A Ransomware Classification Method and System Based on a Large Model
By employing a large-model-based ransomware classification method, deep learning large-model features are extracted and multi-level classification is performed. Combined with a dynamic adaptive update mechanism, this method solves the problems of low ransomware detection accuracy, high resource consumption, and system complexity in existing technologies, achieving efficient and easy-to-use ransomware protection.
Patent Information
- Application Number
- CN202411554796.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-04
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2044-11-04
AI Technical Summary
Existing ransomware detection and classification methods suffer from low detection accuracy, insufficient model generalization ability, high resource consumption, and high system complexity when facing ransomware with frequent mutations and complex encryption methods, making them difficult to widely apply to small and medium-sized enterprises and individual users.
A ransomware classification method based on a large model is adopted. It uses a deep learning large model for feature extraction and multi-level classification, combined with a dynamic adaptive update mechanism, to achieve efficient detection and classification of ransomware, reduce resource consumption and simplify user operations.
It improves the accuracy and generalization of ransomware detection, reduces resource consumption, simplifies system operation, adapts to large-scale data environments and the rapidly changing ransomware ecosystem, and enhances the overall level of network security defense.
Smart Images

Figure CN119740136B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of electronic digital data processing technology, specifically to a ransomware classification method and system based on a large model. Background Technology
[0002] With the increasing sophistication of cyberattacks, ransomware has become a major threat in the field of cybersecurity. Traditional ransomware detection and classification methods typically rely on signature-based matching or behavior-based detection. However, these methods are increasingly showing their limitations when facing new ransomware variants with frequent changes and complex encryption methods. While machine learning-based ransomware detection and classification methods have made some progress, they still suffer from the following problems and drawbacks:
[0003] 1. Limitations of Feature Extraction: Traditional machine learning methods rely on manually designed features or simple automated feature extraction when classifying ransomware. This approach often fails to capture the subtle differences between diverse ransomware variants, resulting in low classification accuracy.
[0004] 2. Insufficient Model Generalization Ability: Existing machine learning models often perform poorly when faced with unseen ransomware variants because their generalization ability is limited and they struggle to cope with the diversity within virus families. During training, these models typically fail to effectively learn the deep-seated patterns and behavioral characteristics of ransomware, resulting in low recognition rates for new viruses.
[0005] 3. High Cost of Dynamic Analysis: While behavior-based dynamic analysis can effectively combat encrypted and obfuscated ransomware, its analysis process is time-consuming and resource-intensive, making it difficult to apply to large-scale datasets. This paper discusses the application of dynamic analysis in ransomware detection and points out its limitations in practical deployment, especially in large-scale network environments.
[0006] 4. Complexity and Ease of Use of Existing Technologies: Most existing ransomware detection and classification systems are complex to configure and operate, requiring users to possess a high level of professional knowledge. This limits their widespread application among small and medium-sized enterprises or individual users. The complexity of most existing ransomware defense systems on the market is one of the important factors affecting user experience.
[0007] The root cause of these problems lies in the fact that existing methods struggle to simultaneously balance feature representation capabilities and model generalization performance, and they fall short when facing the rapidly evolving ransomware ecosystem. In addressing these issues, traditional methods often encounter the challenge of improving detection accuracy while reducing resource consumption and operational complexity. Therefore, a more reliable and efficient ransomware protection solution is needed. Summary of the Invention
[0008] This invention addresses the problems of low efficiency, poor generalization ability, high resource consumption, and system complexity in ransomware detection and classification. It provides a ransomware classification method and system based on a large model. By introducing large model technology, it overcomes the limitations and shortcomings of existing ransomware detection and classification methods, achieving efficient detection and accurate classification of diverse ransomware, enhancing the model's generalization ability, reducing resource consumption, improving system usability and applicability, and adapting to large-scale data environments and the rapidly evolving ransomware ecosystem. This invention will significantly improve the overall level of network security defense, providing users with a more reliable and efficient ransomware protection solution.
[0009] With the rapid development of information technology and the widespread adoption of the internet, ransomware has become a highly threatening form of cyberattack. These viruses encrypt victims' critical data files, forcing them to pay a ransom to regain access. While existing ransomware detection and classification methods have achieved some success in certain specific scenarios, they still face a series of insurmountable technical challenges. Therefore, this invention addresses the deficiencies and shortcomings of existing technologies by proposing a ransomware classification method and system based on a large-scale model, aiming to improve the detection accuracy, classification accuracy, and overall system performance of ransomware.
[0010] (1) Improving the ability to detect and classify variant ransomware: Existing ransomware detection methods rely on signature matching or behavioral analysis, which are often ineffective against frequently mutated ransomware. Signature matching methods cannot handle obfuscated or encrypted variants, while behavioral analysis methods are difficult to apply widely due to their high computational cost. This invention employs large-model technology, which can automatically learn deep feature representations from a large number of virus samples and capture the essential characteristics of ransomware through a higher-dimensional feature space. Thus, even when faced with unseen new variants, this invention can effectively detect and accurately classify them, thereby improving the comprehensiveness and accuracy of ransomware detection.
[0011] (2) Enhancing the generalization ability of the model: Existing machine learning models lack generalization ability, mainly reflected in their low classification accuracy when facing new ransomware. This is primarily because these models struggle to learn a sufficiently broad range of virus features during training, especially common features across multiple virus families. This invention uses a large model to learn more general feature representations, enabling the model to exhibit stronger robustness and generalization ability when facing different virus families and variants, thereby significantly improving the recognition rate of new ransomware.
[0012] (3) Reducing resource consumption in the detection and classification process: While dynamic analysis has advantages in dealing with obfuscated or encrypted ransomware, its computational overhead and time consumption are extremely high, limiting its application in practical scenarios. Static analysis, on the other hand, performs poorly when facing complex variants. This invention reduces reliance on dynamic analysis by combining the feature learning capabilities of large models, while improving the effectiveness of static analysis. Thus, without significantly increasing computational resource consumption, this invention can provide an efficient ransomware detection and classification scheme, suitable for real-time threat detection in large-scale network environments.
[0013] (4) Improving the system's ease of use and applicability: Existing ransomware detection and classification systems are typically complex in design, difficult to operate, and require a high level of professional skills from users, thus limiting their widespread adoption in practical applications. Especially among small and medium-sized enterprises and individual users, where professional knowledge and technical support are lacking, existing systems struggle to achieve their intended effectiveness. This invention designs an easy-to-use ransomware classification system. By introducing an automated feature extraction and classification process, it reduces reliance on manual intervention and professional knowledge, enabling ordinary users to quickly deploy and use the system, effectively defending against ransomware threats.
