A Malware Detection Method and System Based on ViT Siamese Neural Network

By combining static and dynamic analysis of ViT twin neural network model, the problem of low detection accuracy of malware is solved, and efficient feature extraction and accurate identification of malware is achieved.

CN116010950BActive Publication Date: 2025-07-11GUANGDONG UNIV OF TECH +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211664994.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-22
Publication Date
2025-07-11
Estimated Expiration
2042-12-22

AI Technical Summary

Technical Problem

When facing new casting malware, the existing malware detection methods have low detection accuracy and insufficient feature extraction, making it difficult to effectively distinguish between malware and benign software, especially the problems of long-sequence feature extraction, gradient vanishing and gradient explosion in a single convolutional twin network.

Method used

The malware detection method based on ViT twin neural network is adopted, combined with static analysis and dynamic analysis to obtain the original information and operating status information of the PE file. By building the ViT twin neural network model, the hyperparameters of the model are optimized using the training set and test set to extract the features of the malware, and the detection accuracy and recall rate are improved.

Benefits of technology

By combining static and dynamic analysis, the malware features are fully extracted, which significantly improves the detection accuracy and recall rate of malware, and solves the problem of poor detection results in the existing technology.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116010950B_ABST
    Figure CN116010950B_ABST
Patent Text Reader

Abstract

The present invention proposes a malware detection method and system based on a ViT Siamese neural network, which relates to the technical field of computer network information security. First, an open malware PE file dataset is obtained, and the original information of the PE file and the information in the running state are jointly obtained through static analysis and dynamic analysis. The data obtained by static analysis and dynamic analysis are merged, and the merged one-dimensional data is converted into two-dimensional data, and then into a grayscale image. Finally, the grayscale image is segmented into a training set and a test set. Then, a ViT Siamese neural network model is constructed, and the training set and the test set are used to train and test and evaluate the ViT Siamese neural network model respectively. Through continuous parameter tuning and optimization, a trained ViT Siamese neural network model is obtained for malware detection, which can extract the features of malware more fully and improve the accuracy and recall rate of malware detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer network information security, and more particularly, to a malware detection method and system based on a ViT Siamese neural network. Background Art

[0002] With the rapid development of the Internet, its applications have gradually penetrated into every aspect of people's lives, including social interaction, online banking, health-related transactions, and marketing. At the same time, criminals have started to commit crimes on the Internet. They usually use malware to launch cyberattacks on the victim's computer.

[0003] So-called malware refers to any software that deliberately executes malicious payloads on the victim's computer. There are different types of malware, including viruses, worms, Trojan horses, rootkits, and ransomware. Each type and family of malware is designed to affect the original victim machine in different ways, such as damaging the target system, allowing remote code execution, stealing confidential data, etc. The early malware was written for simple purposes and was therefore easier to detect. Such malware can be defined as traditional malware. However, nowadays, the new generation of malware can run in kernel mode and is more destructive and difficult to detect than traditional malware. This kind of malware can easily bypass protection software running in kernel mode, such as firewalls and antivirus software. Generally, traditional malware consists of a single process and does not use complex techniques to hide itself, while the new generation of malware can use multiple different existing or new processes simultaneously and use some obfuscation techniques to hide itself and become persistent in the system. In addition, the new generation of malware can launch more destructive attacks, such as targeted and persistent attacks that have never been seen before, and use more than one type of malware during the attack.

[0004] There are mainly two existing malware detection methods: static detection and dynamic detection. Static detection refers to obtaining characteristic information such as the original code sequence, header information, and Hash value of the software through decompilation tools. The literature "Qi P, Zhang Z, Wang W, et al. Malware detection by exploiting deep learning over binary programs[C] / / 2020 25th International Conference on Pattern Recognition(ICPR). IEEE, 2021:9068-9075" proposed a method of reducing the dimension of the data obtained by decompilation through principal component analysis and classifying the reduced data using the support vector machine algorithm, which improved the malware detection efficiency; Dynamic detection refers to running the software in a sandbox environment and obtaining characteristic information such as the log information, function call information, and context parameters of the software during operation. The literature "Wang S, Zhou G, Lu J, et al. A novel malware detection and classification method based on capsule network[C] / / International Conference on artificial intelligence and security. Springer, Cham, 2019:573-584" converted the characteristic information obtained under operating conditions into RGB images and proposed a capsule network framework with dynamic routing for the classification of malware images. There are differences in the ways of obtaining characteristic information between the two, but both model and discriminate the deep learning method by obtaining characteristic information.

