Malware Recognition Model Training Method, Malware Recognition Method and Device

By calculating the probability matrix of API call type transfer of PE file and performing model training, the problem that existing malware recognition models need to be frequently retrained is solved, and efficient and robust malware recognition is achieved.

CN111382428BActive Publication Date: 2025-06-24BEIJING QIHOOD TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201811647282.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2018-12-29
Publication Date
2025-06-24
Estimated Expiration
2038-12-29

AI Technical Summary

Technical Problem

The existing malware recognition model needs to be constantly retrained as the software changes, and the operation is cumbersome.

Method used

By obtaining the PE file with the security identifier, compute the call type transfer probability matrix of its API, and perform model training based on the matrix and security identifier, obtaining the malware identification model.

Benefits of technology

The high attack resistance and robustness of the malware recognition model is achieved, so that the model does not change with the change of the software structure, reduces the frequency of model retraining, and is difficult to be bypassed by malicious code.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN111382428B_ABST
    Figure CN111382428B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for training a malware recognition model, a malware recognition method and device, relating to the field of network security technology, and capable of solving the problem that the existing malware recognition model needs to be continuously retrained as the software changes. The method of the present invention mainly includes: obtaining a PE file with a security identifier, where the security identifier includes a malicious identifier and a benign identifier; calculating a transition probability matrix of the PE file according to the call types of APIs in the PE file; performing model training based on the transition probability matrix and the security identifier of the PE file to obtain a malware recognition model. The present invention is mainly applicable to scenarios where malware is recognized by analyzing PE files.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly to a method for training a malware recognition model, a malware recognition method and an apparatus. Background Art

[0002] With the continuous development of the Internet, various malware have emerged in an endless stream, and the number of their mutations and variations is even greater. The efficiency of simply based on manual analysis to screen features and implement detection is difficult to meet the needs of large-scale detection. Therefore, the machine learning detection method based on PE (Portable Executable) files has gradually been applied to actual protection services.

[0003] Currently, it mainly focuses on manually extracting features to construct a detection model, that is, parsing sample file structures such as PE headers and import tables to construct a machine learning model. Representative works include the neural network detection model constructed based on PE header structure information proposed by Raff et al., and the deep learning detection model constructed based on byte entropy and string entropy by Saxe et al. The above methods all have a certain detection effect, but the above methods are all based on features such as sample file structures that depend on the samples themselves to construct a machine learning model. Therefore, when the samples (i.e., software) change continuously, it is necessary to retrain continuously to maintain the detection effect, and the operation is relatively cumbersome. Summary of the Invention

[0004] In view of this, a method for training a malware recognition model, a malware recognition method and an apparatus provided by the present invention aim to solve the problem that the existing malware recognition model needs to be retrained continuously as the software changes.

[0005] The object of the present invention is achieved by the following technical solutions:

[0006] In a first aspect, the present invention provides a method for training a malware recognition model, the method comprising:

[0007] Obtaining a PE file with a security identifier, the security identifier including a malicious identifier and a benign identifier;

[0008] Calculating a transition probability matrix of the PE file according to the call type of APIs in the PE file;

[0009] Performing model training based on the transition probability matrix and the security identifier of the PE file to obtain a malware recognition model.

[0010] Optionally, calculating the transition probability matrix of the PE file according to the call type of APIs in the PE file includes:

[0011] Obtaining a control flow graph corresponding to each function in the PE file based on a decompilation tool;

[0012] By parsing the code in the PE file, obtain the API names included in the basic blocks of each control flow graph, and identify the call types corresponding to the API names;

[0013] Count the number of types of call types involved in all control flow graphs of the PE file and the number of times any two call types are arranged in sequence and appear adjacent to each other in the basic block;

[0014] Calculate the transition probability matrix according to the number of types and the number of times.

[0015] Optionally, identifying the call type corresponding to the API name includes:

[0016] According to the API type dictionary containing the mapping relationship between the API name and the call type established in advance, look up the call type corresponding to the obtained API name.

[0017] Optionally, calculating the transition probability matrix according to the number of types and the number of times includes:

[0018] Construct a transition probability matrix with matrix elements M(i, j), where both the number of rows and columns are N;

[0019] Among them, M(i, j) represents the number of times the i-th call type and the j-th call type are arranged in sequence and appear adjacent to each other in the basic block and the number of times the i-th call type has adjacent successor call types among the number of times the i-th call type appears, and N represents the number of types.

[0020] Optionally, obtaining a PE file with a security identifier includes:

[0021] Extract the PE file from the software installation package with a security identifier;

[0022] According to the static information of the extracted PE file, determine whether the extracted PE file is shelled;

[0023] If the extracted PE file is shelled, place the extracted PE file in a sandbox to run, wait for the behavior of the extracted PE file to be fully triggered, dump its occupied memory, and extract the unshelled PE file from the dump file.

[0024] Optionally, the static information includes any one or a combination of the following: file format, program entry point instruction characteristics, and import table.

[0025] Optionally, performing model training based on the transition probability matrix and security identifier of the PE file to obtain a malware recognition model includes:

[0026] Directly perform model training based on the transition probability matrix of the PE file and the corresponding security identifier to obtain the malware recognition model;

[0027] Alternatively, convert the transition probability matrix of the PE file into a one-dimensional feature vector, and perform model training based on the feature vector and the corresponding security identifier to obtain the malware recognition model.

[0028] In a second aspect, the present invention provides a malware recognition method, the method comprising:

[0029] Obtain a PE file to be recognized;

[0030] Calculate the transition probability matrix of the PE file to be recognized according to the call types of APIs in the PE file to be recognized;

[0031] Use the transition probability matrix of the PE file to be recognized and a pre-established malware recognition model to identify whether the software corresponding to the PE file to be recognized is malware, where the malware recognition model is trained according to the malware recognition model training method described in the first aspect.

[0032] Optionally, using the transition probability matrix of the PE file to be recognized and a pre-established malware recognition model to identify whether the software corresponding to the PE file to be recognized is malware includes:

[0033] Directly input the transition probability matrix of the PE file to be recognized into the malware recognition model for maliciousness recognition to determine whether the software corresponding to the PE file to be recognized is malware;

[0034] Or, convert the transition probability matrix of the PE file to be recognized into a one-dimensional feature vector, and input the converted feature vector into the malware recognition model for maliciousness recognition to determine whether the software corresponding to the PE file to be recognized is malware.

[0035] In a third aspect, the present invention provides a malware recognition model training device, the device comprising:

[0036] An acquisition unit, configured to acquire a PE file with a security identifier, where the security identifier includes a malicious identifier and a benign identifier;

[0037] A calculation unit, configured to calculate the transition probability matrix of the PE file according to the call types of APIs in the PE file;

[0038] A training unit, configured to perform model training based on the transition probability matrix and security identifier of the PE file to obtain a malware recognition model.

[0039] Optionally, the computing unit includes:

[0040] A first acquisition module, configured to obtain a control flow graph corresponding to each function in the PE file based on a decompilation tool;

[0041] A second acquisition module, configured to obtain the API names included in the basic blocks of each control flow graph by parsing the code in the PE file;

[0042] An identification module, configured to identify the call type corresponding to the API name;

[0043] A statistics module, configured to count the number of types of call types involved in all control flow graphs of the PE file and the number of times any two call types are arranged in sequence and appear adjacent to each other in the basic block;

[0044] A calculation module, configured to calculate the transition probability matrix according to the number of types and the number of times;

[0045] Optionally, the identification module is configured to look up the call type corresponding to the obtained API name according to an API type dictionary pre-established with a mapping relationship between API names and call types.

[0046] Optionally, the calculation module is configured to construct a transition probability matrix with matrix elements M(i, j), where both the number of rows and columns are N;

[0047] where M(i, j) represents the number of times the i-th call type and the j-th call type are arranged in sequence and appear adjacent to each other in the basic block and the number of times the i-th call type has adjacent successor call types among the number of times the i-th call type appears, and N represents the number of types.

[0048] Optionally, the acquisition unit includes:

[0049] A first extraction module, configured to extract a PE file from a software installation package with a security identifier;

[0050] A judgment module, configured to judge whether the extracted PE file is shelled according to the static information of the extracted PE file;

[0051] A dump module, configured to, when the extracted PE file is shelled, run the extracted PE file in a sandbox, and dump the occupied memory after the behavior of the extracted PE file is fully triggered;

[0052] A second extraction module, configured to extract an unshelled PE file from the dump file.

[0053] Optionally, the static information based on which the determination module makes the determination includes any one or a combination of more than one of the following: file format, program entry point instruction characteristics, and import table.

[0054] Optionally, the training unit is configured to directly perform model training based on the transition probability matrix of the PE file and the corresponding security identifier to obtain the malware recognition model; or convert the transition probability matrix of the PE file into a one-dimensional feature vector, and perform model training based on the feature vector and the corresponding security identifier to obtain the malware recognition model.

[0055] Fourthly, the present invention provides a malware recognition device, which includes:

[0056] An acquisition unit, configured to acquire a PE file to be recognized;

[0057] A calculation unit, configured to calculate the transition probability matrix of the PE file to be recognized according to the call types of APIs in the PE file to be recognized;

[0058] An identification unit, configured to use the transition probability matrix of the PE file to be recognized and a pre-established malware recognition model to identify whether the software corresponding to the PE file to be recognized is malware, where the malware recognition model is trained according to the malware recognition model training method described in the first aspect.

[0059] Optionally, the identification unit is configured to directly input the transition probability matrix of the PE file to be recognized into the malware recognition model for malware identification to determine whether the software corresponding to the PE file to be recognized is malware; or convert the transition probability matrix of the PE file to be recognized into a one-dimensional feature vector, and input the converted feature vector into the malware recognition model for malware identification to determine whether the software corresponding to the PE file to be recognized is malware.

[0060] Fifthly, the present invention provides a storage medium, which stores multiple instructions, and the instructions are suitable for being loaded and executed by a processor to perform the malware recognition model training method described in the first aspect, or to be loaded and executed to perform the malware recognition method described in the second aspect.

[0061] Sixthly, the present invention provides an electronic device, which includes a storage medium and a processor;

[0062] The processor is suitable for implementing each instruction;

[0063] The storage medium is suitable for storing multiple instructions;

[0064] The instructions are adapted to be loaded and executed by the processor to perform the malware recognition model training method as described in the first aspect, or to be loaded and executed to perform the malware recognition method as described in the second aspect.

[0065] By means of the above technical solutions, the malware recognition model training method, malware recognition method and device provided by the present invention can first obtain a PE file with a security identifier, then calculate the transition probability matrix of the PE file according to the call types of APIs in the PE file, and finally perform model training based on the transition probability matrix and security identifier of the PE file to obtain a malware recognition model for subsequent malware recognition using the malware recognition model. It can be seen that since the malware recognition model of the present invention is trained based on the transition probability matrix, and the transition probability matrix captures the dependencies between system calls with different functions, it has high anti-attack ability and robustness and will not change with the change of software structure. Therefore, when the software changes continuously, there is no need to continuously retrain the malware recognition model, thereby reducing the frequency of retraining the malware recognition model. And this method of fundamentally capturing software features makes it difficult for malware authors to bypass malware detection through simple code obfuscation and deformation means.

[0066] The above description is only an overview of the technical solution of the present invention. In order to be able to understand the technical means of the present invention more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present invention more obvious and understandable, the specific embodiments of the present invention are specifically exemplified below. Brief Description of the Drawings

[0067] By reading the following detailed description of the preferred embodiments, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention. And throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:

[0068] Figure 1 Shows a flowchart of a malware recognition model training method provided by an embodiment of the present invention;

[0069] Figure 2 Shows a flowchart of a malware recognition method provided by an embodiment of the present invention;

[0070] Figure 3 Shows a block diagram of the composition of a malware recognition model training device provided by an embodiment of the present invention;

[0071] Figure 4 Shows a block diagram of the composition of another malware recognition model training device provided by an embodiment of the present invention;

[0072] Figure 5 The block diagram of a malware recognition device provided by an embodiment of the present invention is shown. Detailed implementation manners

[0073] Hereinafter, exemplary embodiments of the present disclosure will be described in more detail with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be completely conveyed to those skilled in the art.

[0074] An embodiment of the present invention provides a method for training a malware recognition model, as Figure 1 shown, the method mainly includes:

[0075] 101. Obtain PE files with security identifiers.

[0076] Wherein, the security identifier includes a malicious identifier and a benign identifier. Specifically, a certain scale of manually or automatically labeled malicious samples and benign samples can be collected as a sample library. When model training is required, obtain PE files with malicious identifiers from the malicious samples and obtain PE files with benign identifiers from the benign samples.

[0077] 102. Calculate the transition probability matrix of the PE file according to the call types of APIs in the PE file.

[0078] Since the API transition probability matrix can capture the dependencies between system calls with different functions and has high anti-attack ability and robustness, after obtaining the PE files with security identifiers, each PE file can be analyzed separately to determine the call types of all APIs in each PE file, and then calculate the transition probability matrix of the PE file according to these call types.

[0079] 103. Perform model training based on the transition probability matrix and security identifier of the PE file to obtain a malware recognition model.

[0080] Among them, the malware recognition model can be a support vector machine model, a neural network model, or other models.

[0081] The malware recognition model training method provided by the embodiments of the present invention can first obtain PE files with security labels, then calculate the transition probability matrix of the PE files according to the call types of APIs in the PE files, and finally perform model training based on the transition probability matrix and security labels of the PE files to obtain a malware recognition model for subsequent malware recognition using the malware recognition model. It can be seen that since the malware recognition model of the embodiments of the present invention is trained based on the transition probability matrix, and the transition probability matrix captures the dependencies between system calls with different functions, it has high anti-attack ability and robustness and will not change with the change of software structure. Therefore, when the software changes continuously, there is no need to retrain the malware recognition model continuously, thus reducing the frequency of retraining the malware recognition model. And this method of fundamentally capturing software features makes it difficult for malware authors to bypass malware detection through simple code obfuscation and transformation means.

[0082] In another embodiment of the present invention, an alternative implementation manner of step 102 is further introduced, and this manner includes:

[0083] (1) Obtain the control flow graph corresponding to each function in the PE file based on a decompilation tool.

[0084] The decompilation tool refers to tools such as IDA Pro (Interactive Disassembler Professional) or R2 that can perform reverse analysis on the code segment of the PE file through static analysis. After decompiling the PE file, the functions in it can be identified, and a control flow graph can be obtained from the entry of each function. The nodes in this control flow graph are basic blocks, and the edges are the control flow transfer relationships between basic blocks. A basic block is a basic unit in the program code. When executed, it can and can only start from the first instruction of the basic block and execute until the last instruction. Each function has a unique entry and a corresponding control flow graph, that is, the control flow graph usually includes multiple unconnected subgraphs, and each subgraph corresponds to a unique function entry. This step can be implemented completely automatically by writing an IDC script.

[0085] (2) By parsing the code in the PE file, obtain the API names included in the basic blocks of each control flow graph and identify the call types corresponding to the API names.

[0086] Among them, the specific implementation manner of identifying the call type can be: according to the API type dictionary pre-established with the mapping relationship between API names and call types, look up the call type corresponding to the obtained API name.

[0087] API calls refer to functions exported by major system files such as Kernel32.dll, Ntdll.dll, and advapi.dll. These functions can be classified according to their implemented functions. For example, according to the system resources they affect and operate on, they can be divided into files (such as file creation, reading, and writing), networks (such as creating connections, sending and receiving data), registries (such as creating and reading / writing registry key values), processes (such as process creation and termination), services (such as creating, starting, and stopping system services), and interface UI operations (such as window drawing and destruction).

[0088] (3) Count the number of types of call types involved in all control flow graphs of the PE file and the number of times any two call types appear adjacent to each other in sequence in a basic block.

[0089] (4) Calculate the transition probability matrix based on the number of types and the number of times any two call types are adjacent.

[0090] Construct a transition probability matrix with matrix elements M(i, j), where both the number of rows and columns are N; where M(i, j) represents the number of times the i-th call type and the j-th call type appear adjacent to each other in sequence in a basic block and the number of times the i-th call type has adjacent successor call types among the number of times the i-th call type appears, and N represents the number of types.

[0091] For example, in a certain basic block, after a file reading operation is completed, the file is immediately sent over the network. The first operation is of the file type, and the second operation is of the network type. Then, the number of times for the corresponding item in the matrix for the file type and the network type is incremented by 1. This step requires counting the transition times of various Windows API types for all basic blocks in all control flow graphs.

[0092] Exemplarily, if there are only 3 call types in a certain PE file, the number of times the 1st call type and the 2nd call type appear adjacent to each other in sequence is 2, the number of times the 1st call type and the 3rd call type appear adjacent to each other in sequence is 3, the number of times the 2nd call type and the 1st call type appear adjacent to each other in sequence is 1, the number of times the 2nd call type and the 3rd call type appear adjacent to each other in sequence is 4, the number of times the 3rd call type and the 1st call type appear adjacent to each other in sequence is 2, and the number of times the 3rd call type and the 2nd call type appear adjacent to each other in sequence is 2, then the transition probability matrix is

[0093]

[0094] In another embodiment of the present invention, an alternative implementation of the above step 101 is further introduced. This implementation includes: extracting a PE file from a software installation package with a security identifier; judging whether the extracted PE file is shelled according to the static information of the extracted PE file; if the extracted PE file is shelled, placing the extracted PE file in a sandbox to run, dumping the occupied memory after the behavior of the extracted PE file is triggered completely, and extracting the unshelled PE file from the dump file.

[0095] Wherein, the static information includes any one or a combination of the following: file format, program entry point instruction characteristics, and import table. Shelling means that the program has been protected by a third-party software or a malware author, resulting in the inability to analyze the PE file through static analysis.

[0096] For memory dumping of a shelled PE file, it is necessary to execute the shelled PE file in a controllable closed environment (such as a virtual machine environment like VMWare or VirtualBox). When the shelled PE file is started for a period of time or it is detected that the shelled PE file triggers a network behavior, a memory snapshot image is obtained through the memory dumping function of the virtual execution environment, and the unshelled PE file in it is restored based on the PE structure search of the memory image.

[0097] In another embodiment of the present invention, an alternative implementation of the above step 103 is further introduced. This implementation includes: directly training a malware recognition model according to the transition probability matrix of the PE file and the corresponding security identifier; or converting the transition probability matrix of the PE file into a one-dimensional feature vector, and training a malware recognition model according to the feature vector and the corresponding security identifier.

[0098] That is to say, the transition probability matrix is a two-dimensional vector. A machine learning algorithm that supports multi-dimensional vectors can be directly used to train the malware recognition model, or the two-dimensional vector can be first converted into a one-dimensional vector, and then a machine learning algorithm that supports one-dimensional vectors can be used to train the malware recognition model.

[0099] Further, according to the above method embodiments, another embodiment of the present invention also provides a malware recognition method, as Figure 2 shown, the method includes:

[0100] 201. Obtain a PE file to be recognized.

[0101] Specifically, the PE file to be recognized can be extracted from the software installation package to be recognized first; then, according to the static information of the extracted PE file, it is determined whether the extracted PE file is shelled; if the extracted PE file is shelled, the extracted PE file is placed in a sandbox to run. After the behavior of the extracted PE file is triggered completely, the occupied memory is dumped, and the unshelled PE file is extracted from the dump file.

[0102] 202. Calculate the transition probability matrix of the PE file to be recognized according to the call types of APIs in the PE file to be recognized.

[0103] Specifically, the control flow graph corresponding to each function in the PE file to be recognized can be obtained based on a decompilation tool first; then, by parsing the code in the PE file to be recognized, the API names included in the basic blocks of each control flow graph are obtained, and the call types corresponding to the API names are identified; then, the number of types of call types involved in all control flow graphs of the PE file to be recognized and the number of times any two call types are adjacent are counted; finally, the transition probability matrix is calculated according to the number of types and the number of times any two call types are adjacent. A more specific implementation method can refer to the detailed explanation of step 102 above.

[0104] 203. Use the transition probability matrix of the PE file to be recognized and a pre-established malware recognition model to identify whether the software corresponding to the file to be recognized is malware.

[0105] The malware recognition model is trained according to the above-mentioned malware recognition model training method. The malware recognition model can be a support vector machine model, a neural network model, or other models.

[0106] The malware recognition method provided by the embodiments of the present invention can, after obtaining the PE file to be recognized, first calculate the transition probability matrix of the PE file to be recognized according to the call types of APIs in the PE file to be recognized, and then use the transition probability matrix of the PE file to be recognized and a malware recognition model pre-established based on the transition probability matrices of a large number of known good and malicious PE files to identify whether the software corresponding to the file to be recognized is malware. It can be seen that since the malware recognition model of the embodiments of the present invention is trained based on the transition probability matrix, and the transition probability matrix captures the dependencies between system calls with different functions, it has high anti-attack ability and robustness and will not change with the change of software structure. Therefore, when the software changes continuously, there is no need to retrain the malware recognition model continuously, thereby reducing the frequency of retraining the malware recognition model. And this method of fundamentally capturing software features makes it difficult for malware authors to bypass malware detection through simple code obfuscation and deformation means.

[0107] In another embodiment of the present invention, an alternative implementation manner of the above step 103 is further introduced. This manner includes: when the malware recognition model is directly trained according to the transition probability matrix, directly input the transition probability matrix of the PE file to be recognized into the malware recognition model for malware recognition to determine whether the software corresponding to the PE file to be recognized is malware; or, when the malware recognition model is directly trained according to the one-dimensional feature vector converted from the transition probability matrix, convert the transition probability matrix of the PE file to be recognized into a one-dimensional feature vector, and input the converted feature vector into the malware recognition model for malware recognition to determine whether the software corresponding to the PE file to be recognized is malware.

[0108] Furthermore, according to the above method embodiment, another embodiment of the present invention further provides a malware recognition model training device, as Figure 3 shown, the device includes:

[0109] An acquisition unit 31, configured to acquire a PE file with a security identifier, where the security identifier includes a malicious identifier and a benign identifier;

[0110] A calculation unit 32, configured to calculate the transition probability matrix of the PE file according to the call types of APIs in the PE file;

[0111] A training unit 33, configured to perform model training based on the transition probability matrix and the security identifier of the PE file to obtain a malware recognition model.

[0112] Optionally, as Figure 4 shown, the calculation unit 32 includes:

[0113] A first acquisition module 321, configured to acquire a control flow graph corresponding to each function in the PE file based on a decompilation tool;

[0114] A second acquisition module 322, configured to obtain the API names included in the basic blocks of each control flow graph by parsing the code in the PE file;

[0115] An identification module 323, configured to identify the call types corresponding to the API names;

[0116] A statistics module 324, configured to count the number of types of call types involved in all control flow graphs of the PE file and the number of times any two call types appear adjacent to each other in the basic blocks;

[0117] A calculation module 325, configured to calculate the transition probability matrix according to the number of types and the number of times.

[0118] Optionally, the recognition module 323 is configured to look up the call type corresponding to the obtained API name according to an API type dictionary that pre - establishes the mapping relationship between the API name and the call type.

[0119] Optionally, the calculation module 325 is configured to construct a transition probability matrix with matrix elements M(i, j), where both the number of rows and columns are N.

[0120] Wherein, M(i, j) represents the number of times that the i - th call type and the j - th call type appear adjacent to each other in sequence in the basic block and the number of times that the i - th call type has adjacent subsequent call types among the number of times the i - th call type appears, and N represents the number of types.

[0121] Optionally, as Figure 4 shown, the obtaining unit 31 includes:

[0122] A first extraction module 311, configured to extract a PE file from a software installation package with a security identifier.

[0123] A judgment module 312, configured to judge whether the extracted PE file is shelled according to the static information of the extracted PE file.

[0124] A dump module 313, configured to, when the extracted PE file is shelled, run the extracted PE file in a sandbox, and dump the occupied memory after the behavior of the extracted PE file is completely triggered.

[0125] A second extraction module 314, configured to extract an unshelled PE file from the dump file.

[0126] Optionally, the static information based on which the judgment module makes the judgment includes any one or a combination of the following: file format, program entry point instruction characteristics, and import table.

[0127] Optionally, the training unit 33 is configured to directly perform model training according to the transition probability matrix of the PE file and the corresponding security identifier to obtain the malware recognition model; or convert the transition probability matrix of the PE file into a one - dimensional feature vector, and perform model training according to the feature vector and the corresponding security identifier to obtain the malware recognition model.

[0128] The malware recognition model training device provided by the embodiments of the present invention can first obtain PE files with security labels, then calculate the transition probability matrix of the PE files according to the call types of APIs in the PE files, and finally perform model training based on the transition probability matrix and security labels of the PE files to obtain a malware recognition model for subsequent malware recognition using the malware recognition model. It can be seen that since the malware recognition model of the embodiments of the present invention is trained based on the transition probability matrix, and the transition probability matrix captures the dependencies between system calls with different functions, it has high anti-attack ability and robustness and will not change with the change of software structure. Therefore, when the software changes continuously, there is no need to retrain the malware recognition model continuously, thus reducing the frequency of retraining the malware recognition model. And this method of fundamentally capturing software features makes it difficult for malware authors to bypass malware detection through simple code obfuscation and transformation means.

[0129] Further, according to the above method embodiment, another embodiment of the present invention also provides a malware recognition device, as Figure 5 shown, the device includes:

[0130] An acquisition unit 41, configured to acquire a PE file to be recognized;

[0131] A calculation unit 42, configured to calculate the transition probability matrix of the PE file to be recognized according to the call types of APIs in the PE file to be recognized;

[0132] A recognition unit 43, configured to use the transition probability matrix of the PE file to be recognized and a pre-established malware recognition model to recognize whether the software corresponding to the PE file to be recognized is malware, and the malware recognition model is trained according to the above malware recognition model training method.

[0133] Optionally, the recognition unit 43 is configured to directly input the transition probability matrix of the PE file to be recognized into the malware recognition model for malicious recognition to determine whether the software corresponding to the PE file to be recognized is malware; or convert the transition probability matrix of the PE file to be recognized into a one-dimensional feature vector, and input the converted feature vector into the malware recognition model for malicious recognition to determine whether the software corresponding to the PE file to be recognized is malware.

[0134] The malware recognition device provided by the embodiments of the present invention can, after obtaining the PE file to be recognized, first calculate the transition probability matrix of the PE file to be recognized according to the call types of APIs in the PE file to be recognized, and then use the transition probability matrix of the PE file to be recognized and the malware recognition model established in advance based on the transition probability matrices of a large number of known good and malicious PE files to recognize whether the software corresponding to the file to be recognized is malware. It can be seen that since the malware recognition model of the embodiments of the present invention is trained based on the transition probability matrix, and the transition probability matrix captures the dependencies between system calls of different functions, it has high anti-attack ability and robustness and will not change with the change of software structure. Therefore, when the software changes continuously, there is no need to retrain the malware recognition model continuously, thus reducing the frequency of retraining the malware recognition model. And this method of fundamentally capturing software features makes it difficult for malware authors to bypass malware detection through simple code obfuscation and transformation means.

[0135] Further, according to the above method embodiment, another embodiment of the present invention also provides a storage medium, which stores multiple instructions, and the instructions are suitable for being loaded and executed by a processor to perform the malware recognition model training method as described above, or to load and execute the malware recognition method as described above.

[0136] The storage medium may include non-permanent storage media in computer-readable media, forms such as random access storage media (RAM) and / or non-volatile memory, such as read-only storage media (ROM) or flash memory (flash RAM), and the storage medium includes at least one storage chip.

[0137] Further, according to the above method embodiment, another embodiment of the present invention also provides an electronic device, which includes a storage medium and a processor;

[0138] The processor is suitable for implementing each instruction;

[0139] The storage medium is suitable for storing multiple instructions;

[0140] The instructions are suitable for being loaded and executed by the processor to perform the malware recognition model training method as described above, or to load and execute the malware recognition method as described above.

[0141] The present application also provides a computer program product, which, when executed on an electronic device, is suitable for executing program code initialized with the following method steps:

[0142] Obtain a PE file with a security identifier, where the security identifier includes a malicious identifier and a benign identifier;

[0143] Calculate the transition probability matrix of the PE file according to the call types of APIs in the PE file;

[0144] Based on the transition probability matrix of the PE file and the security identification, perform model training to obtain a malware identification model.

[0145] This application also provides a computer program product, which, when executed on an electronic device, is adapted to execute program code initialized with the following method steps:

[0146] Obtain the PE file to be identified;

[0147] Calculate the transition probability matrix of the PE file to be identified according to the call types of APIs in the PE file to be identified;

[0148] Use the transition probability matrix of the PE file to be identified and a pre-established malware identification model to identify whether the software corresponding to the PE file to be identified is malware, where the malware identification model is trained according to the malware identification model training method described above.

[0149] The embodiments of the present invention also disclose:

[0150] A1. A method for training a malware identification model, the method includes:

[0151] Obtain a PE file with a security identification, where the security identification includes a malware identification and a benign identification;

[0152] Calculate the transition probability matrix of the PE file according to the call types of APIs in the PE file;

[0153] Based on the transition probability matrix of the PE file and the security identification, perform model training to obtain a malware identification model.

