Information determination method and device, model training method and device, equipment, storage medium and computer program product
By obtaining and analyzing the operation behavior generated by running the file to be detected on the terminal, and combining with the target information detection model, the problem of low detection accuracy of malicious file in the prior art is solved, and higher detection accuracy is achieved.
Patent Information
- Application Number
- CN202411839482.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-12
- Publication Date
- 2025-05-06
AI Technical Summary
The prior art relies on static analysis in malicious file detection, resulting in low detection accuracy.
By obtaining the operation behavior generated by the file to be detected after it is run on the terminal, the operation characteristic information is determined based on these operation behaviors, and the operation characteristic information is processed using the target information detection model to determine whether the file to be detected is a malicious file.
Improve the accuracy of malicious file detection by considering the dynamic operation behavior generated after the file to be detected is run, rather than relying solely on static attribute information.
Smart Images

Figure CN119939581A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to information determination, model training methods, devices, equipment, storage media and computer program products. Background Art
[0002] With the development of science and technology, network security has become increasingly important. In order to improve the security of network systems, files in terminals are usually detected to identify malicious files in a timely manner. At present, when identifying malicious files, the relevant technology usually uses static analysis (i.e., analyzing the attribute information of the file) to detect the file to determine whether the file is a malicious file. However, since the relevant technology only considers the attribute information of the file itself, this leads to the problem of low accuracy in detecting malicious files when detecting malicious files. Summary of the invention
[0003] In order to solve the above-mentioned technical problems, the embodiments of the present application hope to provide an information determination, model training method, device, equipment, storage medium and computer program product, which solves the problem of low accuracy in detecting malicious files when detecting malicious files in the related technology.
[0004] The technical solution of this application is implemented as follows:
[0005] A method for determining information, the method comprising:
[0006] Obtain the operation behavior generated after the file to be detected is run on the terminal;
[0007] Determining operation characteristic information based on the operation behavior;
[0008] The operation characteristic information is processed by a target information detection model to obtain a detection result of the file to be detected; wherein, the detection result indicates whether the file to be detected is a malicious file; the target information detection model is obtained by training an initial information detection model based on sample operation characteristic information; the sample operation characteristic information is determined based on a sample operation behavior generated after the sample file is run on the terminal.
[0009] In the above solution, the operation behavior generated after the file to be detected is run on the terminal includes:
[0010] Obtaining file operation behaviors generated on files in the terminal after the file to be detected is run;
[0011] Obtaining configuration operation behavior generated for the configuration information of the terminal after the file to be detected is run;
[0012] Obtain operation sequence information of operations generated on the terminal after the file to be detected is run.
[0013] In the above solution, the determining of the operation characteristic information based on the operation behavior includes:
[0014] Building a file operation feature based on the file operation behavior generated after the file to be detected is run;
[0015] Constructing configuration operation features based on the configuration operation behavior generated after the file to be detected is run;
[0016] Constructing an operation sequence feature based on the operation sequence information generated after the file to be detected is run;
[0017] An operation feature vector is determined based on the file operation feature, the configuration operation feature and the operation sequence feature; wherein the operation feature information includes the operation feature vector.
[0018] In the above solution, determining the operation feature vector based on the file operation feature, the configuration operation feature and the operation sequence feature includes:
[0019] Using a target residual network model to process the file operation feature to obtain a first feature vector;
[0020] Processing the configuration operation feature using a target bidirectional encoding model to obtain a second feature vector;
[0021] Using a target recurrent network model to process the operation sequence features to obtain a third feature vector;
[0022] The first feature vector, the second feature vector and the third feature vector are fused to obtain the operation feature vector.
[0023] In the above solution, determining the operation feature vector based on the file operation feature, the configuration operation feature and the operation sequence feature includes:
[0024] Acquire static features of the file to be detected; wherein the static features are features of the file to be detected when it is not in a running state;
[0025] The operation feature vector is determined based on the file operation feature, the configuration operation feature, the operation sequence feature and the static feature.
[0026] In the above solution, the determining the operation feature vector based on the file operation feature, the configuration operation feature, the operation sequence feature and the static feature includes:
[0027] Determine a first feature vector, a second feature vector, and a third feature vector corresponding to the file operation feature, the configuration operation feature, and the operation sequence feature, respectively;
[0028] Using a target gated network model to process the static features to obtain a fourth feature vector;
[0029] The first eigenvector, the second eigenvector, the third eigenvector and the fourth eigenvector are fused to obtain the operation eigenvector.
[0030] A model training method, the method comprising:
[0031] Get the sample operation behavior generated by running the sample file on the terminal;
[0032] Determining sample operation characteristic information based on the sample operation behavior;
[0033] The initial information detection model is trained based on the sample operation feature information to obtain a target information detection model.
[0034] In the above solution, the step of obtaining the sample operation behavior generated by running the sample file on the terminal includes:
[0035] Obtaining sample file operation behaviors generated for files in the terminal after the sample file is run;
[0036] Obtaining sample configuration operation behaviors generated for the configuration information of the terminal after the sample file is run;
[0037] Obtain sample operation sequence information of operations generated on the terminal after the sample file is run.
[0038] In the above solution, the determining of sample operation feature information of the operation on the terminal based on the sample operation behavior includes:
[0039] Constructing sample file operation features based on sample file operation behaviors generated after the sample file is run;
[0040] Constructing a sample configuration operation feature based on the sample configuration operation behavior generated after the sample file is run;
[0041] Constructing a sample operation sequence feature based on the sample operation sequence information generated after the sample file is run;
[0042] Based on the sample file operation feature, the sample configuration operation feature and the sample operation sequence feature, a sample operation feature vector is determined; wherein the sample operation feature information includes the sample operation feature vector.
[0043] In the above solution, determining the sample operation feature vector based on the sample file operation feature, the sample configuration operation feature and the sample operation sequence feature includes:
[0044] Using a target residual network model to process the sample file operation feature to obtain a first sample feature vector;
[0045] Processing the sample configuration operation feature using a target bidirectional encoding model to obtain a second sample feature vector;
[0046] Using a target recurrent network model to process the sample operation sequence features to obtain a third sample feature vector;
[0047] The first sample feature vector, the second sample feature vector and the third sample feature vector are fused to obtain the sample operation feature vector.
[0048] In the above solution, determining the sample operation feature vector based on the sample file operation feature, the sample configuration operation feature and the sample operation sequence feature includes:
[0049] Acquire a sample static feature of the sample file; wherein the sample static feature is a feature when the sample file is not in a running state;
[0050] The sample operation feature vector is determined based on the sample file operation feature, the sample configuration operation feature, the sample operation sequence feature and the sample static feature.
[0051] In the above solution, determining the sample operation feature vector based on the sample file operation feature, the sample configuration operation feature, the sample operation sequence feature and the sample static feature includes:
[0052] Respectively determine a first sample feature vector, a second sample feature vector, and a third sample feature vector corresponding to the sample file operation feature, the sample configuration operation feature, and the sample operation sequence feature;
[0053] Processing the sample static features using a target gated network model to obtain a fourth sample feature vector;
[0054] The first sample feature vector, the second sample feature vector, the third sample feature vector and the fourth sample feature vector are fused to obtain a sample operation feature vector.
[0055] An information determination device, the device comprising:
[0056] The first acquisition unit is used to acquire the operation behavior generated after the file to be detected is run on the terminal;
[0057] A first determining unit, configured to determine operation feature information based on the operation behavior;
[0058] A processing unit is used to process the operation feature information using a target information detection model to obtain a detection result of the file to be detected; wherein the detection result indicates whether the file to be detected is a malicious file; the target information detection model is obtained by training an initial information detection model based on sample operation feature information; the sample operation feature information is determined based on a sample operation behavior generated after the sample file is run on the terminal.
[0059] A model training device, comprising:
[0060] The second acquisition unit is used to acquire the sample operation behavior generated after the sample file is run on the terminal;
[0061] A second determining unit, configured to determine sample operation feature information based on the sample operation behavior;
[0062] The training unit is used to train the initial information detection model based on the sample operation feature information to obtain the target information detection model.
[0063] An information determination device, the device comprising: a first processor, a first memory and a first communication bus;
[0064] The first communication bus is used to realize the communication connection between the first processor and the first memory;
[0065] The first processor is used to execute the information determination program in the first memory to implement the steps of the above-mentioned information determination method.
[0066] A model training device, the device comprising: a second processor, a second memory, and a second communication bus;
[0067] The second communication bus is used to realize the communication connection between the second processor and the second memory;
[0068] The second processor is used to execute the model training program in the second memory to implement the steps of the above-mentioned model training method.
[0069] A computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the steps of the above-mentioned information determination method or model training method.
[0070] A computer program product, comprising a computer program, which implements the steps of the above-mentioned information determination method or model training method when executed by a processor.
[0071] The information determination, model training method, apparatus, device, storage medium and computer program product provided by the embodiments of the present application can obtain the operation behavior generated after the file to be detected is run on the terminal, and determine the operation feature information based on the operation behavior information, and then use the target information detection model to process the operation feature information to obtain the detection result of the file to be detected, so as to determine whether the file to be detected is a malicious file; in this way, the dynamic operation behavior generated after the file to be detected is run can be obtained, and then the target information detection model is used to process the operation feature information determined based on the dynamic operation behavior to determine whether the file to be detected is a malicious file, that is, the dynamic operation behavior generated after the file to be detected is run is taken into account when detecting malicious files, instead of only considering the static attribute information of the file to be detected as in the related art, which solves the problem of low accuracy in detecting malicious files when detecting malicious files in the related art. BRIEF DESCRIPTION OF THE DRAWINGS
[0072] Figure 1 A flowchart of an information determination method provided in an embodiment of the present application;
[0073] Figure 2 A schematic diagram of the structure of a sandbox environment in an information determination method provided in an embodiment of the present application;
[0074] Figure 3 A schematic diagram of extracting operation feature information in a model training method provided in an embodiment of the present application;
[0075] Figure 4 A flowchart of another information determination method provided in an embodiment of the present application;
[0076] Figure 5 A schematic diagram of a target information detection model in an information determination method provided in an embodiment of the present application;
[0077] Figure 6 A flowchart of a model training method provided in an embodiment of the present application;
[0078] Figure 7 A schematic diagram of the structure of an information determination device provided in an embodiment of the present application;
[0079] Figure 8 A schematic diagram of the structure of a model training device provided in an embodiment of the present application;
[0080] Fig. 9A schematic diagram of the structure of an information determination device provided in an embodiment of the present application;
[0081] Fig.10 A schematic diagram of the structure of a model training device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0082] The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application.
[0083] It should be understood that the "embodiments of the present application" or "the aforementioned embodiments" mentioned throughout the specification mean that specific features, structures or characteristics related to the embodiments are included in at least one embodiment of the present application. Therefore, "in the embodiments of the present application" or "in the aforementioned embodiments" appearing throughout the specification may not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics may be combined in one or more embodiments in any suitable manner. In the various embodiments of the present application, the size of the sequence numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application. The above-mentioned sequence numbers of the embodiments of the present application are for description only and do not represent the advantages and disadvantages of the embodiments.
[0084] It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0085] The present application embodiment provides an information determination method, which can be applied to an information determination device, referring to Figure 1 As shown, the method comprises the following steps:
[0086] Step 101: Obtain the operation behavior generated after the file to be detected is run on the terminal.
[0087] The file to be detected may refer to a portable executable (PE) file.
[0088] In the implementation of this application, the file to be detected can be run in a sandbox environment to obtain the operation behavior generated on the terminal after the file to be detected is processed. Figure 2The sandbox environment shown may include a task scheduling module, a terminal, a behavior monitoring and collection module, and a log processing module. At this time, after receiving the file to be detected, the task scheduling module may allocate the file for transmission to the corresponding terminal. Thereafter, the received file to be detected is run on the terminal. At the same time, the behavior monitoring module collects and records all information generated after the running of the file to be detected. Finally, all the generated information is formatted through the log processing module to obtain an operation log including the operation behavior information (i.e., operation behavior) generated for the terminal.
[0089] In one achievable manner, the operation behavior may include file operation behavior for files in the terminal, configuration operation behavior for the registry of the terminal, and operation sequence information for operations generated by the terminal. In another achievable manner, the operation behavior may also include process operation behavior for processes of the terminal.
[0090] Step 102: Determine operation feature information based on the operation behavior.
[0091] In the embodiment of the present application, the operation feature information may refer to an operation feature vector of an operation generated for a terminal; specifically, it may be as follows: Figure 3 As shown, different types of operations generated for the information in the terminal are determined according to the operation behavior, and then the operation characteristics of different types of operations are constructed. After that, multiple operation characteristics can be processed separately to obtain multiple feature vectors, and then the operation feature vector (i.e., operation feature information) is determined based on the multiple feature vectors.
[0092] Step 103: Use the target information detection model to process the operation feature information to obtain the detection result of the file to be detected.
[0093] Among them, the detection result represents whether the file to be detected is a malicious file; the target information detection model is obtained after training the initial information detection model based on the sample operation feature information; the sample operation feature information is determined based on the sample operation behavior generated after the sample file is run on the terminal.
[0094] In an embodiment of the present application, the target information detection model may be obtained after training the initial information detection model. Wherein, the initial information detection model may refer to a mixture of experts (Mixture of Experts, MoE) model, and the initial information detection model may include multiple different models, specifically, the MoE model may include a long short-term memory model (Long Short-Term Memory, LSTM), a gated recurrent unit (Gate Recurrent Unit, GRU) model, a robustly optimized bidirectional encoding (Robustly optimized BERT Pretraining approach, RoBERTa) model and a transformer (Transformer) model.
[0095] In an embodiment of the present application, different models in the target information detection model can be used to process different feature vectors in the operation feature vector respectively to obtain the processing results of each model for the file to be detected. Then, based on the weight of each model and the processing results of each model for the file to be detected, the final detection result of the file to be detected is determined, and then whether the file to be detected is a malicious file is determined based on the detection result.
[0096] The information determination method provided in the embodiment of the present application can obtain the dynamic operation behavior generated after the file to be detected is run, and then use the target information detection model to process the operation feature information determined based on the dynamic operation behavior to determine whether the file to be detected is a malicious file. That is, when detecting malicious files, the dynamic operation behavior generated after the file to be detected is run is taken into account, rather than only considering the static attribute information of the file to be detected as in the related art, thereby solving the problem of low accuracy in detecting malicious files when detecting malicious files in the related art.
[0097] Based on the above embodiments, the embodiments of the present application provide an information determination method, referring to Figure 4 As shown, the method comprises the following steps:
[0098] Step 201: After the information determination device obtains the file operation behavior generated on the file in the terminal after the file to be detected is run on the terminal.
[0099] In an embodiment of the present application, file operation behavior may refer to operation behavior information of operations on files in the terminal; in one achievable method, operations generated on files in the terminal may refer to creating new files, encrypting files, modifying files, and deleting files, that is, after running the file to be detected on the terminal in the sandbox environment, operation behavior information (i.e., file operation behavior) of operations of creating new files, reading files, modifying files, and deleting files performed on the terminal can be obtained.
[0100] It should be noted that the terminal may refer to a virtual machine.
[0101] Step 202: After the information determination device obtains the configuration operation behavior generated for the configuration information of the terminal after the file to be detected is run on the terminal.
[0102] In an embodiment of the present application, configuration information may refer to hardware configuration information, software configuration information and system configuration information of the terminal stored in the registry of the terminal; configuration operation behavior may refer to operation behavior information of operations on the registry on the terminal; in an achievable manner, operations generated on the registry on the terminal may refer to key value operations, new item operations and modification operations on the paths in the registry, that is, after running the file to be detected on the terminal in the sandbox environment, key value operations (i.e., modifying the configuration information of the system), new item operations (i.e., creating new keys or subkeys in the registry) and modification operation behavior information (i.e., configuration operation behavior) performed on the terminal may be obtained.
[0103] Step 203: The information determination device obtains operation sequence information of the operation generated by the terminal after the file to be detected is run on the terminal.
[0104] In the embodiment of the present application, the operation sequence information may refer to the order information of the steps of all operations generated for the terminal. Specifically, after the file to be detected is run on the terminal in the sandbox environment, the operation sequence information of each operation generated for the terminal can be obtained by calling the Application Programming Interface (API) subsequence.
[0105] Step 204: The information determination device constructs a file operation feature based on the file operation behavior generated after the file to be detected is run.
[0106] In an embodiment of the present application, if the operation generated on the file in the terminal is to add a new file, a file operation feature including the path where the new file is stored and the attribute information of the new file can be constructed according to the corresponding file operation behavior; if the operation generated on the file in the terminal is to encrypt the file, a file operation feature including the encryption time and encryption method of the file can be constructed according to the corresponding file operation behavior.
[0107] Step 205: The information determination device constructs a configuration operation feature based on the configuration operation behavior generated after the file to be detected is run.
[0108] In an embodiment of the present application, if the operation generated for the registry of the terminal is a key-value operation, a configuration operation feature including the modified location, modification time and modified content in the system can be constructed according to the corresponding configuration operation behavior; if the operation generated for the registry of the terminal is a new item operation, a configuration operation feature including the location of the new item and the type of the new item can be constructed according to the corresponding configuration operation behavior.
[0109] Step 206: The information determination device constructs an operation sequence feature based on the operation sequence information generated after the file to be detected is run.
[0110] In the embodiment of the present application, the operation sequence feature may refer to the order of steps of each type of operation generated for the terminal after processing the file to be detected and the logical relationship between the steps.
[0111] In one achievable manner, the operation sequence characteristics may include operation sequence characteristics of operations generated for terminal files and operation sequence characteristics of operations generated for terminal configuration information. In another achievable manner, the operation sequence characteristics may also include operation sequence characteristics of operations generated for other information of the terminal.
[0112] Step 207: The information determination device determines an operation feature vector based on the file operation feature, the configuration operation feature, and the operation sequence feature.
[0113] The operation feature information includes an operation feature vector.
[0114] In the embodiment of the present application, different models can be used to process the file operation feature, configuration operation feature and operation sequence feature to obtain corresponding feature vectors, and then the obtained multiple feature vectors are processed to obtain the final operation feature vector, that is, the operation feature information. In the embodiment of the present application, step 207 can be implemented by steps 207a to 207d.
[0115] It should be noted that in another feasible method, the static features of the file to be detected can be obtained, and the operation feature vector can be determined jointly by combining the file operation features, configuration operation features and operation sequence features. In this case, step 207 can be implemented through steps 207e to 207f.
[0116] Step 207a: The information determination device uses the target residual network model to process the file operation feature to obtain a first feature vector.
[0117] In the embodiment of the present application, the target residual network model may refer to a residual network (Residual Network, ResNet) model. Specifically, the ResNet model may be used to convert the file operation feature to obtain the operation vector corresponding to the text operation feature, that is, the first feature vector; that is, the first feature vector may be obtained after vectorization processing of the file operation feature.
[0118] Step 207b: The information determination device processes the configuration operation feature using a target bidirectional coding model to obtain a second feature vector.
[0119] In the embodiment of the present application, the target bidirectional coding model may refer to a RoBERTa model. Specifically, the RoBERTa model may be used to convert the configuration operation feature to obtain an operation vector corresponding to the configuration operation feature, i.e., a second feature vector; that is, the second feature vector may be obtained by vectorizing the configuration operation feature.
[0120] Step 207c: The information determination device uses the target recurrent network model to process the operation sequence features to obtain a third feature vector.
[0121] In the embodiment of the present application, the target recurrent network may refer to an LSTM model. Specifically, the LSTM model may be used to transform the operation sequence features to obtain a feature vector corresponding to the operation sequence features, i.e., a third feature vector; that is, the third feature vector may be obtained by vectorizing the operation sequence features.
[0122] It should be noted that, in a feasible manner, a GRU model may also be used to transform the operation sequence features to obtain the third feature vector.
[0123] Step 207d: The information determination device fuses the first feature vector, the second feature vector and the third feature vector to obtain an operation feature vector.
[0124] In an embodiment of the present application, the first feature vector, the second feature vector and the third feature vector can be fused to obtain an operation feature vector for the operation of the terminal. Thereafter, the operation feature vector can be input into a target information detection model to process the operation feature vector through the target information detection model to determine whether the file to be detected is a malicious file.
[0125] Step 207e: The information determination device obtains static features of the file to be detected.
[0126] Among them, the static features are the features when the file to be detected is not in a running state.
[0127] In the embodiment of the present application, static features may refer to features such as file size, operation code sequence, and file section size. Specifically, a neural network model, a random forest algorithm, and a principal component analysis algorithm may be used to extract multiple static features of the file to be detected.
[0128] Step 207f: The information determination device determines an operation feature vector based on the file operation feature, the configuration operation feature, the operation sequence feature and the static feature.
[0129] In an embodiment of the present application, different network models can be used to process file operation features, configuration operation features, operation sequence features and static features respectively to obtain multiple feature vectors, and then the multiple feature vectors are processed to obtain operation feature vectors.
[0130] In the embodiment of the present application, step 207f can be implemented through steps 207f1 to 207f3.
[0131] Step 207f1, the information determination device determines the first feature vector, the second feature vector and the third feature vector corresponding to the file operation feature, the configuration operation feature and the operation sequence feature respectively.
[0132] In an embodiment of the present application, a target residual network model, a target bidirectional encoding model and a target recurrent network model can be used to process file operation features, configuration operation features and operation sequence features respectively to obtain a first feature vector, a second feature vector and a third feature vector.
