Software malicious behavior identification method based on ensemble learning and dynamic analysis

A technology integrating learning and identification methods, applied in the fields of information security detection and network security, can solve problems such as software difficulties, and achieve the effect of improving generalization ability and making up for code confusion.

Pending Publication Date: 2021-11-02
中国星网网络应用有限公司
View PDF3 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

Traditional software detection methods mostly rely on feature libraries, making it very difficult to face increasingly complex software

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Software malicious behavior identification method based on ensemble learning and dynamic analysis
  • Software malicious behavior identification method based on ensemble learning and dynamic analysis
  • Software malicious behavior identification method based on ensemble learning and dynamic analysis

Examples

Experimental program
Comparison scheme
Effect test

Embodiment

[0029] figure 1 Shown is a schematic diagram of the safety assessment model of the present invention, which mainly adopts two parts of dynamic analysis features and integrated learning training, so the present invention mainly includes the dynamic analysis stage and the behavior recognition stage.

[0030] In the dynamic analysis stage, the sandbox method is first used to simulate the operation of the software. The present invention uses the DroidBox dynamic analysis tool to run all the software data sets in a sandbox model, so as to conform to the normal use specifications as much as possible. At the same time, the monkey is used to randomly click on it to simulate the user's use, so various dynamic features can better reflect the authenticity of the software. In this way, various dynamic features such as system calls, network behaviors, taint tracking, and string operations are extracted, and each feature is explained below.

[0031] A system call is a part of the operating...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention relates to the field of network security and information security detection, in particular to a software malicious behavior identification method based on ensemble learning and dynamic analysis. The method comprises the following steps: dynamically analyzing software by adopting a sandbox method, randomly clicking the software by using monkey to simulate the use of a user at the same time, and then extracting system calling, network behaviors, stain tracking and character string operation as dynamic characteristics; integrating a random forest, a support vector machine, naive Bayes and k-nearest neighbor by adopting an integrated learning method based on stacking, and training feature vectors to generate a training model; and inputting the dynamic features of the malicious software to be identified into the trained classifier, and completing identification by the classifier. Advantages and disadvantages of each classifier in traditional machine learning are avoided by adopting an integrated learning method, and meanwhile, the effectiveness of malicious behavior recognition can be better reflected by utilizing dynamic behaviors as features.

Description

technical field [0001] The invention relates to the fields of network security and information security detection, in particular to a software malicious behavior identification method based on integrated learning and dynamic analysis. Background technique [0002] With the development of information technology, the complexity of software is getting higher and higher, and people's dependence on software is becoming stronger and stronger. Many illegal program developers also aimed at this market, and developed many malicious programs to inject software to make huge profits, seriously infringing on the information security of users. Most of the traditional software detection methods rely on feature libraries, which makes it very difficult to face increasingly complex software. How to effectively identify malicious behaviors in malware and protect users' personal interests has become a hot topic today. Scholars and research organizations at home and abroad are actively involve...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & AuthorityApplications(China)
IPC IPC(8): G06N20/20G06F21/56G06K9/62
CPCG06N20/20G06F21/566G06F18/241
Inventor王丹
Owner中国星网网络应用有限公司