[0005] Faced with the ever-changing malware, traditional detection methods, such as signature-based, heuristic, and behavioral detection methods, obviously cannot meet the requirements of today's society for detection accuracy, especially when faced with new malware with a packer. In recent years, with the development of machine learning and deep learning, deep learning neural networks can distinguish whether a program is malware after being well trained, and have shown excellent performance, and have also shown good detection effects when faced with new malware with a packer. However, the threat of malware has always existed, but existing malware detection methods generally have problems such as low detection accuracy, insufficient feature extraction, and poor detection effects on new malware. The prior art discloses a malware family detection method, storage medium and computing device. The detection method includes: first, extracting features from all malware training samples of each class in the malware training set to obtain corresponding multiple feature vectors; then, converting the multiple feature vectors into feature images, generating image pairs based on the feature images, constructing a twin network model and training the model using the image pairs; taking out the samples to be tested from the malware test set, and using the trained twin network model to count the similarity scores between each sample to be tested and the malware training sample; calculating the threshold, and distinguishing the sample to be tested as a known malware family or a new malware family based on the threshold. This scheme can correctly detect the category to which the malware belongs, and the classification effect is good. However, with the changes and upgrades of malware, the dynamic detection method alone is not enough to achieve a good detection effect in terms of detection accuracy, and a single convolutional twin network is difficult to solve problems such as long sequence feature extraction, gradient disappearance and gradient explosion.

[0006] Therefore, how to combine dynamic detection and static detection to improve the malware detection rate is a technical problem that needs to be solved urgently. Summary of the invention

[0007] In order to solve the problem of how to combine dynamic detection and static detection to improve the malware detection rate, the present invention proposes a malware detection method and system based on ViT (Vsion Transformer) twin neural network, which can better extract the features of malware and improve the accuracy and recall rate of malware detection.

[0008] In order to achieve the above technical effects, the technical solution of the present invention is as follows:

[0009] A malware detection method based on ViT twin neural network, the method comprising the following steps:

[0010] S1. Obtain a public malware PE file dataset and delete unlabeled PE files in the PE malware dataset;

[0011] S2. Determine whether the current PE file is a shelled file. If so, perform the unpacking process and execute step S3; otherwise, execute step S3;

[0012] S3. Perform static analysis and dynamic analysis operations on the PE file respectively. Among them, during static analysis, obtain the original information of the PE file through decompilation; during dynamic analysis, run the PE file in a sandbox environment to obtain the information of the PE file in the running state;

[0013] S4. Combine the data obtained from static analysis and dynamic analysis, convert the combined one-dimensional data into two-dimensional data, then convert it into a grayscale image, and finally split the grayscale image into a training set and a test set;

[0014] S5. Build a ViT Siamese neural network model;

[0015] S6. Use the training set to train the ViT Siamese neural network model, continuously optimize and adjust the hyperparameters in the ViT Siamese neural network model, and use the test set to evaluate the ViT Siamese neural network model to obtain a trained ViT Siamese neural network model for malware detection.

[0016] Preferably, in step S2, use the detection tool PEiD to detect the PE file to confirm whether the PE file is shelled. When the PE file is a shelled file, use the UPX unpacking tool for unpacking. Detect and unpack the shelled PE file for subsequent static analysis and dynamic analysis of the PE file.

[0017] Preferably, the original information of the PE file obtained through decompilation in step S3 includes: DOS header information, PE signature, PE file header information, PE section optional information, section table, idata section, text section, data section. After obtaining the original information of the PE file, convert all the obtained original information into vector format through Embedding encoding technology, delete meaningless data and standardize the data, and add rows and items to the data.

