proposes a malware similarity measurement method called heterogeneous graph matching network-based similarity (HGMSim) to address the above problems. This method first uses the disassembly tool IDA Pro to extract a malware’s call graph, which is then abstracted into a heterogeneous graph to effectively capture the heterogeneous semantics of different function node types and their call relationships. Meanwhile, cross-graph edges are established for similar function nodes of the same type in two call graphs to mine the implicit neighbor semantics between nodes in different call graphs, and a heterogeneous graph matching network is constructed. Then, the study proposes a heterogeneous graph embedding method based on local node graph matching strategy and implements malware similarity measurement to solve the problem of difficulty in distinguishing malware with highly similar graph structures between different families. Finally, experimental results show that HGMSim performs best in malware similarity measurement.
Key words:  malware similarity  call graph  heterogeneous graph matching network  cross-graph interaction

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: