Malware detection method based on semantic analysis and bidirectional encoding representation

CN116432184BActive Publication Date: 2026-08-28SHENYANG LIGONG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310588930.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-24
Publication Date
2026-08-28
Estimated Expiration
2043-05-24

AI Technical Summary

Technical Problem

不仅如此,物联网的发展使得所有的事物都相互连接并通过网络交换信息,但这也允许跨多个平台的互连设备大量扩散恶意软件,物联网生态系统也极易受到通过传统计算机和智能手机进行的大量恶意软件攻击

Benefits of technology

[0060]本发明分析了基于上下文语义分析对于恶意代码API调用序列检测的重要程度和实际需求,了解了API调用序列与特定的病毒形式和执行环境无关,存在很大的普适性;其次,根据以往基于语义分析模型与恶意代码检测的相关技术,对比了不同语义分析模型的优劣,提出了基于上下文语义分析和双向编码表征的检测模型;在此基础上,构建ConvLSTM模型完成了恶意代码的API调用序列检测;最后使用PyQt技术搭建了恶意代码API调用序列检测系统,提供更直观地恶意代码检测效果。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116432184B_ABST
    Figure CN116432184B_ABST
Patent Text Reader

Abstract

The present application aims at the problem of ambiguous word representation and lack of context semantics in traditional model detection of malicious code, and proposes a malware detection method based on semantic analysis and bidirectional encoding representation, which combines BERT with convolution recurrent network based on external attention mechanism, uses malware API function call sequence as the feature of model learning, and performs static analysis to detect existing malware; the API call function sequence has correlation in context and semantics, BERT is used for word representation task, and semantic information is received from the sequence; the convolutional neural network and the long short-term memory network are respectively used for completing secondary feature extraction and API function chain relationship mining; and the attention mechanism is added after the long short-term memory network, so that the key information in the text can be better focused, the influence of noise is reduced, and the accuracy in the text classification task is improved; the present application is not affected by the change and deformation of malicious code itself, and the accuracy reaches 98.81%.
Need to check novelty before this filing date? Find Prior Art

Citation Information

Patent Citations

  • Malicious software detection method based on comparative learning

    CN116541838A

  • Computer-Automated Systems and Methods for Cross-Platform Code Threat Detection

    US20260147887A1