[0014] (5) Solving the classification problem in large-scale datasets: With the explosive growth of network data, existing ransomware detection systems often face problems of insufficient computing resources and slow processing speed when dealing with large-scale datasets. This invention improves the processing efficiency on large-scale datasets by adopting parallel computing technology and an optimized large model structure, enabling the system to quickly identify and classify ransomware in massive network traffic, meeting the real-time detection needs of modern network environments.
[0015] (6) Addressing the rapidly evolving ransomware ecosystem: Ransomware development exhibits a rapid evolution and diversification trend. Traditional detection and classification methods cannot keep up with the evolution of virus families in a timely manner, leading to a decline in detection effectiveness. This invention, through the adaptive learning capability of a large model, can continuously adjust and optimize the classification model during the process of virus ecosystem changes, thereby maintaining efficient detection and accurate classification of new ransomware and reducing security risks in the network environment.
[0016] This invention provides a ransomware classification method based on a large model, comprising the following steps:
[0017] S1. The data collection and preprocessing module collects data and captures ransomware data for preprocessing to obtain preprocessed data.
[0018] S2, the large model training and feature extraction module uses a deep learning large model to learn and extract features from the preprocessed data to obtain high-level feature representations. The deep learning large model is a large model that has been pre-trained in an unsupervised or semi-supervised manner and then fine-tuned based on the feature corpus supervised by SFT.
[0019] S3. The multi-level classification module performs multi-level classification of ransomware based on high-level feature representations. Multi-level classification includes preliminary classification and refined classification. In the preliminary classification, ransomware samples are assigned to virus families or types based on high-level features. In the refined classification, graph-level feature vectors of ransomware samples are extracted through graph neural networks, and a classifier is used to classify the graph-level feature vectors to identify variants and behavioral patterns of ransomware. It is then determined whether the identified ransomware is a new type of ransomware sample. If yes, proceed to step S4; otherwise, proceed to step S5.
[0020] S4. The dynamic adaptive update module dynamically adjusts the parameters of the deep learning model based on the new ransomware sample, and proceeds to step S5.
[0021] S5. Users classify ransomware results through the user interaction and management module, completing a ransomware classification method based on a large model.
[0022] In the ransomware classification method based on a large model described in this invention, as a preferred embodiment, in step S1, the data collection and preprocessing module collects historical network traffic data, historical file system data, historical behavior logs, and network traffic data, file system data, and behavior logs to be analyzed for training the deep learning large model. The ransomware data includes traffic features related to ransomware extracted from network communication data packets, suspected ransomware samples / behavior logs captured from file system data, and operation behavior records in the system.
[0023] Traffic characteristics associated with ransomware include: suspicious IP addresses, port usage, attack payload, packet length, and file type hashes. Suspected ransomware sample / behavior logs include: records of suspicious file creation and modification, and operation behavior records including file access and process startup.
[0024] Preprocessing methods include data cleaning, formatting, normalization, and feature selection. Data cleaning involves removing invalid, duplicate, or noisy data; formatting involves converting data from different sources into a uniform format; normalization involves normalizing numerical features; and feature selection involves selecting the most representative data features based on predefined criteria.
[0025] The ransomware classification method based on a large model described in this invention, as a preferred embodiment, includes the following steps in step S2:
[0026] S21. Use the collected historical ransomware data to train the deep learning model. The historical ransomware data consists of historical network traffic data, historical file system data, and historical behavior logs collected by the data collection and preprocessing module. The historical ransomware data includes virus families and virus variants.
[0027] S22. Use a deep learning large model to extract features and generate pseudo-labels. The pseudo-labels include the family characteristics, sample characteristics and intelligence characteristics of ransomware. The pseudo-labels are combined with manually labeled real data to obtain a fine-tuned dedicated dataset and fine-tune the deep learning large model.
[0028] S23. By combining the self-attention mechanism with the retraining of the embedding layer, the deep learning large model maps the input data to the corresponding feature space and generates high-level feature representations.
[0029] The ransomware classification method based on a large model described in this invention, as a preferred embodiment, includes the following method in step S22 for fine-tuning the deep learning large model:
[0030] S221. In the feature extraction stage, the deep learning large model generates pseudo-labels based on specific variant features.
[0031]
[0032] Where, x i is the feature vector of the original ransomware sample, ∫ is the feature extraction function, and the specific variant features include encryption algorithms and propagation methods;
[0033]
[0034] Wherein, C(x) i S(x) is a special encryption algorithm. i The difference lies in the file structure.
[0035] S222. Utilize multi-level feature representation learning to simultaneously capture high-level family features and fine-grained variant features:
[0036] z i =Concat(h f ,h u );
[0037] Among them, z i For joint features, h f As a high-level family characteristic, h u It is a fine-grained variant characteristic;
[0038] S223. By optimizing the objective function L, a joint loss of family and variant features is learned simultaneously:
[0039] L = L family (h f )L variant (h u );
[0040] Where L is the joint loss function, L family For family classification loss, L variant For variant classification loss;
[0041] S224. For new variant data, large deep learning models introduce an adaptive learning mechanism, updating parameters through gradient descent in each training iteration:
[0042] θ t+1 =θ t -αΔ θ L(x new ,θ t );
[0043] Where α is the learning rate dynamically adjusted based on the new variant data, and Δ θ L is the gradient of the joint loss function L with respect to the model parameters θ, Δ θ This represents the amount of time the model parameters are updated.
[0044] S225. Generate adversarial examples x using adversarial training methods. adu adversarial example x adu By adding a perturbation term ∈·sign(Δ) to the original input x x L(x,y)) is used to generate:
[0045] x adu =x+∈·sign(Δ x L(x,y));
[0046] Where ∈ controls the magnitude of the perturbation, sign(Δ) x L(x,y)) is the sign of the gradient of the loss function with respect to the input x, Δ x This refers to the disturbance or change in the input data;
[0047] S226. Use the LoRA method to adjust the parameters of a large deep learning model. LoRA decomposes the original weight matrix W into low-rank matrices A and B, where the dimensions of A and B are smaller than those of the original weight matrix W.
[0048] Freeze the original weight matrix W without updating it, and only train the newly added low-rank matrices A and B. During training, only the newly added low-rank matrices AA and BB participate in the gradient update, while the original weight matrix W remains unchanged.