[0133] It should be noted that the process of obtaining the first eigenvector may refer to step 207a; the process of obtaining the second eigenvector may refer to step 207b; and the process of obtaining the third eigenvector may refer to step 207c.
[0134] Step 207f2: The information determination device uses the target gated network model to process the static features to obtain a fourth feature vector.
[0135] In the embodiment of the present application, the target gated network model may refer to a GRU model. Specifically, the GRU model may be used to transform the static features to obtain a feature vector corresponding to the static features, i.e., the fourth feature vector; that is, the fourth feature vector may be obtained by vectorizing the static features.
[0136] Step 207f3: The information determination device fuses the first feature vector, the second feature vector, the third feature vector and the fourth feature vector to obtain an operation feature vector.
[0137] In the embodiment of the present application, the first eigenvector, the second eigenvector, the third eigenvector and the fourth eigenvector may be fused to obtain a final operation eigenvector.
[0138] Step 208: The information determination device processes the operation feature information using the target information detection model to obtain a detection result of the file to be detected.
[0139] The detection result indicates whether the file to be detected is a malicious file.
[0140] In the embodiments of the present application, Figure 5 As shown, after the operation feature vector is input into the target information detection model, the gating network in the target information detection model can classify the input feature vector and assign different types of vectors to multiple different models in the target information detection model. After that, the multiple models will process the input vectors respectively to obtain multiple processing results for the files to be detected. Finally, the detection result of the files to be detected can be determined according to the weight of each model and the processing result output by each model.
[0141] In one achievable manner, the gating network in the target information detection model will assign the first feature vector corresponding to the file operation behavior to the converter model, the second feature vector corresponding to the configuration operation behavior to the Roberta model, and the third feature vector corresponding to the operation sequence information to the LSTM model. After that, the converter model, the Roberta model, and the LSTM model process the corresponding feature vectors respectively, and calculate the processing results of each model and the weight of each model to obtain the detection result to determine whether the file to be detected is a malicious file. In another achievable manner, if the operation feature information also includes a fourth feature vector corresponding to the process operation feature and other feature vectors corresponding to other operation features, the gating system can also assign the fourth feature vector and other feature vectors to other network models in the target information detection model, and then jointly determine the detection result of the file to be detected based on the processing results of the converter model, the Roberta model, the LSTM model, and other network models and the weights of other network models. It should be noted that other network models can refer to GRU models and multilayer perceptron (MLP) models.
[0142] The information determination method provided in the embodiment of the present application can obtain the dynamic operation behavior generated after the file to be detected is run, and then use the target information detection model to process the operation feature information determined based on the dynamic operation behavior to determine whether the file to be detected is a malicious file. That is, when detecting malicious files, the dynamic operation behavior generated after the file to be detected is run is taken into account, rather than only considering the static attribute information of the file to be detected as in the related art, thereby solving the problem of low accuracy in detecting malicious files when detecting malicious files in the related art.
[0143] Based on the above embodiments, the embodiments of the present application provide a model training method, referring to Figure 6 As shown, the method comprises the following steps:
[0144] Step 301: The model training device obtains sample operation behaviors generated after the sample file is run on the terminal.
[0145] The sample files may include malicious files and non-malicious files, and the malicious files and non-malicious files may refer to PE files.
[0146] In the implementation of the present application, after running the sample file in the sandbox environment, the generated operation behavior (i.e., sample operation behavior) can be obtained. In one achievable manner, the sample operation behavior may include sample file operation behavior generated for files in the terminal, sample configuration operation behavior generated for the registry of the terminal, and sample operation sequence information of sample operations generated for the terminal. In another achievable manner, the operation behavior may also include sample process operation behavior generated for the process of the terminal.
[0147] In the embodiment of the present application, step 301 can be implemented by steps 301a to 301c:
[0148] Step 301a: After the model training device obtains the sample file and runs it, the sample file operation behavior generated for the file in the terminal.
[0149] In one achievable manner, after running the sample file on a terminal in a sandbox environment, behavior information of operations of creating a new file, reading a file, modifying a file, and deleting a file (ie, sample file operation behavior) can be obtained.
[0150] Step 301b: After the model training device obtains the sample file and runs it, it generates a sample configuration operation behavior for the configuration information of the terminal.
[0151] In an embodiment of the present application, after running the sample file on a terminal in a sandbox environment, behavior information (ie, sample configuration operation behavior) of key value operations, new item operations, and path modification operations performed on the terminal can be obtained.
[0152] Step 301c: The model training device obtains sample operation sequence information of operations generated by the terminal after the sample file is run.
[0153] In the embodiment of the present application, the sample operation sequence information may refer to the order information of the steps of the sample operation generated for the terminal. Specifically, after the sample file is run on the terminal in the sandbox environment, the sample operation sequence information of each sample operation generated for the terminal may be obtained by calling the API subsequence.
[0154] Step 302: The information determination device determines sample operation feature information based on the sample operation behavior.
[0155] In one achievable manner, Figure 3 As shown, sample file operation features, sample configuration operation features and sample operation sequence features can be respectively constructed according to sample file operation behavior, sample configuration operation behavior and sample operation sequence information. Then, the respectively obtained sample operation features and sample operation sequence features are processed to obtain corresponding sample feature vectors. Then, the obtained multiple sample feature vectors are processed to obtain sample operation feature information.
[0156] In the embodiment of the present application, step 302 can be implemented through steps 302a to 302d.
[0157] Step 302a: The model training device constructs sample file operation features based on the sample file operation behaviors generated after the sample file is run.
[0158] In an embodiment of the present application, if the operation generated on the file of the terminal is to modify the file, a sample file operation feature including the modification time of the file, the modification content and the information of the user who modified the file can be constructed based on the sample file operation behavior; if the operation generated on the file of the terminal is to delete the file, a sample file operation feature including the path of the deleted file, the deletion time of the file and the information of the user who deleted the file can be constructed based on the sample file operation behavior.
[0159] Step 302b: The model training device constructs a sample configuration operation feature based on the sample configuration operation behavior generated after the sample file is run.
[0160] In an embodiment of the present application, if the operation generated for the registry of the terminal is a path modification operation, a sample configuration operation feature including the location of the path, the format of the path, and the level of the registry where the path is located can be constructed according to the sample configuration operation behavior.
[0161] Step 302c: The model training device constructs a sample operation sequence feature based on the sample operation sequence information generated after the sample file is run.
[0162] In the embodiment of the present application, the sample operation sequence feature may refer to the order of steps of each operation generated after the sample file is run and the logical relationship between each step.
[0163] In one achievable manner, the sample operation sequence features may include sample operation sequence features of sample operations generated for files of the terminal and operation sequence features of sample operations generated for configuration information of the terminal. In another achievable manner, the sample operation sequence features may also include operation sequence features of sample operations generated for other information of the terminal.
[0164] Step 302d: The model training device determines a sample operation feature vector based on the sample file operation feature, the sample configuration operation feature, and the sample operation sequence feature.
[0165] The sample operation feature information includes a sample operation feature vector.
[0166] In an embodiment of the present application, different models can be used to process the sample file operation features, sample configuration operation features and sample operation sequence features respectively to obtain corresponding sample feature vectors. Then, the obtained multiple sample feature vectors are processed to obtain the final sample operation feature vector, that is, the sample operation feature information.