[0154] A2. According to the method described in A1, calculating the transition probability matrix of the PE file according to the call types of APIs in the PE file includes:

[0155] Based on a decompilation tool, obtain the control flow graph corresponding to each function in the PE file;

[0156] By parsing the code in the PE file, obtain the API names included in the basic blocks of each control flow graph, and identify the call types corresponding to the API names;

[0157] Count the number of types of call types involved in all control flow graphs of the PE file and the number of times any two call types appear adjacent to each other in the basic blocks in sequence;

[0158] Calculate the transition probability matrix according to the number of types and the number of times.

[0159] A3. According to the method described in A2, identifying the call types corresponding to the API names includes:

[0160] Look up and obtain the call type corresponding to the obtained API name according to the pre-established API type dictionary containing the mapping relationship between the API name and the call type.

[0161] A4. According to the method described in A2, calculating the transition probability matrix according to the number of types and the number of times includes:

[0162] Construct a transition probability matrix with matrix elements M(i, j), where both the number of rows and columns are N;

[0163] Among them, M(i, j) represents the number of times that the i-th call type and the j-th call type appear adjacent to each other in the basic block and the number of times that the i-th call type has adjacent successor call types among the number of times the i-th call type appears, and N represents the number of types.

[0164] A5. According to the method described in A1, obtaining a PE file with a security identifier includes:

[0165] Extract the PE file from the software installation package with a security identifier;

[0166] According to the static information of the extracted PE file, determine whether the extracted PE file is shelled;

[0167] If the extracted PE file is shelled, place the extracted PE file to run in a sandbox, dump its occupied memory after the behavior of the extracted PE file is triggered completely, and extract the unshelled PE file from the dump file.

[0168] A6. According to the method described in A5, the static information includes any one or a combination of the following: file format, program entry point instruction characteristics, and import table.

[0169] A7. According to the method described in any one of A1 - A6, training a model based on the transition probability matrix and security identifier of the PE file to obtain a malware identification model includes:

[0170] Directly train a model according to the transition probability matrix and the corresponding security identifier of the PE file to obtain the malware identification model;

[0171] Alternatively, convert the transition probability matrix of the PE file into a one-dimensional feature vector, and perform model training based on the feature vector and the corresponding security identifier to obtain the malware recognition model.

[0172] B8. A malware recognition method, the method comprising:

[0173] Obtain a PE file to be recognized;

[0174] Calculate the transition probability matrix of the PE file to be recognized according to the call types of APIs in the PE file to be recognized;

[0175] Use the transition probability matrix of the PE file to be recognized and a pre-established malware recognition model to identify whether the software corresponding to the PE file to be recognized is malware, where the malware recognition model is trained according to the malware recognition model training method described in any one of 1-7.

[0176] B9. According to the method described in B8, using the transition probability matrix of the PE file to be recognized and a pre-established malware recognition model to identify whether the software corresponding to the PE file to be recognized is malware includes:

[0177] Directly input the transition probability matrix of the PE file to be recognized into the malware recognition model for malicious recognition to determine whether the software corresponding to the PE file to be recognized is malware;

[0178] Alternatively, convert the transition probability matrix of the PE file to be recognized into a one-dimensional feature vector, and input the converted feature vector into the malware recognition model for malicious recognition to determine whether the software corresponding to the PE file to be recognized is malware.

[0179] C10. A malware recognition model training device, the device comprising:

[0180] An acquisition unit, configured to acquire a PE file with a security identifier, where the security identifier includes a malicious identifier and a benign identifier;

[0181] A calculation unit, configured to calculate the transition probability matrix of the PE file according to the call types of APIs in the PE file;

[0182] A training unit, configured to perform model training based on the transition probability matrix and the security identifier of the PE file to obtain a malware recognition model.

[0183] C11. According to the device described in C10, the calculation unit includes:

[0184] The first acquisition module is used to obtain the control flow graph corresponding to each function in the PE file based on a decompilation tool;

[0185] The second acquisition module is used to obtain the API names included in the basic blocks of each control flow graph by parsing the code in the PE file;

[0186] The identification module is used to identify the call type corresponding to the API name;

[0187] The statistics module is used to count the number of types of call types involved in all control flow graphs of the PE file and the number of times any two call types are arranged in sequence and appear adjacent to each other in the basic block;

[0188] The calculation module is used to calculate the transition probability matrix according to the number of types and the number of times;

[0189] C12. The device according to C11, wherein the identification module is used to look up the call type corresponding to the obtained API name according to an API type dictionary pre-established with the mapping relationship between the API name and the call type.

[0190] C13. The device according to C11, wherein the calculation module is used to construct a transition probability matrix with matrix elements M(i, j), where the number of rows and columns is N;

[0191] Wherein, M(i, j) represents the number of times the i-th call type and the j-th call type are arranged in sequence and appear adjacent to each other in the basic block and the number of times the i-th call type has adjacent successor call types among the number of times the i-th call type appears, and N represents the number of types.

[0192] C14. The device according to C10, wherein the acquisition unit includes:

[0193] The first extraction module is used to extract the PE file from a software installation package with a security identifier;

[0194] The judgment module is used to judge whether the extracted PE file is shelled according to the static information of the extracted PE file;

[0195] The dump module is used to, when the extracted PE file is shelled, run the extracted PE file in a sandbox, and dump the occupied memory after the behavior of the extracted PE file is fully triggered;

[0196] The second extraction module is used to extract the unshelled PE file from the dump file.

[0197] C15. The device according to C14, wherein the static information based on which the determination module makes the determination includes any one or a combination of more than one of the following: file format, program entry point instruction characteristics, and import table.

[0198] C16. The device according to any one of C10 - C15, wherein the training unit is configured to directly perform model training based on the transition probability matrix of the PE file and the corresponding security identifier to obtain the malware recognition model; or convert the transition probability matrix of the PE file into a one-dimensional feature vector, and perform model training based on the feature vector and the corresponding security identifier to obtain the malware recognition model.