[0018] Preferably, the information of the PE file in the running state obtained includes: reading and writing of the registry, the number of host connections, changes in files in the Windows directory and System directory, log information during the running of the PE file, function call information, context parameter information. Convert all the obtained information into vector format through Embedding encoding technology.

[0019] Preferably, the specific process of step S4 is:

[0020] S41. Combine the data obtained from static analysis and dynamic analysis, standardize the data using the min-max method, and then multiply all the standardized results by 255 to standardize all the data into the range of [0, 255];

[0021] S42. Add feature items to the original data, and all the added feature item values are 0;

[0022] S43. Construct a Markov transition field, and use the Markov transition field to convert the original one-dimensional data into two-dimensional data and convert the two-dimensional data into a grayscale image.

[0023] Preferably, in step S43, the process of constructing the Markov transition field is as follows:

[0024] S431. Divide the sequence data of length n into Q quantile bins according to its value range, and each data point i belongs to a unique q i ;

[0025] S432. Construct a Markov transition matrix W of size [Q, Q], where W[i, j] is determined by the frequency of the data in q i being adjacent to the data in q j ;

[0026] S433. Construct a Markov transition field M of size, and the value of M[i, j] is W[q i , q j .

[0027] Preferably, the process of constructing the ViT Siamese neural network model and the ViT Siamese neural network model processing data in step S5 is as follows:

[0028] S51. Build a patch module. The patch module performs a patch operation on the malware grayscale image obtained in S43, divides the grayscale image, performs positional encoding on each divided image, then flattens the image data into one-dimensional data, and combines the positional encoding with the flattened data;

[0029] S52. Build the Encoder module, and use four Encoder modules to form a Transformer Encoder module. Also, introduce multiple multi-head attention mechanism modules and residual connection modules. Perform a residual connection between the current data stream and the data stream after extracting the main features through the multi-head attention mechanism, and add the two data streams item by item. The grayscale image data first passes through the patch embedding layer of the Transformer Encoder module, and the position encoding is combined with the flattened data. Then, the obtained data is input into the Transformer Encoder module for feature extraction;

[0030] S53. Build a ViT Siamese network by sharing the loss value, and introduce an MLP fully connected layer; in the ViT Siamese network, there are two input values. Two predicted values are obtained through the ViT Siamese network, and the error between the two predicted values and the actual value is the loss value, which is shared and used in the ViT Siamese network; after feature extraction through the ViT Siamese network, the GELU activation function of the MLP fully connected layer is used to perform a non-linear output probability value on the data, and finally determine whether it is malware.

[0031] Preferably, the process of step S6 is as follows:

[0032] S61. Input the training set grayscale images into the ViT Siamese neural network model, and train using the gradient descent method, continuously adjusting the dropout, learning rate, number of multi-head attention mechanisms, and activation function of the MLP fully connected layer in the ViT Siamese neural network model;

[0033] S62. Based on binary classification, use accuracy and recall as evaluation metrics, and use the test set to evaluate the ViT Siamese neural network model.

[0034] Preferably, the calculation formula for the accuracy evaluation metric is:

[0035]

[0036] The calculation formula for the recall evaluation metric is:

[0037]

[0038] Among them, TP represents a malware being correctly detected as malware; FN represents a malware being determined as non-malware; FP represents a non-malware being determined as malware; TN represents a non-malware being determined as non-malware.

[0039] This application also proposes a malware detection system based on the ViT Siamese neural network. The system includes:

[0040] A data acquisition unit, which acquires a publicly available malware PE file dataset and deletes the unlabeled PE files in the PE malware dataset;

[0041] A shelling judgment unit, which judges whether the current PE file is a shelled file. If so, after performing shelling removal, it enters the static and dynamic analysis unit for static analysis and dynamic analysis operations. Otherwise, it enters the static and dynamic analysis unit for static analysis and dynamic analysis operations;

[0042] A static and dynamic analysis unit, which performs static analysis and dynamic analysis operations on the PE file respectively. Among them, during static analysis, the original information of the PE file is obtained through decompilation; during dynamic analysis, the PE file is run in a sandbox environment to obtain the information of the PE file in the running state;