[0049] The adjusted weight W' = W + ΔW.
[0050] In the ransomware classification method based on a large model described in this invention, as a preferred embodiment, in step S226, ΔW = A × B;
[0051] The dimension of low-rank matrix A is d×r, and the dimension of low-rank matrix B is r×k, where r is the rank and r is less than d and k.
[0052] In the ransomware classification method based on a large model described in this invention, as a preferred embodiment, in step S23, the deep learning large model extracts basic features and abstract features from the input data during the training process. The basic features include byte frequency and operating system calls; the abstract features include the virus's behavior patterns and file encryption methods; and the high-level features are represented by the complex behavior patterns and features of the virus output by the deep learning large model after understanding the input data.
[0053] Raw or processed data, including the original feature representation of virus samples, is input into the embedding layer. The embedding layer maps the discrete input to a continuous vector space and learns distributed representations of words or byte sequences. The discrete input includes words or byte sequences.
[0054] In the feature extraction stage:
[0055] H l =Attention(H l-1 )·W l ;
[0056] Among them, H l For the feature representation of the l-th layer, Attention(H) l-1 ) represents the feature representation H in the previous layer. l-1 The representation obtained by applying the self-attention mechanism, W l Let be the weight matrix of the l-th layer.
[0057] In the ransomware classification method based on a large model described in this invention, as a preferred embodiment, in step S3, the refined classification model adopts a graph neural network;
[0058] The refined classification model represents the characteristics of ransomware samples' behavior patterns, file encryption methods, and ransom demands as nodes in a graph, and uses edges to represent the dependencies or similarities between nodes;
[0059] During training, each node receives information from its neighboring nodes through a message passing mechanism and updates its own feature representation to capture the complex relationships in the virus samples.
[0060] Then, graph pooling is used to aggregate the features of the entire graph into graph-level feature vectors, which facilitates subsequent fine-grained classification.
[0061] Finally, the graph-level feature vectors are classified using a classifier to identify specific variants, infection routes, and impact ranges of ransomware. The classification results include the specific ransomware variant name, infection route, and impact range.
[0062] The ransomware classification method based on a large model described in this invention, as a preferred approach, involves classifying the extracted graph-level feature vectors during the fine-grained classification process to identify specific variants of ransomware. The classification relies on feature vectors obtained from the graph neural network, which represent the behavior patterns, encryption methods, and ransom demands of the ransomware samples.
[0063] The classifier is based on a fully connected neural network. It uses multi-layer linear transformations and non-linear activation functions to gradually map the input high-dimensional feature vector to a lower-dimensional space for classification.
[0064] The feature vectors are processed through multiple layers of a fully connected neural network. Each layer performs a linear transformation on the original vectors and applies a non-linear activation function, enabling the large deep learning model to learn the classification boundary.
[0065] The output of each layer is:
[0066] h (l+1) =σ(W (l) ·h (l) +b (l) );
[0067] Among them, h (l) W is the input feature of the l-th layer. (l) Let b be the weight matrix. (l) Here, σ is the bias term, and σ is the nonlinear activation function.
[0068] The final layer is the Softmax classification layer, which converts the output of the neural network into a probability distribution. Each output value represents the probability that the input feature vector belongs to a certain ransomware variant.
[0069]
[0070] Among them, z i Let P(y) be the i-th joint feature output from the last layer, C be the number of classification categories, and P(y) be the i-th joint feature output from the last layer. i |x) represents the probability that the input sample is classified into the i-th category.
[0071] In the ransomware classification method based on a large model described in this invention, as a preferred embodiment, in step S4, the ransomware classification system incorporates new ransomware samples into the training set and uses incremental learning to update the parameters of the deep learning large model.
[0072] Ransomware classification systems can perform real-time deep learning of large models;
[0073] The ransomware classification system has established a user feedback mechanism, allowing security experts or users to verify and provide feedback on the classification results.
[0074] This invention provides a ransomware classification system based on a large model. The ransomware classification system includes a data collection and preprocessing module, a large model training and feature extraction module, a multi-level classification module, a dynamic adaptive update module and a user interaction and management module, all electrically connected in sequence.
[0075] The deep learning model is either the Transformer model or the GPT model, and the classifier of the multi-level classification module is based on a fully connected neural network.
[0076] The user interaction and management module provides a user interface and API interface, supporting users to perform system configuration, data input, result viewing and management operations, and setting up a permission management mechanism. Users can configure system parameters, upload data and view classification results through the user interface. The graphical user interface also supports chart display, allowing users to view statistical analysis and trend changes of classification results. The user interaction and management module provides a RESTful API, supporting programmatic integration with external systems for data input, classification result output and model management.
[0077] This invention overcomes the limitations and shortcomings of existing ransomware detection and classification methods by introducing large-scale model technology. It achieves efficient detection and accurate classification of diverse ransomware, enhances the model's generalization ability, reduces resource consumption, improves system usability and applicability, and adapts to large-scale data environments and the rapidly evolving ransomware ecosystem. These technological improvements will significantly enhance the overall level of network security defense, providing users with a more reliable and efficient ransomware protection solution.
[0078] This invention proposes a ransomware classification method and system based on a large model, aiming to solve the problems of low efficiency, poor generalization ability, high resource consumption, and system complexity in existing ransomware detection and classification technologies. The technical solution of this invention has the following key features and innovations:
[0079] Large-Model-Driven Feature Extraction and Classification: This invention employs a deep learning large-model approach, leveraging its powerful feature learning capabilities to automate feature extraction from ransomware samples. By learning from massive amounts of historical ransomware data, the large-model can generate highly abstract feature representations. These features can not only accurately distinguish different types of ransomware but also effectively identify new variants and families.
[0080] Multi-level classification architecture: To improve the accuracy and efficiency of classification, this invention designs a multi-level classification architecture. In the first level, the system performs preliminary classification of ransomware based on extracted high-level features, assigning it to a specific virus family or category. In subsequent levels, the system further analyzes the specific behavioral patterns and characteristics of the virus to complete a refined classification. This hierarchical structure ensures that the system maintains efficient and accurate classification capabilities even when faced with complex virus samples.
[0081] Dynamic Adaptive Model Update: This invention introduces a dynamic adaptive model update mechanism. When new ransomware samples or variants emerge, the system can rapidly update the existing large model parameters through incremental learning, ensuring that the model can adapt to changes in the viral ecosystem in a timely manner. This mechanism reduces the need for manual intervention while ensuring the system's continued efficiency and accuracy.