[0167] In the embodiment of the present application, step 302d can be implemented through steps 302d1 to 302d4.
[0168] It should be noted that in another feasible method, the static features of the sample file can be obtained, and the sample operation feature vector can be determined by combining the sample file operation features, the sample configuration operation features and the sample operation sequence features. In this case, step 302 can be implemented through steps 302d5 to 302d6.
[0169] Step 302d1: The model training device uses the target residual network model to process the sample file operation features to obtain a first sample feature vector.
[0170] In an embodiment of the present application, a ResNet model may be used to convert the sample file operation features to obtain a sample operation vector corresponding to the sample text operation features, that is, a first sample feature vector.
[0171] Step 302d2: The model training device uses the target bidirectional encoding model to process the sample configuration operation characteristics to obtain a second sample feature vector.
[0172] In an embodiment of the present application, the RoBERTa model can be used to convert the sample configuration operation feature to obtain a sample operation vector corresponding to the sample configuration operation feature, that is, a second sample feature vector.
[0173] Step 302d3: The model training device uses the target recurrent network model to process the sample operation sequence features to obtain a third sample feature vector.
[0174] In an embodiment of the present application, an LSTM model may be used to transform the sample operation sequence features to obtain a sample feature vector corresponding to the sample operation sequence features, that is, a third sample feature vector.
[0175] Step 302d4: The model training device fuses the first sample feature vector, the second sample feature vector and the third sample feature vector to obtain a sample operation feature vector.
[0176] In an embodiment of the present application, the first sample feature vector, the second sample feature vector and the third sample feature vector may be fused to obtain a sample operation feature vector for the operation of the terminal, and then the sample operation feature vector may be input into the initial information detection model.
[0177] Step 302d5: The model training device obtains sample static features of the sample file.
[0178] The static features of the sample are the features when the sample file is not in the running state.
[0179] In the embodiment of the present application, reference may be made to step 307e to extract static features of the sample file using a neural network model or the like.
[0180] Step 302d6: The model device determines a sample operation feature vector based on the sample file operation feature, the sample configuration operation feature, the sample operation sequence feature, and the sample static feature.
[0181] In an embodiment of the present application, different network models can be used to process sample file operation features, sample configuration operation features, sample operation sequence features and sample static features respectively to obtain multiple sample feature vectors. Then, the multiple sample feature vectors are processed to obtain a sample operation feature vector.
[0182] In the embodiment of the present application, step 302d6 can be implemented through steps 302d61 to 302d63.
[0183] Step 302d61, the model training device determines the first sample feature vector, the second sample feature vector and the third sample feature vector corresponding to the sample file operation feature, the sample configuration operation feature and the sample operation sequence feature respectively.
[0184] In an embodiment of the present application, referring to steps 407a to 407c, a target residual network model, a target bidirectional coding model, and a target recurrent network model are respectively used to process sample file operation features, sample configuration operation features, and sample operation sequence features to obtain a first sample feature vector, a second sample feature vector, and a third sample feature vector.
[0185] Step 302d62: The model training device uses the target gated network model to process the static features of the sample to obtain a fourth sample feature vector.
[0186] In the embodiment of the present application, the target gated network model may refer to a GRU model. Specifically, the GRU model may be used to convert the sample static features to obtain a feature vector corresponding to the sample static features, that is, the fourth sample feature vector.
[0187] Step 302d63: The model training device fuses the first sample feature vector, the second sample feature vector, the third sample feature vector and the fourth sample feature vector to obtain a sample operation feature vector.
[0188] In the embodiment of the present application, the first sample feature vector, the second sample feature vector, the third sample feature vector and the fourth sample feature vector may be fused to obtain a final sample operation feature vector.
[0189] Step 303: The model training device trains the initial information detection model based on the sample operation feature information to obtain the target information detection model.
[0190] In an embodiment of the present application, after the sample operation feature vector is input into the initial information detection model, the gating network in the initial information detection model can classify the input sample feature vector, and train different models in the initial information detection model according to different types of sample vectors to obtain the final target information detection model. Specifically, the gating network in the initial information detection model can classify the input sample feature vector and input it into different models in the initial information detection model, and then determine the detection result of the sample file (i.e., whether the sample file is a malicious file) according to the output result of each model and the weight of each model. When the detection result differs greatly from the actual information, adjust the weight and parameters of each model in the initial information detection model, and continue to train the adjusted initial information detection model according to the sample operation feature information until the target information detection model is trained.
[0191] The model training method provided in the embodiment of the present application can obtain the sample operation behavior generated after the sample file is run on the terminal, and determine the sample operation feature information based on the sample operation behavior. After that, the initial information detection model is trained based on the sample operation feature information to obtain the target information detection model; that is, when training the target information detection model, the dynamic operation behavior generated after the file to be detected is run is taken into account, rather than only considering the static attribute information of the file to be detected as in the related art, which solves the problem of low accuracy in detecting malicious files in the related art, thereby making the detection result of malicious files determined by the target information detection model more accurate.
[0192] Based on the above embodiments, the embodiments of the present application provide an information determination device, which can be applied to Figure 1 and 4 In the information determination method provided in the corresponding embodiment, refer to Figure 7 As shown, the information determination device 4 may include: a first acquisition unit 41, a first determination unit 42 and a processing unit 43, wherein:
[0193] The first acquisition unit 41 is used to acquire the operation behavior generated after the file to be detected is run on the terminal;
[0194] A first determining unit 42, configured to determine operation feature information based on the operation behavior;
[0195] The processing unit 43 is used to process the operation feature information using the target information detection model to obtain the detection result of the file to be detected; wherein the detection result indicates whether the file to be detected is a malicious file; the target information detection model is obtained by training the initial information detection model based on the sample operation feature information; the sample operation feature information is determined based on the sample operation behavior generated after the sample file is run on the terminal.
[0196] In other embodiments of the present application, the first acquisition unit 41 is further configured to perform the following steps:
[0197] Obtain the file operation behavior generated on the file in the terminal after the file to be detected is run;
[0198] Obtain the configuration operation behavior generated by the terminal configuration information after the file to be detected is run;
[0199] Obtain the operation sequence information of the operations generated on the terminal after the file to be detected is run.
[0200] In other embodiments of the present application, the first determining unit 42 is further configured to perform the following steps:
[0201] Construct file operation features based on the file operation behaviors generated after the file to be detected is run;
[0202] Based on the configuration operation behaviors generated after the file to be detected is run, a configuration operation feature is constructed;
[0203] Based on the operation sequence information generated after the file to be detected is run, an operation sequence feature is constructed;
[0204] Based on the file operation feature, the configuration operation feature and the operation sequence feature, an operation feature vector is determined; wherein the operation feature information includes the operation feature vector.
[0205] In other embodiments of the present application, the first determining unit 42 is further configured to perform the following steps:
[0206] The target residual network model is used to process the file operation features to obtain the first feature vector;
[0207] The configuration operation features are processed using a target bidirectional encoding model to obtain a second feature vector;
[0208] The target recurrent network model is used to process the operation sequence features to obtain the third feature vector;
[0209] The first eigenvector, the second eigenvector and the third eigenvector are fused to obtain an operation eigenvector.