[0043] A data processing unit, which merges the data obtained from static analysis and dynamic analysis, converts the merged one-dimensional data into two-dimensional data, then into a grayscale image, and finally divides the grayscale image into a training set and a test set;

[0044] A model design and construction unit, which is used to construct a ViT Siamese neural network model;

[0045] A model training and evaluation unit, which trains the ViT Siamese neural network model using the training set, continuously optimizes and adjusts the hyperparameters in the ViT Siamese neural network model, and uses the test set to evaluate the ViT Siamese neural network model to obtain a trained ViT Siamese neural network model for malware detection.

[0046] Compared with the prior art, the beneficial effects of the technical solution of the present invention are:

[0047] The present invention proposes a malware detection method and system based on a ViT Siamese neural network. First, a publicly available malware PE file dataset is acquired, and the original information and the information in the running state of the PE file are jointly obtained through static analysis and dynamic analysis. The data obtained from static analysis and dynamic analysis are merged, the merged one-dimensional data is converted into two-dimensional data, then into a grayscale image, and finally the grayscale image is divided into a training set and a test set. Then, a ViT Siamese neural network model is constructed, and the ViT Siamese neural network model is trained and tested and evaluated using the training set and the test set respectively, and the parameters are continuously adjusted and optimized to obtain a trained ViT Siamese neural network model for malware detection, which can more fully extract the features of malware and improve the accuracy and recall rate of malware detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1 It represents a schematic flowchart of the malware detection method based on the ViT Siamese neural network proposed in Embodiment 1 of the present invention;

[0049] Figure 2 It represents the basic structure diagram of the PE file proposed in Embodiment 2 of the present invention;

[0050] Figure 3 It represents the structure diagram of the data processing by the Transformer Encoder module proposed in Embodiment 2 of the present invention;

[0051] Figure 4 It represents the schematic diagram of the data processing by the Encoder module proposed in Embodiment 2 of the present invention;

[0052] Figure 5 It represents the schematic diagram of the data processing by the ViT Siamese neural network model proposed in Embodiment 2 of the present invention;

[0053] Figure 6 It represents the schematic diagram of the malware detection system based on the ViT Siamese neural network proposed in Embodiment 3 of the present invention. Detailed implementation manners

[0054] The accompanying drawings are only for illustrative purposes and should not be construed as a limitation to this patent;

[0055] To better illustrate this embodiment, some parts of the accompanying drawings are omitted, enlarged or reduced, and do not represent the actual size;

[0056] For those skilled in the art, it is understandable that some well-known content descriptions in the accompanying drawings may be omitted.

[0057] The technical solutions of the present invention will be further described below in conjunction with the accompanying drawings and embodiments.

[0058] The description of the positional relationship in the accompanying drawings is only for illustrative purposes and should not be construed as a limitation to this patent;

[0059] Embodiment 1

[0060] In this embodiment, a malware detection method based on the ViT Siamese neural network is proposed. The flow schematic diagram of this method is as Figure 1 shown, see Figure 1 , and the method includes the following steps:

[0061] S1. Obtain a publicly available malware PE file dataset and delete the unlabeled PE files in the PE malware dataset; In this embodiment, the publicly available malware PE file dataset obtained is the BODMAS dataset. The BODMAS dataset is an open-source dataset about malware created and maintained by Blue Hexagon and UIUC. After deleting the unlabeled samples in the BODMAS dataset, there are 57,293 malware and 77,142 benign Windows PE files remaining.

[0062] S2. Determine whether the current PE file is a shelled file. If so, perform shell removal and proceed to step S3; otherwise, proceed to step S3;

[0063] S3. Perform static analysis and dynamic analysis operations on the PE file respectively. Among them, during static analysis, obtain the original information of the PE file through decompilation; during dynamic analysis, run the PE file in a sandbox environment to obtain the information of the PE file in the running state;

[0064] S4. Combine the data obtained from static analysis and dynamic analysis, convert the combined one-dimensional data into two-dimensional data, then convert it into a grayscale image, and finally divide the grayscale image into a training set and a test set;

[0065] S5. Construct a ViT Siamese neural network model;

[0066] S6. Use the training set to train the ViT Siamese neural network model, continuously optimize and adjust the hyperparameters in the ViT Siamese neural network model, and use the test set to evaluate the ViT Siamese neural network model to obtain a trained ViT Siamese neural network model for malware detection.