[0082] Efficient resource utilization and parallel computing: Addressing the large-scale data processing demands that may arise during ransomware detection and classification, this invention optimizes the model's computational architecture, employing parallel computing techniques and efficient resource allocation strategies. This enables the system to maintain low resource consumption and high operating speed when processing massive amounts of data, making it suitable for large-scale deployment in real-world network environments.
[0083] Simplified User Interface and Automated Operation: This invention places particular emphasis on ease of use, designing a simplified user interface and introducing a highly automated operation process. Users only need to perform minimal configuration to start the system and perform ransomware detection and classification, which significantly lowers the barrier to entry and expands its applicability to small and medium-sized enterprises and individual users.
[0084] This invention, by introducing large-scale modeling technology and an innovative classification architecture, constructs a highly efficient, accurate, and easy-to-use ransomware classification method and system, which can significantly improve the effectiveness of ransomware detection and defense in practical applications. This technical solution not only covers a wide range of ransomware types and variants but also adapts to the rapidly changing network threat environment, providing users with comprehensive security protection.
[0085] The present invention has the following advantages:
[0086] (1) Highly Intelligent Detection and Classification: This invention achieves intelligent detection and classification of ransomware through the deep learning capabilities of a large model. Compared with traditional signature matching methods, this invention can automatically learn and extract deep-level features, thereby effectively dealing with frequently mutated ransomware. This not only improves the accuracy of detection but also significantly reduces reliance on manual intervention, reducing false positives and false negatives.
[0087] (2) Strong generalization ability: Traditional machine learning models often fail when dealing with new ransomware, especially when virus variants evolve rapidly. The large model of this invention learns common features of a wide range of virus families, giving the system a stronger generalization ability. This means that the system can better cope with different types of ransomware, regardless of which virus family it belongs to, ensuring efficient detection and classification.
[0088] (3) Efficient Resource Utilization and Parallel Processing: When processing large-scale datasets, traditional dynamic analysis methods often face bottlenecks such as high computational resource consumption and slow processing speed. This invention significantly improves resource utilization by employing parallel computing technology and an optimized model architecture, enabling the system to maintain efficient operation in massive data environments. This efficiency provides technical support for real-time detection and classification, which is difficult for traditional methods to achieve.
[0089] (4) Simplified User Experience: Compared with traditional systems, this invention places particular emphasis on ease of use, designing a simplified user interface and automated operation processes. Users do not need in-depth professional knowledge to easily complete the system configuration and operation, lowering the technical threshold and expanding the system's applicable user group, including small and medium-sized enterprises and individual users. This is a significant advantage in existing complex and demanding systems.
[0090] (5) Real-time adaptation to changes in the ransomware ecosystem: Traditional systems are typically slow to react to changes in the virus ecosystem and struggle to adapt to new threats. This invention, through a dynamic adaptive model update mechanism, can rapidly adjust system parameters to respond to the emergence of new ransomware. This real-time adaptability ensures that the system remains forward-looking in responding to the evolution of ransomware, reducing potential security risks.
[0091] (6) Compared with existing technologies, this invention demonstrates significant advantages in intelligent detection, resource utilization, user experience, data fusion, ecological adaptability, and defense system integration. These beneficial effects not only improve the overall level of ransomware detection and defense, but also provide users with a more efficient and comprehensive security protection solution, far exceeding the capabilities of traditional technologies. Attached Figure Description
[0092] Figure 1This paper presents a ransomware classification method and system architecture and flowchart based on a large model.
[0093] Figure 2 A flowchart illustrating the data preprocessing process of a ransomware classification method and system based on a large model;
[0094] Figure 3 This is a flowchart illustrating the large-model training and feature extraction process of a ransomware classification method and system based on a large model.
[0095] Figure 4 This is a flowchart illustrating a ransomware classification method and system based on a large model, and a multi-level classification module for hierarchical classification of ransomware.
[0096] Figure 5 This is a flowchart of a ransomware classification method and system based on a large model, and its dynamic adaptive update module. Detailed Implementation
[0097] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments.
[0098] Example 1
[0099] like Figures 1-5 As shown, the present invention provides a ransomware classification method and system based on a large model. The system mainly consists of a data preprocessing module, a large model feature extraction module, a multi-level classification module, a dynamic update module, and a user interaction module.
[0100] like Figure 1 As shown, the overall architecture of the ransomware classification system based on a large model includes multiple modules such as data collection and preprocessing, large model training and feature extraction, multi-level classification, dynamic adaptive updating, and user interaction and management. Each module interacts with data and instructions through internal interfaces to form a complete ransomware classification and defense system.
[0101] Data collection and preprocessing module: This module is responsible for collecting data from various sources such as network traffic, file system, and behavior logs, and performing preprocessing operations such as cleaning, formatting, and normalization on the data to ensure the quality and consistency of the input data.
[0102] Large-scale model training and feature extraction module: Utilizing a large deep learning model, this module learns and extracts features from the preprocessed data, generating high-level feature representations. These features will be used in subsequent classification steps.
[0103] Multi-level classification module: Based on features extracted from a large model, the system performs multi-level classification of ransomware, including preliminary classification and refined classification. Preliminary classification is responsible for identifying virus families or types, while refined classification further identifies specific variants and behavioral patterns of the virus.
[0104] Dynamic Adaptive Update Module: When new ransomware samples emerge, this module is responsible for dynamically adjusting the parameters of the large model, ensuring that the model can adapt to the new threat environment in a timely manner through incremental learning.
[0105] User interaction and management module: Provides user interface and API interface, allowing users to perform operations such as system configuration, data input, and result viewing.
[0106] Step 1: Data Collection and Preprocessing Module
[0107] like Figure 2 As shown, the data collection and preprocessing module is the foundation of the entire system, responsible for collecting information from multiple data sources and standardizing it.
[0108] ① Data Collection: Network Traffic Data: By capturing data packets in network communication, traffic characteristics related to ransomware are extracted, such as suspicious IP addresses, port usage, attack payloads, packet lengths, file type hashes, etc. File System Data: The file system is scanned to capture possible ransomware samples and behavioral logs, such as records of suspicious file creation and modification. Behavioral Logs: Various operational behaviors in the system are recorded, including file access and process startups, for analysis of potential ransomware activity.