[0210] In other embodiments of the present application, the first determining unit 42 is further configured to perform the following steps:
[0211] Obtaining static features of the file to be detected; wherein the static features are features of the file to be detected when it is not in a running state;
[0212] An operation feature vector is determined based on the file operation feature, the configuration operation feature, the operation sequence feature and the static feature.
[0213] In other embodiments of the present application, the first determining unit 42 is further configured to perform the following steps:
[0214] Determine a first feature vector, a second feature vector, and a third feature vector corresponding to the file operation feature, the configuration operation feature, and the operation sequence feature, respectively;
[0215] The static features are processed using a target gated network model to obtain a fourth eigenvector;
[0216] The first eigenvector, the second eigenvector, the third eigenvector and the fourth eigenvector are fused to obtain an operation eigenvector.
[0217] It should be noted that the specific implementation process of the steps performed by each unit in this embodiment can be referred to Figure 1 and 4 The implementation process of the information determination method provided in the corresponding embodiment will not be repeated here.
[0218] The information determination device provided in the embodiment of the present application can obtain the dynamic operation behavior generated after the file to be detected is run, and then use the target information detection model to process the operation feature information determined based on the dynamic operation behavior to determine whether the file to be detected is a malicious file. That is, when detecting malicious files, the dynamic operation behavior generated after the file to be detected is processed is taken into account, rather than only considering the static attribute information of the file to be detected as in the related art, which solves the problem of low accuracy in detecting malicious files when detecting malicious files in the related art.
[0219] Based on the above embodiments, the embodiments of the present application provide a model training device, which can be applied to Figure 1 and 6 In the model training method provided in the corresponding embodiment, refer to Figure 8 As shown, the model training device 5 may include: a second acquisition unit 51, a second determination unit 52 and a training unit 53, wherein:
[0220] The second acquisition unit 51 is used to acquire the sample operation behavior generated after the sample file is run on the terminal;
[0221] A second determining unit 52, configured to determine sample operation feature information based on the sample operation behavior;
[0222] The training unit 53 is used to train the initial information detection model based on the sample operation feature information to obtain the target information detection model.
[0223] In other embodiments of the present application, the second acquisition unit 51 is further configured to perform the following steps:
[0224] Get the sample file operation behavior generated for the file in the terminal after the sample file is run;
[0225] After obtaining the sample file and running it, the sample configuration operation behavior generated for the terminal configuration information;
[0226] Get sample operation sequence information of operations generated on the terminal after the sample file is run.
[0227] In other embodiments of the present application, the second determining unit 52 is further configured to perform the following steps:
[0228] Based on the sample file operation behaviors generated after the sample file is run, construct the sample file operation features;
[0229] Based on the sample configuration operation behaviors generated after the sample file is run, a sample configuration operation feature is constructed;
[0230] Based on the sample operation sequence information generated after the sample file is run, a sample operation sequence feature is constructed;
[0231] Based on the sample file operation feature, the sample configuration operation feature and the sample operation sequence feature, a sample operation feature vector is determined; wherein the sample operation feature information includes the sample operation feature vector.
[0232] In other embodiments of the present application, the second determining unit 52 is further configured to perform the following steps:
[0233] Using the target residual network model to process the sample file operation features to obtain a first sample feature vector;
[0234] The sample configuration operation feature is processed using a target bidirectional encoding model to obtain a second sample feature vector;
[0235] The target recurrent network model is used to process the sample operation sequence features to obtain a third sample feature vector;
[0236] The first sample feature vector, the second sample feature vector and the third sample feature vector are fused to obtain a sample operation feature vector.
[0237] In other embodiments of the present application, the second determining unit 52 is further configured to perform the following steps:
[0238] Obtaining sample static features of the sample file; wherein the sample static features are features when the sample file is not in a running state;
[0239] A sample operation feature vector is determined based on the sample file operation feature, the sample configuration operation feature, the sample operation sequence feature and the sample static feature.
[0240] In other embodiments of the present application, the second determining unit 52 is further configured to perform the following steps:
[0241] Determine a first sample feature vector, a second sample feature vector, and a third sample feature vector corresponding to the sample file operation feature, the sample configuration operation feature, and the sample operation sequence feature, respectively;
[0242] The target gated network model is used to process the static features of the sample to obtain a fourth sample feature vector;
[0243] The first sample feature vector, the second sample feature vector, the third sample feature vector and the fourth sample feature vector are fused to obtain a sample operation feature vector.
[0244] It should be noted that the specific implementation process of the steps performed by each unit in this embodiment can be referred to Figure 6 The implementation process of the model training method provided in the corresponding embodiment will not be repeated here.
[0245] The model training device provided in the embodiment of the present application can obtain the sample operation behavior generated after the sample file is run on the terminal, and determine the sample operation feature information based on the sample operation behavior. After that, the initial information detection model is trained based on the sample operation feature information to obtain the target information detection model; that is, when training the target information detection model, the dynamic operation behavior generated after the file to be detected is run is taken into account, rather than only considering the static attribute information of the file to be detected as in the related art, which solves the problem of low accuracy in detecting malicious files in the related art, thereby making the detection result of malicious files determined by the target information detection model more accurate.
[0246] Based on the above embodiments, the embodiments of the present application provide an information determination device, which can be applied to Figure 1 and 4 In the information determination method provided in the corresponding embodiment, refer to Fig. 9 As shown, the information determination device 6 may include: a first processor 61, a first memory 62 and a first communication bus 63, wherein:
[0247] The first communication bus 63 is used to realize the communication connection between the first processor 61 and the first memory 62;
[0248] The first processor 61 is used to execute the information determination program in the first memory 62 to implement the following steps:
[0249] Obtain the operation behavior generated after the file to be detected is run on the terminal;
[0250] Determine operation characteristic information based on the operation behavior;
[0251] The target information detection model is used to process the operation feature information to obtain the detection result of the file to be detected; wherein the detection result represents whether the file to be detected is a malicious file; the target information detection model is obtained after training the initial information detection model based on the sample operation feature information; the sample operation feature information is determined based on the sample operation behavior generated after the sample file is run on the terminal.
[0252] In other embodiments of the present application, the first processor 61 is used to execute the operation behavior generated after the file to be detected is run on the terminal in the first memory 62 to implement the following steps:
[0253] Obtain the file operation behavior generated on the file in the terminal after the file to be detected is run;
[0254] Obtain the configuration operation behavior generated by the terminal configuration information after the file to be detected is run;
[0255] Obtain the operation sequence information of the operations generated on the terminal after the file to be detected is run.
[0256] In other embodiments of the present application, the first processor 61 is used to execute the information determination program in the first memory 62 to determine the operation characteristic information based on the operation behavior, so as to implement the following steps:
[0257] Construct file operation features based on the file operation behaviors generated after the file to be detected is run;
[0258] Based on the configuration operation behaviors generated after the file to be detected is run, a configuration operation feature is constructed;
[0259] Based on the operation sequence information generated after the file to be detected is run, an operation sequence feature is constructed;
[0260] Based on the file operation feature, the configuration operation feature and the operation sequence feature, an operation feature vector is determined; wherein the operation feature information includes the operation feature vector.