[0067] Example 2

[0068] For the already obtained dataset, determine whether the current PE file is a shelled file. The full name of shelling is executable program resource compression, and the compressed program can be directly run. Some binary program shelling programs, in order to prevent being cracked and decompiled, will implant code to obtain control of the program first and then return the control to the original code, so that the true entry point of the original program can be hidden. Therefore, professional shelling analysis software is required to analyze and remove the shell of the executable file before static analysis and dynamic analysis can be performed on the executable file. In this example, the executable program is detected by the detection tool PEiD to see if it is shelled. If it is shelled, the UPX shell removal tool is used to perform shell removal operations on the executable program, and the shelled executable program and the non-shelled program are mixed together for subsequent static analysis and dynamic analysis of the PE file.

[0069] In the static analysis operation, the original information of the executable program is obtained by reverse engineering the training set and test set data through the compilation tool JadClipse. The basic structure diagram of the PE file is as Figure 2As shown in the figure, the original information of the PE file obtained by decompilation includes: DOS header information, PE signature, PE file header information, PE section optional information, section table, idata section, text section, and data section. After obtaining the original information of the PE file, all the obtained original information is converted into a vector format through the Embedding encoding technology, meaningless data is deleted, and the data is standardized, and rows and items are added to the data. Common Embedding methods include Word2vec Embedding, neural network embedding, and graph embedding. In this embodiment, Word2vec Embeddng is used because word2vec takes an unsupervised form as the training method and can obtain a relatively good-quality embedding representation without labeling.

[0070] In the dynamic analysis operation, the running environment required by the executable program is simulated through a sandbox, and the system process monitoring software is called to record a series of operations such as the reading and writing of the registry, the number of host connections, and the changes in files in the Windows directory and System directory during the running of the program under test. The information obtained about the PE file in the running state includes: the reading and writing of the registry, the number of host connections, the changes in files in the Windows directory and System directory, the log information during the running of the PE file, function call information, and context parameter information. All the obtained information is converted into a vector format through the Embedding encoding technology.

[0071] In step S4, the specific process of merging the data obtained from static analysis and dynamic analysis, converting the merged one-dimensional data into two-dimensional data, then into a grayscale image, and finally splitting the grayscale image into a training set and a test set is as follows:

[0072] S41. Merge the data obtained from static analysis and dynamic analysis of the BODMAS dataset. The total dimension of the sample data merged together is 2372. Standardize the data using the min-max method. Since the grayscale of a grayscale image is the value indicating the brightness of the image, that is, the color depth of the points in a black-and-white image, and the range is from 0 to 255, with black being 0, then multiply all the standardized results by 255 to standardize all the data into the interval of [0, 255]. The formula for data standardization is:

[0073]

[0074] Among them, Y ij represents the value of X ij after standardization, i represents the i-th sample, j represents the j-th dimension, and X max is the maximum value of this feature item, and X minis the minimum value of this feature item;

[0075] S42. To retain all original features and be able to convert one-dimensional data into two-dimensional data, feature items are added to the original data, and the values of the added feature items are all 0; the original 2381 one-dimensional items are added to 2401 one-dimensional items.

[0076] S43. By constructing a Markov transition field, the original 2401 one-dimensional data items are converted into 49*49 two-dimensional data items, and then the two-dimensional data is converted into a grayscale image, and all the overall data sets are divided into a training set and a test set in a ratio of 7:3.

[0077] The process of constructing the Markov transition field is as follows:

[0078] S431. The sequence data of length n is divided into Q quantile bins according to its value range, and each data point i belongs to a unique q i ;

[0079] S432. Construct a Markov transition matrix W of size [Q, Q], where W[i, j] is determined by the frequency of the data in q i being adjacent to the data in q j ;

[0080] S433. Construct a Markov transition field M of size, and the value of M[i, j] is W[q i , q j .