[0109] ② Data Preprocessing: Data Cleaning: Remove invalid, duplicate, or noisy data to ensure the accuracy of subsequent processing. Formatting: Convert data from different sources into a uniform format for subsequent module processing. Normalization: Normalize numerical features to prevent data of different scales from affecting classification results. Feature Selection: Select the most representative data features according to predefined criteria to reduce dimensionality and computational complexity.
[0110] Step 2: Large Model Training and Feature Extraction Module
[0111] like Figure 3 As shown, after data preprocessing, the core large-scale model training and feature extraction module will be performed using a deep learning model (such as the Transformer or GPT model). This module relies on the model's self-attention mechanism to extract important features from the complex input ransomware data.
[0112] Model Selection: The system employs pre-trained large models, such as the Transformer model. These models possess powerful learning capabilities, enabling them to extract abstract features from large amounts of complex data. Pre-trained on large datasets (e.g., Transformer, GPT models), they have acquired rich language and sequence feature learning capabilities, demonstrating a deep understanding, particularly regarding text structure and temporal dependencies. Through fine-tuning, these models can quickly adapt to ransomware detection tasks and be optimized according to specific needs, ensuring optimal performance in ransomware classification tasks.
[0113] Model Training: The model is trained using collected historical ransomware data. Training data should include samples from different virus families and variants to ensure the model can learn the diverse characteristics of viruses. Through supervised learning, the model learns to map input data to the corresponding feature space, generating high-level feature representations. Simultaneously, a dedicated dataset related to ransomware is selected for fine-tuning the pre-trained model. During fine-tuning, multiple types of ransomware samples are used to ensure the model can learn the characteristics of different families and variants. Supervised learning is employed for fine-tuning, using classification labels to guide the model's learning process. During fine-tuning, the focus is on the model's performance in virus variant identification to ensure its generalization ability. During training, feature extraction is not limited to raw features but also generates more abstract high-level feature representations, further improving the model's detection performance.
[0114] Model fine-tuning: Based on SFT-supervised feature corpus fine-tuning, the large model is first pre-trained unsupervised or semi-supervised to output a model with preliminary feature learning capabilities, able to identify basic ransomware characteristics. Next, pseudo-labels are generated through feature extraction, including ransomware family characteristics (such as specific encryption algorithms and propagation methods), sample characteristics (such as file structure and code patterns), and intelligence characteristics (such as associated IP addresses and domain names). These pseudo-labels are combined with manually labeled real data to form a comprehensive dataset for fine-tuning.
[0115] During fine-tuning, particular emphasis was placed on the model's performance in identifying ransomware variants. To this end, a series of techniques were employed to enhance the model's variant identification capabilities: First, during the feature extraction stage, fine-grained pseudo-labels (including specific encryption algorithms, propagation methods, etc.) were generated based on the characteristics of the virus variants. These pseudo-labels, generated based on these characteristics, marked the unique features of the virus variants. In the feature extraction stage, it was assumed that the feature vector of the original ransomware sample was x. i pseudo-tags Generate based on specific variant characteristics (such as encryption algorithms, propagation methods, etc.).
[0116]
[0117] Here, ∫ is a feature extraction function that targets specific variant behaviors of ransomware, such as special encryption algorithms C, file structure differences S, etc.
[0118]
[0119] This process generates fine-grained pseudo-labels to annotate the unique features of the variants. The dataset annotated with pseudo-labels contains virus family characteristics (such as typical ransomware behavior patterns) and variant characteristics (such as minor differences in file structure).
[0120] Secondly, by utilizing multi-level feature representation learning, both high-level family features and fine-grained variant features can be captured simultaneously, improving the classification ability for different viral variants. The high-level family feature representation is set as h. f Fine-grained variant characteristics are represented by h u The joint features learned through the neural network are represented as follows:
[0121] z i =Concat(h f ,h u );
[0122] Joint features are achieved by splicing together high-level family features h. f and fine-grained variant characteristics h u This feature combines family-level characteristics with specific variant details, used to distinguish and classify virus families and specific variants.
[0123] By optimizing the objective function L, the joint loss for learning both family and variant features is: L = L family (h f )L variant (h u );
[0124] The joint loss function L is used to simultaneously optimize the family classification loss L. family And variant classification loss L variant It ensures that the model learns feature representations at both the family and variant levels during training, thereby improving its ability to distinguish between virus families and variants.
[0125] For novel variant data, the model introduces an adaptive learning mechanism. Assume the features of the new data are represented as x. new The model parameters θ are dynamically adjusted through an online update mechanism, and the learning rate α is adaptively adjusted.
[0126] θ t+1 =θ t -αΔ θ L(x new,θ t )
[0127] Here, α is dynamically adjusted based on the data from the new variant, ensuring the model has good adaptability when facing new variants. Parameters are updated using gradient descent in each training iteration. The learning rate α controls the step size of each update, Δ... θ L is the gradient of the loss function L with respect to the model parameters θ, Δ θ The update amount of the model parameters is achieved through iterative updates using optimization algorithms such as gradient descent during training to reduce the model's prediction error.
[0128] Simultaneously, adversarial examples x are generated through adversarial training methods. adu To mimic possible variant behaviors, adversarial examples are generated using the following formula:
[0129] x adu =x+∈·sign(Δ x L(x,y))
[0130] By adding a perturbation term ∈·sign(Δ) to the original input x x L(x,y)) is used to generate adversarial examples x. adu Here, ∈ controls the magnitude of the perturbation, sign(Δ) x L(x,y)) denotes the sign of the gradient of the loss function with respect to the input x, Δ x This refers to the perturbation or change in the input data, typically used in adversarial training to enhance the model's robustness to small changes by introducing perturbations. This formula is used to generate misleading adversarial examples on the model to improve its robustness and defense against adversarial attacks.
[0131] Furthermore, meta-learning techniques are employed to ensure the model can quickly adapt to limited variant data, improving classification accuracy for novel variants. Subsequently, the message segmentation model and message state model are trained separately to ensure the model can accurately parse feature information from messages.
[0132] To reduce computational scale, the optimized lightweight model version uses the LoRA (Low-Rank Adaptation) method for parameter tuning. Its core idea is to reduce the number of parameters that need to be trained, thereby reducing computational resource consumption. Specifically, LoRA focuses on the weight matrix of the self-attention layer in the model, decomposing it into a low-rank matrix to reduce the number of parameters while maintaining the model's expressive power.
