Malware-Detection Method with a Convolutional Recurrent Neural Network Using Opcode Sequences

操作码 计算机科学 卷积神经网络 自编码 恶意软件 人工智能 深度学习 模式识别(心理学) 可执行文件 机器学习 数据挖掘 操作系统 计算机硬件
作者
Seungho Jeon,Jongsub Moon
出处
期刊:Information Sciences [Elsevier BV]
卷期号:535: 1-15 被引量:103
标识
DOI:10.1016/j.ins.2020.05.026
摘要

This paper presents a novel malware-detection model with a convolutional recurrent neural network using opcode sequences. Statistically, an executable file is considered as a set of consecutive machine codes. First, the theoretical foundation on which opcode sequences can be used to detect malware has been discussed. Next, an algorithm for extracting opcode sequences from executables and a deep learning-based malware-detection method that uses the opcode sequences as input have been presented. The proposed model comprises an opcode-level convolutional autoencoder that transforms a long opcode sequence to a relatively short compressed sequence at the front end and a dynamic recurrent neural network classifier that performs a prediction task using the codes generated by the opcode-level convolutional autoencoder at the rear end. Experimentally, the proposed model provided a malware-detection accuracy of 96%, receiver operating characteristic-area under the curve of 0.99, and true positive rate (TPR) of 95%. The highest accuracy and TPR achieved by existing malware-detection methods using opcode sequences were 97% and 82%, respectively. Compared with this method, the proposed model delivered a slightly lower accuracy of 96% but a considerably larger TPR of 95%. Therefore, the proposed model is capable of more reliable malware detection.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
xiaofutongxue完成签到,获得积分10
1秒前
CipherSage应助echo采纳,获得10
1秒前
彩色以南发布了新的文献求助10
2秒前
鄂老三发布了新的文献求助10
2秒前
singsong发布了新的文献求助10
2秒前
3秒前
Tomjugj应助学术laji采纳,获得10
4秒前
在水一方应助Daphne采纳,获得10
4秒前
5秒前
博尔塔拉完成签到,获得积分10
5秒前
Zerolii发布了新的文献求助10
6秒前
阿俞完成签到,获得积分10
6秒前
123发布了新的文献求助10
7秒前
周济发布了新的文献求助10
7秒前
Roger完成签到,获得积分10
8秒前
8秒前
科研通AI6.2应助qiao采纳,获得10
10秒前
大个应助XFF采纳,获得10
10秒前
yangyanDai完成签到,获得积分20
11秒前
科研通AI6.2应助echo采纳,获得10
11秒前
打打应助Zerolii采纳,获得10
13秒前
14秒前
FashionBoy应助Robin采纳,获得10
17秒前
彩色以南完成签到,获得积分10
17秒前
Phil丶完成签到,获得积分10
17秒前
Twilight完成签到,获得积分10
18秒前
18秒前
fcyyc发布了新的文献求助10
19秒前
官尔完成签到 ,获得积分10
20秒前
浮浮世世发布了新的文献求助200
21秒前
21秒前
研友_VZG7GZ应助大力的一斩采纳,获得10
22秒前
翼静完成签到,获得积分10
23秒前
achoo发布了新的文献求助10
23秒前
23秒前
jason0023完成签到,获得积分10
23秒前
Zerolii完成签到,获得积分10
24秒前
25秒前
krysten完成签到,获得积分10
26秒前
28秒前
高分求助中
Overcoming Stigma and Bias in Obesity Management 1200
Signals, Systems, and Signal Processing 610
Software that combines deep learning,3D reconstruction and CFD to analyze the state of carotid arteries from ultrasound imaging 500
Bounds for Statistical Estimation in Semiparametric Models 500
Forced degradation and stability indicating LC method for Letrozole: A stress testing guide 500
Ideology and Meaning-Making under the Putin Regime 450
Adhesion Science: Principles & Practice 400
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6491605
求助须知:如何正确求助?哪些是违规求助? 8289495
关于积分的说明 17688448
捐赠科研通 5582877
什么是DOI,文献DOI怎么找? 2915084
邀请新用户注册赠送积分活动 1892206
关于科研通互助平台的介绍 1750000