[0081] In this embodiment, the process of constructing the ViT Siamese neural network model and the ViT Siamese neural network model processing data in step S5 is as follows:

[0082] S51. Build a patch module, and the patch module performs a patch operation on the malware grayscale image obtained in S43, divides the grayscale image, performs positional encoding on each segmented image, then flattens the image data into one-dimensional data, and combines the positional encoding with the flattened data;

[0083] S52. Build an Encoder module, and use four Encoder modules to form a Transformer Encoder module. The schematic diagram of the Transformer Encoder module processing data is as Figure 3 shown, and multiple multi-head attention mechanism modules and residual connection modules are introduced. In this embodiment, 6 multi-head attention mechanisms are used, and the current data stream is residually connected to the data stream after extracting the main features by the multi-head attention mechanism, and the two data are added one by one. The process diagram Figure 4As shown, set the batch size to 256, the patch size to 7, and the epoch to 200. Initialize the dropout to 0.01, and set the learnrate to a dynamic value with an initial value of 0.05. Every time the epoch increases by 50, the learn rate decreases by 50%. The grayscale image data will first pass through the patch embedding layer of the VIT model. Since the patch size is set to 7, this layer will cut the malware grayscale image with an original size of 49*49 into images with a size of 7*7. Then, positional encoding is performed on the segmented grayscale images, and then the image data is flattened into one-dimensional data. The grayscale image data first passes through the patch embedding layer of the TransformerEncoder module, and the positional encoding is combined with the flattened data. Then, the obtained data is passed into the Transformer Encoder module for feature extraction. The specific description of the Transformer Encoder is as follows:

[0084] Step1: Perform LN normalization on the input data;

[0085] Step2: Use the multi-head attention mechanism to extract features from the processed data and calculate the feature weights;

[0086] Step3: Perform a residual connection between the original data input in the first step and the data after feature extraction by the multi-head attention mechanism;

[0087] Step4: Perform LN normalization again on the data after the residual connection in the third step;

[0088] Step5: Use MLP to perform a non-linear transformation on the normalized data;

[0089] Step6: Perform a residual connection between the data after the residual connection in the third step and the data after the non-linear transformation by MLP;

[0090] Step7: Perform the first operation on the obtained data again and loop four times repeatedly.

[0091] S53. Build a ViT Siamese network by sharing the loss value and introduce an MLP fully connected layer; see Figure 5 , in the ViT Siamese network, there are two input values. Two predicted values are obtained through the ViT Siamese network. The error between the two predicted values and the actual value is the loss value, and this loss value is shared and used in the ViT Siamese network; after feature extraction by the ViT Siamese network, the GELU activation function of the MLP fully connected layer is used to perform a non-linear output probability value on the data, and finally determine whether it is malware.

[0092] In this embodiment, the process of training the ViT Siamese neural network model using the training set, continuously optimizing and adjusting the hyperparameters in the ViT Siamese neural network model, and evaluating the ViT Siamese neural network model using the test set is as follows:

[0093] S61. Input the grayscale images of the training set into the ViT Siamese neural network model, train using the gradient descent method, and continuously adjust the dropout, learning rate, number of multi-head attention mechanisms, and activation function of the MLP fully connected layer in the ViT Siamese neural network model;

[0094] S62. Based on binary classification, use accuracy and recall as evaluation metrics, and evaluate the ViT Siamese neural network model using the test set.

[0095] Among them, the calculation formula for the accuracy evaluation metric is:

[0096]

[0097] The calculation formula for the recall evaluation metric is:

[0098]

[0099] Among them, TP represents that a malware is correctly detected as malware; FN represents that a malware is determined to be non-malware; FP represents that a non-malware is determined to be malware; TN represents that a non-malware is determined to be non-malware.