[0133] Specific steps for parameter adjustment using the LoRA method
[0134] Low-rank decomposition of the original weight matrix
[0135] The core of the Transformer model is the self-attention mechanism, where the weight matrix W typically has high dimensionality. In the LoRA method, the original weight matrix W is decomposed into two smaller low-rank matrices A and B, satisfying W≈A×B, where the dimensions of A and B are much smaller than the original matrix W.
[0136] ΔW=A×B
[0137] Here, A is a low-rank matrix with dimensions typically d×r, and B is another low-rank matrix with dimensions r×k, where r represents the rank, which is the degree of dimensionality reduction. To achieve a significant reduction in the number of parameters, r is usually much smaller than d and k, thereby reducing computational complexity and memory consumption while maintaining model performance.
[0138] Specifically, d and k are the dimensions of the original weight matrix, while r is a smaller value used to approximate these dimensions. By limiting the size of r, the LoRA method can fine-tune only the newly added low-rank matrices A and B, while keeping the original weight matrix W unchanged, thereby effectively reducing computational overhead.
[0139] During the fine-tuning phase, LoRA freezes the original weight matrix W in the Transformer model and does not update it. Instead, it trains only the newly added low-rank matrices A and B. Since the number of parameters in A and B is much smaller than that in W, this greatly reduces the number of parameters that need to be fine-tuned.
[0140] During training, only the newly added low-rank matrices AA and BB participate in gradient updates, while the original weight matrix W remains unchanged. This approach reduces computational overhead and improves training efficiency, making it particularly suitable for large-scale models. The fine-tuned weights W' = W + ΔW, i.e., W' = W + A × B, where A and B are the core components of the training. A significant advantage of the LoRA method is that it concentrates the model's additional computational burden on the low-rank matrices, maintaining the model's lightweight nature. Therefore, a model fine-tuned using LoRA can significantly reduce computational resource requirements while maintaining high performance, resulting in a more efficient ransomware classification model.
[0141] Feature extraction: After training, the model can automatically extract discriminative features from the input data, which will be used for subsequent virus classification. The feature extraction process is automated; the system selects an appropriate level for feature extraction based on the different types and complexity of the data. This is particularly important for the processing of the embedding layer and the generation of high-level feature representations.
[0142] Feature extraction process: During training, the model automatically extracts discriminative features from the input data. These features include low-level basic features (such as byte frequency, operating system calls, etc.) and higher-level abstract features (such as virus behavior patterns, file encryption methods, etc.).
[0143] Embedding layer processing: Input: Raw or processed data, typically including the raw feature representation of virus samples. The embedding layer learns distributed representations of words or byte sequences by mapping discrete inputs (such as words or byte sequences) to a continuous vector space. The feature vectors generated by the retrained embedding layer better capture the contextual information of the input data, improving the understanding of the data by subsequent layers.
[0144] High-level feature representations: During the feature extraction stage, the model generates more abstract high-level feature representations. These high-level feature representations can capture the deep structure and patterns of the data, thereby improving classification performance.
[0145] When using Transformer or similar deep learning models, the generation of feature representations can be expressed by the following formula:
[0146] H l =Attention(H l-1 )·W l
[0147] Among them, H l It is the feature representation of the l-th layer, Attention(H) l-1 ) indicates that the feature representation H is in the previous layer. l-1 The representation obtained by applying the self-attention mechanism, W l This is the weight matrix for this layer. In this representation, the model focuses on different parts of the input data through a self-attention mechanism, generating feature representations that are meaningful to the input data. These high-level features are typically the model's deep understanding of the input data, reflecting the complex behavioral patterns and characteristics of the virus.
[0148] Through these steps, the model is able to extract highly discriminative features from the input data, which play a crucial role in classification tasks. Retraining the Embedding layer ensures that the feature representations can adapt to new data requirements, while the generation of high-level feature representations provides an understanding of the deep structure of the data.
[0149] Step 3: Multi-level classification module
[0150] like Figure 4As shown, this module is responsible for hierarchically classifying ransomware based on extracted features, including preliminary classification and refined classification.
[0151] Preliminary Classification: The system first performs a preliminary classification of ransomware samples based on the extracted high-level features. The goal of this preliminary classification is to categorize the virus into a specific virus family or type (e.g., WannaCry, Locky, etc.). This ensures both classification speed and preliminary accuracy.
[0152] Refined Classification: After the initial classification, the system further refines the classification of virus samples. This refined classification analyzes the specific behavioral patterns, file encryption methods, ransom demands, and other characteristics of the viruses. The refined classification model employs a graph neural network. First, the behavioral patterns, file encryption methods, ransom demands, and other features of the ransomware samples are represented as nodes in a graph, with edges representing the dependencies or similarities between these nodes. During training, each node receives information from its neighbors through a message passing mechanism and updates its own feature representation, thus capturing the complex relationships within the virus samples. Next, graph pooling is used to aggregate the features of the entire graph into graph-level feature vectors, facilitating subsequent refined classification. Finally, a pre-designed classifier classifies these feature vectors to identify specific ransomware variants, infection routes, and impact ranges. The classification results include detailed information such as the specific ransomware variant name, infection route, and impact range.
[0153] In the process of fine-grained classification, the core role of the classifier is to classify the extracted graph-level feature vectors and identify specific variants of ransomware. This classification step relies on feature vectors obtained from graph neural networks (GNNs), which represent high-level information such as the behavior patterns, encryption methods, and ransom demands of ransomware samples.
[0154] The classifier classifies the feature vectors as follows: After processing by a graph neural network (GNN), the ransomware sample is represented as a graph-level feature vector. This feature vector contains all the associated features extracted from information such as behavioral patterns, encryption methods, and ransom demands, and is a high-dimensional representation of the ransomware sample.
[0155] The classifier is based on fully connected neural network technology, which can effectively handle high-dimensional feature vectors and classify complex patterns. Fully connected neural networks progressively map the input high-dimensional feature vectors to a lower-dimensional space through multiple layers of linear transformations and non-linear activation functions (such as ReLU or Sigmoid), thereby achieving classification.
[0156] The feature vectors are processed through multiple layers of a fully connected neural network. Each layer performs a linear transformation on the original vector (i.e., through transformations of the weight matrix and bias terms) and applies a non-linear activation function, enabling the model to learn complex classification boundaries. The output of each layer can be represented as:
[0157] h (l+1) =σ(W (l) ·h (l) +b (l) )
[0158] Among them, h (l) W is the input feature of the l-th layer. (l) It is the weight matrix, b (l) σ is the bias term, and σ is a non-linear activation function, such as ReLU.