[0261] In other embodiments of the present application, the first processor 61 is used to execute the information determination program in the first memory 62 to determine the operation feature vector based on the file operation feature, the configuration operation feature and the operation sequence feature, so as to implement the following steps:
[0262] The target residual network model is used to process the file operation features to obtain the first feature vector;
[0263] The configuration operation features are processed using a target bidirectional encoding model to obtain a second feature vector;
[0264] The target recurrent network model is used to process the operation sequence features to obtain the third feature vector;
[0265] The first eigenvector, the second eigenvector and the third eigenvector are fused to obtain an operation eigenvector.
[0266] In other embodiments of the present application, the first processor 61 is further configured to execute the information determination program in the first memory 62 to determine the operation characteristic information based on the operation behavior, so as to implement the following steps:
[0267] Obtaining static features of the file to be detected; wherein the static features are features of the file to be detected when it is not in a running state;
[0268] An operation feature vector is determined based on the file operation feature, the configuration operation feature, the operation sequence feature and the static feature.
[0269] In other embodiments of the present application, the first processor 61 is further configured to execute the information determination program in the first memory 62 to determine the operation feature vector based on the file operation feature, the configuration operation feature, the operation sequence feature and the static feature, so as to implement the following steps:
[0270] Determine a first feature vector, a second feature vector, and a third feature vector corresponding to the file operation feature, the configuration operation feature, and the operation sequence feature, respectively;
[0271] The static features are processed using a target gated network model to obtain a fourth eigenvector;
[0272] The first eigenvector, the second eigenvector, the third eigenvector and the fourth eigenvector are fused to obtain an operation eigenvector.
[0273] It should be noted that the specific implementation process of the steps executed by the first processor in this embodiment can refer to Figure 1 and 4 The implementation process of the information determination method provided in the corresponding embodiment will not be repeated here.
[0274] The information determination device provided by the embodiment of the present application can obtain the dynamic operation behavior generated after the file to be detected is run, and then use the target information detection model to process the operation feature information determined based on the dynamic operation behavior to determine whether the file to be detected is a malicious file. That is, when detecting malicious files, the dynamic operation behavior generated after the file to be detected is processed is taken into account, rather than only considering the static attribute information of the file to be detected as in the related art, which solves the problem of low accuracy in detecting malicious files when detecting malicious files in the related art.
[0275] Based on the above embodiments, the embodiments of the present application provide a model training device, which can be applied to Figure 1 and 6 In the model training method provided in the corresponding embodiment, refer to Fig.10 As shown, the model training device 7 may include: a second processor 71, a second memory 72, and a second communication bus 73, wherein:
[0276] The second communication bus 73 is used to realize the communication connection between the second processor 71 and the second memory 72;
[0277] The second processor 71 is used to execute the model training program in the second memory 72 to implement the following steps:
[0278] Get the sample operation behavior generated after the sample file is run on the terminal;
[0279] Determine sample operation characteristic information based on the sample operation behavior;
[0280] The initial information detection model is trained based on the sample operation feature information to obtain the target information detection model.
[0281] In other embodiments of the present application, the second processor 71 is further used to execute the sample operation behavior generated after the acquisition sample file of the model training program in the second memory 72 is run on the terminal, so as to implement the following steps:
[0282] Get the sample file operation behavior generated for the file in the terminal after the sample file is run;
[0283] After obtaining the sample file and running it, the sample configuration operation behavior generated for the terminal configuration information;
[0284] Get sample operation sequence information of operations generated on the terminal after the sample file is run.
[0285] In other embodiments of the present application, the second processor 71 is further configured to execute the model training program in the second memory 72 to determine the sample operation feature information based on the sample operation behavior, so as to implement the following steps:
[0286] Based on the sample file operation behaviors generated after the sample file is run, construct the sample file operation features;
[0287] Based on the sample configuration operation behaviors generated after the sample file is run, a sample configuration operation feature is constructed;
[0288] Based on the sample operation sequence information generated after the sample file is run, a sample operation sequence feature is constructed;
[0289] Based on the sample file operation feature, the sample configuration operation feature and the sample operation sequence feature, a sample operation feature vector is determined; wherein the sample operation feature information includes the sample operation feature vector.
[0290] In other embodiments of the present application, the second processor 71 is further used to execute the model training program in the second memory 72 based on the sample file operation characteristics, the sample configuration operation characteristics and the sample operation sequence characteristics, and determine the sample operation feature vector to implement the following steps:
[0291] Using the target residual network model to process the sample file operation features to obtain a first sample feature vector;
[0292] The sample configuration operation feature is processed using a target bidirectional encoding model to obtain a second sample feature vector;
[0293] The target recurrent network model is used to process the sample operation sequence features to obtain a third sample feature vector;
[0294] The first sample feature vector, the second sample feature vector and the third sample feature vector are fused to obtain a sample operation feature vector.
[0295] In other embodiments of the present application, the second processor 71 is further configured to execute the model training program in the second memory 72 to determine the sample operation feature information based on the sample operation behavior, so as to implement the following steps:
[0296] Obtaining sample static features of the sample file; wherein the sample static features are features when the sample file is not in a running state;
[0297] A sample operation feature vector is determined based on the sample file operation feature, the sample configuration operation feature, the sample operation sequence feature and the sample static feature.
[0298] In other embodiments of the present application, the second processor 71 is further used to execute the model training program in the second memory 72 based on the sample file operation features, the sample configuration operation features, the sample operation sequence features and the sample static features, and determine the sample operation feature vector to implement the following steps:
[0299] Determine a first sample feature vector, a second sample feature vector, and a third sample feature vector corresponding to the sample file operation feature, the sample configuration operation feature, and the sample operation sequence feature, respectively;
[0300] The target gated network model is used to process the static features of the sample to obtain a fourth sample feature vector;
[0301] The first sample feature vector, the second sample feature vector, the third sample feature vector and the fourth sample feature vector are fused to obtain a sample operation feature vector.
[0302] It should be noted that the specific implementation process of the steps executed by the processor in this embodiment can refer to Figure 6 The implementation process of the model training method provided in the corresponding embodiment will not be repeated here.
[0303] The model training device provided in the embodiment of the present application can obtain the sample operation behavior generated after the sample file is run on the terminal, and determine the sample operation feature information based on the sample operation behavior. After that, the initial information detection model is trained based on the sample operation feature information to obtain the target information detection model; that is, when training the target information detection model, the dynamic operation behavior generated after the file to be detected is run is taken into account, rather than only considering the static attribute information of the file to be detected as in the related art, which solves the problem of low accuracy in detecting malicious files in the related art, thereby making the detection result of malicious files determined by the target information detection model more accurate.
[0304] Based on the foregoing embodiments, the embodiments of the present application provide a computer-readable storage medium, which stores one or more programs, and the one or more programs can be executed by one or more processors to implement Figure 1 and 4 The information determination method provided by the corresponding embodiment, and Figure 6 The corresponding embodiments provide steps of the model training method.
[0305] Based on the above embodiments, an embodiment of the present application provides a computer program product, the computer program product includes a computer program, the computer program is executed by a processor to achieve Figure 1 and 4 The information determination method provided by the corresponding embodiment, and Figure 6 The corresponding embodiments provide steps of the model training method.