[0100] Embodiment 3

[0101] As Figure 6 shown, the present application also proposes a malware detection system based on the ViT Siamese neural network. The system includes:

[0102] A data acquisition unit that acquires a publicly available malware PE file dataset and deletes the unlabeled PE files in the PE malware dataset;

[0103] A shell judgment unit that judges whether the current PE file is a shelled file. If so, after performing unpacking processing, it enters the dynamic and static analysis unit for static analysis and dynamic analysis operations. Otherwise, it enters the dynamic and static analysis unit for static analysis and dynamic analysis operations;

[0104] A dynamic and static analysis unit that performs static analysis and dynamic analysis operations on the PE file respectively. Among them, during static analysis, the original information of the PE file is obtained through decompilation; during dynamic analysis, the PE file is run in a sandbox environment to obtain the information of the PE file in the running state;

[0105] A data processing unit that merges the data obtained from static analysis and dynamic analysis, converts the merged one-dimensional data into two-dimensional data, then into a grayscale image, and finally divides the grayscale image into a training set and a test set;

[0106] A model design and construction unit for constructing a ViT Siamese neural network model;

[0107] A model training and evaluation unit that trains the ViT Siamese neural network model using the training set, continuously optimizes and adjusts the hyperparameters in the ViT Siamese neural network model, and evaluates the ViT Siamese neural network model using the test set to obtain a trained ViT Siamese neural network model for malware detection.

[0108] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the present invention, and are not intended to limit the implementation manners of the present invention. For those of ordinary skill in the art, other different forms of changes or modifications can be made based on the above description. It is not necessary and impossible to enumerate all the implementation manners here. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the claims of the present invention.

Claims

1. A malware detection method based on a ViT Siamese neural network, characterized in that, The method includes the following steps: S1. Obtain the publicly available malicious software PE file dataset, and delete the unlabeled PE files in the PE malware dataset; S2. Determine whether the current PE file is an obfuscated file. If so, perform de-obfuscation processing and execute step S3; otherwise, execute step S3; S3. Perform static analysis and dynamic analysis operations on the PE file respectively. Among them, during static analysis, obtain the original information of the PE file through decompilation; during dynamic analysis, run the PE file in a sandbox environment to obtain the information of the PE file in the running state; S4. Merge the data obtained from static analysis and dynamic analysis, convert the merged one-dimensional data into two-dimensional data, then convert it into a grayscale image, and finally split the grayscale image into a training set and a test set; S5. Construct a ViT Siamese neural network model; S6. Use the training set to train the ViT Siamese neural network model, continuously optimize and adjust the hyperparameters in the ViT Siamese neural network model, and use the test set to evaluate the ViT Siamese neural network model to obtain a trained ViT Siamese neural network model for malware detection.

2. The malware detection method based on the ViT Siamese neural network according to claim 1, characterized in that In step S2, use the detection tool PEiD to detect the PE file to confirm whether the PE file is obfuscated. When the PE file is an obfuscated file, use the UPX de-obfuscation tool for de-obfuscation processing.

3. The malware detection method based on the ViT Siamese neural network according to claim 2, characterized in that In step S3, the original information of the PE file obtained through decompilation includes: DOS header information, PE signature, PE file header information, PE section optional information, section table, idata section, text section, data section. After obtaining the original information of the PE file, convert all the obtained original information into a vector format through the Embedding encoding technology, delete meaningless data and standardize the data, and add rows and items to the data.

4. The malware detection method based on the ViT Siamese neural network according to claim 2, wherein The information of the PE file in the running state obtained includes: reading and writing of the registry, the number of host connections, changes in files in the Windows directory and System directory, log information during the running of the PE file, function call information, context parameter information, and convert all the obtained information into a vector format through the Embedding encoding technology.

5. The malware detection method based on the ViT Siamese neural network according to claim 1, characterized in that The specific process of step S4 is: S41. Merge the data obtained from static analysis and dynamic analysis, standardize the data using the min-max method, and then multiply all the standardized results by 255 to standardize all the data into the interval [0, 255]; S42. Add feature items to the original data, and all the added feature item values are 0; S43. Construct a Markov transition field, and use the Markov transition field to convert the original one-dimensional data into two-dimensional data and convert the two-dimensional data into a grayscale image.