[0159] The final layer is typically a softmax classification layer, used to transform the neural network's output into a probability distribution. Each output value represents the probability that the input feature vector belongs to a particular ransomware variant.
[0160]
[0161] Among them, z i It is the i-th element of the last layer output, C is the number of categories, and P(y) is the i-th element of the last layer output. i |x) represents the probability that the input sample is classified into the i-th category.
[0162] By using the probability values output by the Softmax layer, the model can determine which variant has the highest probability and classify it as the ransomware variant. The classification result includes not only the specific variant name but also detailed information such as **infection route and scope of impact**. This information originates from various high-dimensional information in the feature vectors, such as behavioral patterns, encryption methods, and ransom demands. The classifier performs classification operations on the graph-level feature vectors extracted by the graph neural network, progressively extracting high-dimensional information using a fully connected neural network, and generating classification probabilities using the Softmax layer. Ultimately, it identifies the specific variant of the ransomware and its related characteristics, such as infection route and scope of impact. This process effectively distinguishes different variants of the virus, improving the accuracy and precision of ransomware detection.
[0163] Step 4: Dynamic Adaptive Update Module
[0164] like Figure 5 As shown, in order to cope with the continuous evolution of ransomware, this invention designs a dynamic adaptive update mechanism to perform incremental learning, real-time updates and feedback, to ensure that the system can adapt to new threats in a timely manner.
[0165] Incremental learning: When new ransomware samples are detected, the system automatically incorporates these samples into the training set and uses incremental learning techniques to update the parameters of the large model. Incremental learning ensures that the model can quickly adapt to new ransomware without requiring a complete retraining.
[0166] Real-time updates: The system supports real-time model updates, enabling the classifier to immediately utilize the latest data for detection and classification in practical applications. The real-time update mechanism ensures model updates are completed without impacting system performance through optimized algorithms and resource scheduling.
[0167] Feedback Mechanism: The system establishes a user feedback mechanism, allowing security experts or users to verify and provide feedback on the classification results. This feedback information will serve as an important reference for model optimization, further improving the system's accuracy.
[0168] Step 5: User Interaction and Management Module
[0169] This module provides a user interface and API interface, supporting users to perform system configuration, data input, result viewing and management operations.
[0170] User Interface: A user-friendly graphical user interface (GUI) is provided, allowing users to intuitively configure system parameters, upload data, and view classification results. The interface also supports chart displays, enabling users to view statistical analysis, trend changes, and other information related to the classification results.
[0171] API Interface: The system provides a RESTful API, supporting programmatic integration with external systems to perform operations such as data input, classification result output, and model management. The API interface is designed to be simple, easy to integrate, and can seamlessly connect with existing security defense systems or other applications.
[0172] Access Control: The system has a built-in multi-level access control mechanism, with different user roles having different operating permissions. Administrators can control advanced operations such as system configuration, model updates, and data management, while ordinary users can only perform routine operations such as data uploading and result viewing.
[0173] Through the detailed description above, the various modules and operation steps of the ransomware classification method and system based on a large model of this invention have been clearly described. The system, through the collaborative work of multiple innovative technical modules, can effectively improve the accuracy, real-time performance, and ease of use of ransomware detection and classification, and is suitable for a wide range of network security protection needs.
[0174] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.
Claims
1. A ransomware classification method based on a large model, characterized in that: Includes the following steps: S1. The data collection and preprocessing module collects data and captures ransomware data for preprocessing to obtain preprocessed data. S2. The large model training and feature extraction module uses a deep learning large model to learn and extract features from the preprocessed data to obtain a high-level feature representation. The deep learning large model is a large model that has been pre-trained in an unsupervised or semi-supervised manner and then fine-tuned based on the feature corpus supervised by SFT. S3. The multi-level classification module performs multi-level classification of ransomware based on the high-level feature representation. The multi-level classification includes preliminary classification and refined classification. In the preliminary classification, ransomware samples are assigned to virus families or types based on the high-level features. In the refined classification, graph-level feature vectors of ransomware samples are extracted through graph neural networks, and a classifier is used to classify the graph-level feature vectors to identify variants and behavioral patterns of ransomware. It is then determined whether the identified ransomware is a new type of ransomware sample. If yes, proceed to step S4; otherwise, proceed to step S5. S4. The dynamic adaptive update module dynamically adjusts the parameters of the deep learning model based on the new ransomware sample, and proceeds to step S5. S5. Users classify ransomware through the user interaction and management module, completing a ransomware classification method based on a large model.
2. The ransomware classification method based on a large model according to claim 1, characterized in that: In step S1, the data collection and preprocessing module collects historical network traffic data, historical file system data, historical behavior logs, and network traffic data, file system data, and behavior logs to be analyzed for training deep learning large models. The ransomware data includes traffic features related to ransomware extracted from network communication data packets, suspected ransomware samples / behavior logs captured from file system data, and operation behavior records in the system. The traffic characteristics related to ransomware include: suspicious IP addresses, port usage, attack payload, packet length, and file type hash. The suspected ransomware sample / behavior logs include: records of suspicious file generation and modification. The operation behavior records include file access and process startup. Preprocessing methods include data cleaning, formatting, normalization, and feature selection. Data cleaning involves removing invalid, duplicate, or noisy data; formatting involves converting data from different sources into a uniform format; normalization involves normalizing numerical features; and feature selection involves selecting the most representative data features based on predefined criteria.
3. The ransomware classification method based on a large model according to claim 1, characterized in that: Step S2 includes the following steps: S21. The deep learning model is trained using the collected historical ransomware data. The historical ransomware data includes historical network traffic data, historical file system data, and historical behavior logs collected by the data collection and preprocessing module. The historical ransomware data includes virus families and virus variants. S22. Use the deep learning big model to extract features and generate pseudo-labels. The pseudo-labels include ransomware family features, sample features and intelligence features. The pseudo-labels are combined with manually labeled real data to obtain a fine-tuning special dataset and fine-tune the deep learning big model. S23. By combining the self-attention mechanism with the retraining of the embedding layer, the deep learning large model maps the input data to the corresponding feature space and generates the high-level feature representation.