[0306] It should be noted that the above-mentioned computer-readable storage medium can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory (Flash Memory), a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM) and other memories; it can also be various electronic devices including one or any combination of the above-mentioned memories, such as mobile phones, computers, tablet devices, personal digital assistants, etc.
[0307] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or device including the element.
[0308] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0309] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, a disk, or an optical disk), and includes a number of instructions for a terminal device (which can be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in each embodiment of the present application.
[0310] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0311] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0312] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
Claims
1. A method for determining information, characterized in that: The method comprises: Obtain the operation behavior generated after the file to be detected is run on the terminal; Determining operation characteristic information based on the operation behavior; The operation characteristic information is processed by a target information detection model to obtain a detection result of the file to be detected; wherein, the detection result indicates whether the file to be detected is a malicious file; the target information detection model is obtained by training an initial information detection model based on sample operation characteristic information; the sample operation characteristic information is determined based on a sample operation behavior generated after the sample file is run on the terminal.
2. The method according to claim 1, characterized in that The obtaining of the operation behavior generated after the file to be detected is run on the terminal includes: Obtaining file operation behaviors generated on files in the terminal after the file to be detected is run; Obtaining configuration operation behavior generated for the configuration information of the terminal after the file to be detected is run; Obtain operation sequence information of operations generated on the terminal after the file to be detected is run.
3. The method according to claim 1 or 2, characterized in that: The determining of the operation characteristic information based on the operation behavior includes: Building a file operation feature based on the file operation behavior generated after the file to be detected is run; Constructing configuration operation features based on the configuration operation behavior generated after the file to be detected is run; Constructing an operation sequence feature based on the operation sequence information generated after the file to be detected is run; An operation feature vector is determined based on the file operation feature, the configuration operation feature and the operation sequence feature; wherein the operation feature information includes the operation feature vector.
4. The method according to claim 3, characterized in that The determining of the operation feature vector based on the file operation feature, the configuration operation feature and the operation sequence feature comprises: Using a target residual network model to process the file operation feature to obtain a first feature vector; Processing the configuration operation feature using a target bidirectional encoding model to obtain a second feature vector; Using a target recurrent network model to process the operation sequence features to obtain a third feature vector; The first feature vector, the second feature vector and the third feature vector are fused to obtain the operation feature vector.
5. The method according to claim 3, characterized in that: The determining of the operation feature vector based on the file operation feature, the configuration operation feature and the operation sequence feature comprises: Acquire static features of the file to be detected; wherein the static features are features of the file to be detected when it is not in a running state; Determining the operation feature vector based on the file operation feature, the configuration operation feature, the operation sequence feature and the static feature; Accordingly, determining the operation feature vector based on the file operation feature, the configuration operation feature, the operation sequence feature and the static feature includes: Determine a first feature vector, a second feature vector, and a third feature vector corresponding to the file operation feature, the configuration operation feature, and the operation sequence feature, respectively; Using a target gated network model to process the static features to obtain a fourth feature vector; The first eigenvector, the second eigenvector, the third eigenvector and the fourth eigenvector are fused to obtain the operation eigenvector.
6. A model training method, characterized in that: The method further comprises: Get the sample operation behavior generated after the sample file is run on the terminal; Determining sample operation characteristic information based on the sample operation behavior; The initial information detection model is trained based on the sample operation characteristic information to obtain a target information detection model.
7. The method according to claim 6, characterized in that The obtaining of sample operation behaviors generated after the sample file is run on the terminal includes: Obtaining sample file operation behaviors generated for files in the terminal after the sample file is run; Obtaining sample configuration operation behaviors generated for the configuration information of the terminal after the sample file is run; After the sample file is executed, sample operation sequence information of the operation generated for the terminal is obtained.
8. The method according to claim 6 or 7, characterized in that: The determining of sample operation feature information based on the sample operation behavior includes: Constructing sample file operation features based on sample file operation behaviors generated after the sample file is run; Constructing a sample configuration operation feature based on the sample configuration operation behavior generated after the sample file is run; Constructing a sample operation sequence feature based on the sample operation sequence information generated after the sample file is run; Based on the sample file operation feature, the sample configuration operation feature and the sample operation sequence feature, a sample operation feature vector is determined; wherein the sample operation feature information includes the sample operation feature vector.
9. The method according to claim 8, characterized in that The determining of the sample operation feature vector based on the sample file operation feature, the sample configuration operation feature and the sample operation sequence feature includes: Using a target residual network model to process the sample file operation feature to obtain a first sample feature vector; Processing the sample configuration operation feature using a target bidirectional encoding model to obtain a second sample feature vector; Using a target recurrent network model to process the sample operation sequence features to obtain a third sample feature vector; The first sample feature vector, the second sample feature vector and the third sample feature vector are fused to obtain the sample operation feature vector.
10. The method according to claim 8, characterized in that The determining of the sample operation feature vector based on the sample file operation feature, the sample configuration operation feature and the sample operation sequence feature includes: Acquire a sample static feature of the sample file; wherein the sample static feature is a feature when the sample file is not in a running state; Determine the sample operation feature vector based on the sample file operation feature, the sample configuration operation feature, the sample operation sequence feature and the sample static feature; Accordingly, determining the sample operation feature vector based on the sample file operation feature, the sample configuration operation feature, the sample operation sequence feature and the sample static feature includes: Respectively determine a first sample feature vector, a second sample feature vector, and a third sample feature vector corresponding to the sample file operation feature, the sample configuration operation feature, and the sample operation sequence feature; Processing the sample static features using a target gated network model to obtain a fourth sample feature vector; The first sample feature vector, the second sample feature vector, the third sample feature vector and the fourth sample feature vector are fused to obtain the sample operation feature vector.
11. An information determination device, characterized in that: The device comprises: The first acquisition unit is used to acquire the operation behavior generated after the file to be detected is run on the terminal; A first determining unit, configured to determine operation feature information based on the operation behavior; A processing unit is used to process the operation feature information using a target information detection model to obtain a detection result of the file to be detected; wherein the detection result indicates whether the file to be detected is a malicious file; the target information detection model is obtained by training an initial information detection model based on sample operation feature information; the sample operation feature information is determined based on a sample operation behavior generated after the sample file is run on the terminal.
12. A model training device, characterized in that: The device comprises: The second acquisition unit is used to acquire the sample operation behavior generated after the sample file is run on the terminal; A second determining unit, configured to determine sample operation feature information based on the sample operation behavior; The training unit is used to train the initial information detection model based on the sample operation feature information to obtain the target information detection model.
13. An information determination device, characterized in that: The device comprises: a first processor, a first memory and a first communication bus; The first communication bus is used to realize the communication connection between the first processor and the first memory; The first processor is used to execute the information determination program in the first memory to implement the steps of the information determination method according to any one of claims 1 to 5.
14. A model training device, characterized in that: The device comprises: a second processor, a second memory, and a second communication bus; The second communication bus is used to realize the communication connection between the second processor and the second memory; The second processor is used to execute the model training program in the second memory to implement the steps of the model training method as described in any one of claims 6 to 10.
15. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the information determination method as described in any one of claims 1 to 5, or the steps of the model training method as described in any one of claims 6 to 10.
16. A computer program product, comprising a computer program, characterized in that: When the computer program is executed by a processor, the computer program implements the steps of the method according to any one of claims 1 to 5 or 6 to 10.