[0199] D17. A malware recognition device, the device comprising:

[0200] An acquisition unit, configured to acquire a PE file to be recognized;

[0201] A calculation unit, configured to calculate the transition probability matrix of the PE file to be recognized according to the call types of APIs in the PE file to be recognized;

[0202] An identification unit, configured to use the transition probability matrix of the PE file to be recognized and a pre-established malware recognition model to identify whether the software corresponding to the file to be recognized is malware, where the malware recognition model is trained according to the malware recognition model training method described in any one of A1 - A7.

[0203] D18. The device according to D17, wherein the identification unit is configured to directly input the transition probability matrix of the PE file to be recognized into the malware recognition model for malware identification to determine whether the software corresponding to the PE file to be recognized is malware; or convert the transition probability matrix of the PE file to be recognized into a one-dimensional feature vector, and input the converted feature vector into the malware recognition model for malware identification to determine whether the software corresponding to the PE file to be recognized is malware.

[0204] E19. A storage medium storing multiple instructions, the instructions being adapted to be loaded and executed by a processor to perform the malware recognition model training method described in any one of A1 - A7, or to be loaded and executed to perform the malware recognition method described in any one of B8 - B9.

[0205] F20. An electronic device, the electronic device comprising a storage medium and a processor;

[0206] The processor is adapted to implement each instruction;

[0207] The storage medium is adapted to store multiple instructions;

[0208] The instruction is adapted to be loaded and executed by the processor for the malware recognition model training method described in any one of A1 - A7, or to be loaded and executed for the malware recognition method described in any one of B8 - B9.

[0209] In the above embodiments, the descriptions of the respective embodiments have their own focuses. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0210] It can be understood that the relevant features in the above methods and devices can be referred to each other. Additionally, the "first", "second", etc. in the above embodiments are used to distinguish the embodiments, and do not represent the superiority or inferiority of the respective embodiments.

[0211] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.

[0212] The algorithms and displays provided herein are not inherently related to any particular computer, virtual system, or other device. Various general - purpose systems can also be used in conjunction with the teachings herein. The structure required to construct such systems will be apparent from the above description. In addition, the present invention is not directed to any particular programming language. It should be understood that the content of the present invention described herein can be implemented using various programming languages, and the description of the specific language above is for disclosing the best mode of the present invention.

[0213] In the specification provided herein, a large number of specific details are set forth. However, it can be understood that the embodiments of the present invention can be practiced without these specific details. In some instances, well - known methods, structures, and technologies have not been shown in detail so as not to obscure the understanding of this specification.

[0214] Similarly, it should be understood that, in order to streamline this disclosure and assist in understanding one or more of the various inventive aspects, in the above description of the exemplary embodiments of the present invention, the various features of the present invention are sometimes grouped together into a single embodiment, figure, or description thereof. However, the disclosed method should not be construed as reflecting an intention that the claimed invention requires more features than are expressly recited in each claim. Rather, as reflected in the following claims, the inventive aspects lie in less than all the features of the preceding single disclosed embodiment. Thus, the claims following the detailed description are hereby expressly incorporated into the detailed description, where each claim stands on its own as a separate embodiment of the present invention.

[0215] Those skilled in the art can understand that the modules in the devices in the embodiments can be adaptively changed and arranged in one or more devices different from the embodiments. The modules or units or components in the embodiments can be combined into one module or unit or component, and in addition, they can be divided into multiple sub-modules or sub-units or sub-components. Except that at least some of such features and / or processes or units are mutually exclusive, any combination can be adopted to combine all the features disclosed in this specification (including the accompanying claims, abstract and drawings) and all the processes or units of any method or device so disclosed. Unless otherwise explicitly stated, each feature disclosed in this specification (including the accompanying claims, abstract and drawings) can be replaced by an alternative feature that provides the same, equivalent or similar purpose.

[0216] In addition, those skilled in the art can understand that although some of the embodiments described herein include certain features included in other embodiments rather than other features, the combination of the features of different embodiments means that it is within the scope of the present invention and forms different embodiments. For example, in the following claims, any one of the claimed embodiments can be used in any combination.

[0217] Each component embodiment of the present invention can be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. Those skilled in the art should understand that a microprocessor or a digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components in the malware recognition model training method, malware recognition method and device according to the embodiments of the present invention. The present invention can also be implemented as a device or device program (for example, a computer program and a computer program product) for executing part or all of the methods described herein. Such a program implementing the present invention can be stored on a computer-readable medium, or can be in the form of one or more signals. Such signals can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.

[0218] It should be noted that the above embodiments are illustrative of the present invention and not restrictive thereof, and alternative embodiments can be designed by those skilled in the art without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of elements or steps not listed in the claim. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention can be implemented by means of hardware including several different elements and by means of a suitably programmed computer. In a unit claim listing several devices, several of these devices can be embodied by the same item of hardware. The use of the words first, second, and third, etc. does not denote any order. These words can be interpreted as names.

Claims

1. A method for training a malware recognition model, characterized in that The method includes: Obtain a PE file with a security identifier, where the security identifier includes a malicious identifier and a benign identifier; Calculate the transition probability matrix of the PE file according to the call types of APIs in the PE file; Perform model training based on the transition probability matrix and the security identifier of the PE file to obtain a malware recognition model; Calculating the transition probability matrix of the PE file according to the call types of APIs in the PE file includes: Obtain the control flow graph corresponding to each function in the PE file based on a decompilation tool; By parsing the code in the PE file, obtain the API names included in the basic blocks of each control flow graph, and identify the call types corresponding to the API names; Count the number of types of call types involved in all control flow graphs of the PE file and the number of times any two call types appear adjacent to each other in the basic blocks; Calculate the transition probability matrix according to the number of types and the number of times.

2. The method according to claim 1, wherein Identifying the call type corresponding to the API name includes: According to the pre-established API type dictionary containing the mapping relationship between API names and call types, look up the call type corresponding to the obtained API name.