6. The malware detection method based on the ViT Siamese neural network according to claim 5, wherein, In step S43, the process of constructing the Markov transition field is: S431. Divide the sequence data of length n into Q quantile bins according to their value ranges, and each data point i belongs to a unique q i ; Construct a Markov transition matrix W of size [Q, Q], where W[i, j] is determined by the frequency of the data in q i being adjacent to the data in q j ; S433. Construct a Markov transition field M with dimensions, where the value of M[i, j] is W[q i , q j .

7. The malware detection method based on the ViT Siamese neural network according to claim 5, wherein The process of constructing the ViT Siamese neural network model and the ViT Siamese neural network model processing data described in step S5 is: S51. Build a patch module. The patch module performs a patch operation on the grayscale image of the malware obtained in S43, divides the grayscale image, performs position encoding on each divided image, then flattens the image data into one-dimensional data, and combines the position encoding with the flattened data; S52. Build an Encoder module, and use four Encoder modules to form a Transformer Encoder module. Also introduce multiple multi-head attention mechanism modules and residual connection modules. Perform a residual connection between the current data stream and the data stream after extracting the main features through the multi-head attention mechanism, and add the two data streams one by one. The grayscale image data first passes through the patch embedding layer of the Transformer Encoder module, and the position encoding is combined with the flattened data, and then the obtained data is input into the Transformer Encoder module for feature extraction; S53. Build a ViT Siamese network by sharing the loss value, and introduce an MLP fully connected layer; in the ViT Siamese network, there are two input values, and two predicted values are obtained through the ViT Siamese network. The error between the two predicted values and the actual value is the loss value, and this loss value is shared in the ViT Siamese network; after feature extraction by the ViT Siamese network, the GELU activation function of the MLP fully connected layer is used to perform a non-linear output probability value on the data, and finally determine whether it is malware.

8. The malware detection method based on the ViT Siamese neural network according to claim 6, characterized in that, The process of step S6 is as follows: S61. Input the grayscale images of the training set into the ViT Siamese neural network model, and train using the gradient descent method, continuously adjusting the dropout of the ViT Siamese neural network model, the size of the learning rate, the number of multi-head attention mechanisms, and the activation function of the MLP fully connected layer; S62. Based on binary classification, use accuracy and recall as evaluation metrics, and use the test set to evaluate the ViT Siamese neural network model.

9. The malware detection method based on the ViT Siamese neural network according to claim 8, wherein, The calculation formula for the accuracy evaluation metric is: The calculation formula for the recall evaluation metric is: Among them, TP represents a malware being correctly detected as malware; FN represents a malware being determined as non-malware; FP represents a non-malware being determined as malware; TN represents a non-malware being determined as non-malware.

10. A malware detection system based on a ViT siamese neural network, characterized in that, The system includes: A data acquisition unit that acquires a publicly available malware PE file dataset and deletes the unlabeled PE files in the PE malware dataset; A shell judgment unit that judges whether the current PE file is a shelled file. If so, after performing unpacking processing, it enters the static and dynamic analysis unit for static and dynamic analysis operations. Otherwise, it enters the static and dynamic analysis unit for static and dynamic analysis operations; A static and dynamic analysis unit that performs static and dynamic analysis operations on the PE file respectively. Among them, during static analysis, the original information of the PE file is obtained through decompilation; during dynamic analysis, the PE file is run in a sandbox environment to obtain the information of the PE file in the running state; A data processing unit that merges the data obtained from static analysis and dynamic analysis, converts the merged one-dimensional data into two-dimensional data, then into a grayscale image, and finally divides the grayscale image into a training set and a test set; A model design and construction unit for constructing a ViT Siamese neural network model; A model training and evaluation unit that trains the ViT Siamese neural network model using the training set, continuously optimizes and adjusts the hyperparameters in the ViT Siamese neural network model, and evaluates the ViT Siamese neural network model using the test set to obtain a trained ViT Siamese neural network model for malware detection.

Citation Information

Patent Citations

  • Malicious software family detection method, storage medium and computing equipment

    CN111027069A

  • Multi-stage training method of face key point detection model based on ViT network

    CN115311728A