4. The ransomware classification method based on a large model according to claim 3, characterized in that: In step S22, the method for fine-tuning the large deep learning model includes: S221. In the feature extraction stage, the deep learning large model generates pseudo-labels based on specific variant features. Where, x i is the feature vector of the original ransomware sample, ∫ is the feature extraction function, and the specific variant features include encryption algorithms and propagation methods; Wherein, C(x) i S(x) is a special encryption algorithm. i The difference lies in the file structure. S222. Utilize multi-level feature representation learning to simultaneously capture high-level family features and fine-grained variant features: z i =Concat(h f ,h u ); Among them, z i For joint features, h f As a high-level family characteristic, h u It is a fine-grained variant characteristic; S223. By optimizing the objective function L, a joint loss of family and variant features is learned simultaneously: L=L family (h f )+L variant (h u ); Where L is the joint loss function, L family For family classification loss, L variant For variant classification loss; S224. For novel variant data, the deep learning large model introduces an adaptive learning mechanism, updating parameters through gradient descent in each training iteration: i t+1 =θ t -aD θ L(x new ,i t ); Where α is the learning rate dynamically adjusted based on the new variant data, and Δ θ L is the gradient of the joint loss function L with respect to the model parameters θ, Δ θ This represents the amount of time the model parameters are updated. S225. Generate adversarial examples x using adversarial training methods. adu The adversarial example x adu By adding a perturbation term ∈·sign(Δ) to the original input x x L(x,y)) is used to generate: x adu =x+∈·sign(Δ x L(x,y)); Where ∈ controls the magnitude of the perturbation, sign(Δ) x L(x,y)) is the sign of the gradient of the loss function with respect to the input x, Δ x This refers to the disturbance or change in the input data; S226. Use the LoRA method to adjust the parameters of the deep learning large model. LoRA decomposes the original weight matrix W into low-rank matrices A and B, where the dimensions of A and B are smaller than those of the original weight matrix W. Freeze the original weight matrix W without updating it, and only train the newly added low-rank matrices A and B. During training, only the newly added low-rank matrices A and B participate in the gradient update, while the original weight matrix W remains unchanged. The adjusted weights W ′ =W + ΔW.
5. The ransomware classification method based on a large model according to claim 4, characterized in that: In step S226, ΔW = A × B; The dimension of low-rank matrix A is d×r, and the dimension of low-rank matrix B is r×k, where r is the rank and r is less than d and k.
6. The ransomware classification method based on a large model according to claim 4, characterized in that: In step S23, the deep learning big model extracts basic features and abstract features from the input data during the training process. The basic features include byte frequency and operating system calls; the abstract features include the virus's behavior patterns and file encryption methods; and the high-level features are the complex behavior patterns and features of the virus that are output by the deep learning big model after understanding the input data. Raw or processed data, including the original feature representation of virus samples, is input into the embedding layer. The embedding layer maps the discrete input to a continuous vector space and learns distributed representations of words or byte sequences, where the discrete input includes words or byte sequences. In the feature extraction stage: H l =Attention(H l-1 )·W l ; Among them, H l For the feature representation of the l-th layer, Attention(H) l-1 ) represents the feature representation H in the previous layer. l-1 The representation obtained by applying the self-attention mechanism, W l Let be the weight matrix of the l-th layer.
7. The ransomware classification method based on a large model according to claim 1, characterized in that: In step S3, the refined classification model uses a graph neural network; The refined classification model represents the characteristics of ransomware sample behavior patterns, file encryption methods, and ransom demands as nodes in a graph, and uses edges to represent the dependencies or similarities between nodes. During training, each node receives information from its neighboring nodes through a message passing mechanism and updates its own feature representation to capture the complex relationships in the virus samples. Then, graph pooling is used to aggregate the features of the entire graph into graph-level feature vectors, which facilitates subsequent fine-grained classification. Finally, the graph-level feature vectors are classified using a classifier to identify specific variants, infection routes, and impact ranges of ransomware. The classification results include the specific ransomware variant name, infection route, and impact range.
8. The ransomware classification method based on a large model according to claim 7, characterized in that: During the fine-grained classification process, the classifier will classify the extracted graph-level feature vectors to identify specific variants of ransomware. The classification relies on feature vectors obtained from the graph neural network, which represent the behavior patterns, encryption methods, and ransom demands of the ransomware samples. The classifier is based on a fully connected neural network. It uses multi-layer linear transformations and non-linear activation functions to gradually map the input high-dimensional feature vector to a lower-dimensional space for classification. The feature vector is processed through multiple layers of a fully connected neural network. Each layer performs a linear transformation on the original vector and applies a non-linear activation function, enabling the deep learning model to learn the classification boundary. The output of each layer is: h (l+1) =σ(W (l) ·h (l) +b (l) ); Among them, h ( l) represents the input features of the l-th layer, W ( l) is the weight matrix, b ( l) is the bias term, and σ is the nonlinear activation function; The final layer is the Softmax classification layer, which converts the output of the neural network into a probability distribution. Each output value represents the probability that the input feature vector belongs to a certain ransomware variant. Among them, z i Let P(y) be the i-th joint feature output from the last layer, C be the number of classification categories, and P(y) be the i-th joint feature output from the last layer. i |x) represents the probability that the input sample is classified into the i-th category.
9. The ransomware classification method based on a large model according to claim 1, characterized in that: In step S4, the dynamic adaptive update module incorporates new ransomware samples into the training set and uses incremental learning to update the parameters of the deep learning model. The dynamic adaptive update module can update the large deep learning model in real time. The dynamic adaptive update module establishes a user feedback mechanism, allowing security experts or users to verify and provide feedback on the classification results.
10. A ransomware classification method based on a large model according to any one of claims 1 to 9, characterized in that: The ransomware classification system using a large model-based ransomware classification method includes, in sequence, the data collection and preprocessing module, the large model training and feature extraction module, the multi-level classification module, and the dynamic adaptive update module and the user interaction and management module, all electrically connected to the large model training and feature extraction module. The deep learning model is either a Transformer model or a GPT model, and the classifier of the multi-level classification module is based on a fully connected neural network. The user interaction and management module provides a user interface and API interface, supporting users to perform system configuration, data input, result viewing and management operations, and setting up an access control mechanism. Users can configure system parameters, upload data and view classification results through the user interface. The user interface also supports chart display, allowing users to view statistical analysis and trend changes of classification results. The user interaction and management module provides a RESTful API, supporting programmatic integration with external systems for data input, classification result output and model management.
Citation Information
Patent Citations
Cluster partitioning processing method and cluster partitioning processing device for virus files
CN102930206A
Malicious software detection method and device
CN104715194A