3. The method according to claim 1, characterized in that, Calculating the transition probability matrix according to the number of types and the number of times includes: Construct a transition probability matrix with matrix elements M(i, j), where both the number of rows and columns are N; Wherein, M(i, j) represents the number of times the i-th call type and the j-th call type appear adjacent to each other in the basic block and the number of times the i-th call type has adjacent successor call types, and N represents the number of types.

4. The method according to claim 1, wherein Obtaining a PE file with a security identifier includes: Extract the PE file from the software installation package with a security identifier; According to the static information of the extracted PE file, determine whether the extracted PE file is shelled; If the extracted PE file is shelled, place the extracted PE file in a sandbox to run, dump its occupied memory after the behavior of the extracted PE file is fully triggered, and extract the unshelled PE file from the dump file.

5. The method according to claim 4, characterized in that, The static information includes any one or a combination of the following: file format, program entry point instruction characteristics, and import table.

6. The method according to any one of claims 1-5, characterized in that, Performing model training based on the transition probability matrix and the security identifier of the PE file to obtain a malware recognition model includes: Directly perform model training according to the transition probability matrix and the corresponding security identifier of the PE file to obtain the malware recognition model; Or, convert the transition probability matrix of the PE file into a one-dimensional feature vector, and perform model training according to the feature vector and the corresponding security identifier to obtain the malware recognition model.

7. A malware identification method, characterized in that, The method includes: Obtain a PE file to be recognized; Calculate the transition probability matrix of the PE file to be recognized according to the call types of APIs in the PE file to be recognized; Using the transition probability matrix of the PE file to be identified and the pre-established malware identification model, identify whether the software corresponding to the file to be identified is malware, and the malware identification model is trained according to the malware identification model training method described in any one of 1-6.

8. The method according to claim 7, wherein Using the transition probability matrix of the PE file to be identified and the pre-established malware identification model to identify whether the software corresponding to the file to be identified is malware includes: Directly input the transition probability matrix of the PE file to be identified into the malware identification model for malware identification to determine whether the software corresponding to the PE file to be identified is malware; Alternatively, convert the transition probability matrix of the PE file to be identified into a one-dimensional feature vector, and input the converted feature vector into the malware identification model for malware identification to determine whether the software corresponding to the PE file to be identified is malware.

9. A malware recognition model training device, characterized in that The device includes: An acquisition unit for acquiring a PE file with a security identifier, where the security identifier includes a malicious identifier and a benign identifier; A calculation unit for calculating the transition probability matrix of the PE file according to the call types of APIs in the PE file; A training unit for performing model training based on the transition probability matrix and security identifier of the PE file to obtain a malware identification model; The calculation unit includes: A first acquisition module for acquiring the control flow graph corresponding to each function in the PE file based on a decompilation tool; A second acquisition module for acquiring the API names included in the basic blocks of each control flow graph by parsing the code in the PE file; An identification module for identifying the call types corresponding to the API names; A statistics module for counting the number of types of call types involved in all control flow graphs of the PE file and the number of times any two call types appear adjacent to each other in the basic blocks; A calculation module for calculating the transition probability matrix according to the number of types and the number of times; 10. The device according to claim 9, characterized in that, The identification module is used to find the call type corresponding to the acquired API name according to a pre-established API type dictionary including the mapping relationship between API names and call types.

11. The device according to claim 9, characterized in that, The calculation module is used to construct a transition probability matrix with matrix elements M(i, j), where both the number of rows and columns are N; Among them, M(i, j) represents the number of times the i-th call type and the j-th call type appear adjacent to each other in the basic block and the number of times the i-th call type has adjacent successor call types, and N represents the number of types.

12. The device according to claim 9, wherein The acquisition unit includes: A first extraction module for extracting a PE file from a software installation package with a security identifier; A judgment module for judging whether the extracted PE file is shelled according to the static information of the extracted PE file; A dump module for, when the extracted PE file is shelled, running the extracted PE file in a sandbox, and dumping the occupied memory after the behavior of the extracted PE file is fully triggered. A second extraction module for extracting unpacked PE files from the dump file.

13. The device according to claim 12, wherein The static information based on which the determination module makes the determination includes any one or a combination of more than one of the following: file format, program entry point instruction characteristics, and import table.

14. The device according to any one of claims 9 - 13, characterized in that, The training unit is configured to directly perform model training based on the transition probability matrix of the PE file and the corresponding security identifier to obtain the malware recognition model; or convert the transition probability matrix of the PE file into a one-dimensional feature vector, and perform model training based on the feature vector and the corresponding security identifier to obtain the malware recognition model.

15. A malware recognition device, characterized in that, The device includes: An acquisition unit for acquiring a PE file to be recognized. A calculation unit for calculating the transition probability matrix of the PE file to be recognized according to the call types of APIs in the PE file to be recognized. An identification unit for identifying whether the software corresponding to the file to be recognized is malware by using the transition probability matrix of the PE file to be recognized and a pre-established malware recognition model, where the malware recognition model is trained according to the malware recognition model training method described in any one of claims 1-6.

16. The device according to claim 15, characterized in that, The identification unit is configured to directly input the transition probability matrix of the PE file to be recognized into the malware recognition model for malware identification to determine whether the software corresponding to the PE file to be recognized is malware; or convert the transition probability matrix of the PE file to be recognized into a one-dimensional feature vector, and input the converted feature vector into the malware recognition model for malware identification to determine whether the software corresponding to the PE file to be recognized is malware.

17. A storage medium, characterized in that, The storage medium stores multiple instructions, and the instructions are applicable to be loaded and executed by a processor to execute the malware recognition model training method described in any one of claims 1-6, or to load and execute the malware recognition method described in any one of claims 7-8.

18. An electronic device, characterized in that, The electronic device includes a storage medium and a processor; The processor is adapted to implement each instruction; The storage medium is adapted to store multiple instructions; The instructions are applicable to be loaded and executed by the processor to execute the malware recognition model training method described in any one of claims 1-6, or to load and execute the malware recognition method described in any one of claims 7-8.

Citation Information

Patent Citations

  • Spectral method for identifying computer software action

    CN103778372A

  • Malicious application detection method and device

    CN105787365A