Malicious software method and device, electronic equipment, storage medium and program product

By acquiring and analyzing the software's opcode sequence, static and dynamic characteristics, and combining with the aggregation model for detection, the problem of malware detection accuracy and high false alarm rate is solved, and efficient and automated malware detection is achieved.

CN119939582APending Publication Date: 2025-05-06CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411997225.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In the case of large software differentiation, how to improve detection accuracy and reduce false positives, especially in the face of rapid variants of malware and high concealment.

Method used

By obtaining the opcode sequence of the software to be detected, converting it into an opcode set, combining static and dynamic features, aggregation models such as multi-random forests for feature space oversampling and consensus prediction are used to improve the accuracy of software detection.

Benefits of technology

This method can improve the accuracy of software detection, reduce false positives, and effectively judge malware that has not appeared, realize fully automated detection without relying on manual participation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939582A_ABST
    Figure CN119939582A_ABST
Patent Text Reader

Abstract

The invention provides a malicious software method and device, electronic equipment, a storage medium and a program product, and relates to the technical field of security. The method comprises the following steps: acquiring an operation code sequence of software to be detected, wherein the operation code sequence comprises a plurality of operation codes; converting the operation code sequence into an operation code set, wherein the operation code set is an n-gram set; obtaining a first feature set according to the operation code set and the operation codes; obtaining static characteristics and dynamic characteristics of the to-be-detected software; obtaining a second feature set according to the static features and the dynamic features; and based on the aggregation model, obtaining a software detection result according to the first feature set and the second feature set. According to the method, the composite features of static, dynamic and operation code features are fused for analysis, consensus prediction is provided by the aggregation model, malicious software which does not appear can be judged, the accuracy of software detection is improved, and false alarms are reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] With the rapid development of Internet technology, application software continues to emerge and has a profound impact on people's lives. However, the emergence of malware poses a serious threat to users' privacy and security, and may also cause damage to computers, servers, and cloud computing environments. Illegal attacks launched by malware have posed a severe challenge to Internet security, and the number of malware has shown a sharp growth trend. To make matters more complicated, various variants emerge in an endless stream, and these malware variants are often highly concealed and extremely difficult to detect by traditional detection methods. At the same time, more and more advanced technologies are used to evade security detection, further exacerbating the complexity and severity of this problem.

[0003] How to improve detection accuracy and reduce false alarms when software differentiation is large is an issue that needs to be addressed urgently.

[0004] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute the prior art known to ordinary technicians in the field. Summary of the invention

[0005] The present disclosure provides a malware method, device, electronic device, storage medium and program product, which at least to a certain extent improve the accuracy of software detection and reduce false positives.

[0006] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by the practice of the present disclosure.

[0007] According to one aspect of the present disclosure, a malware detection method is provided, including: obtaining an operation code sequence of software to be detected, wherein the operation code sequence includes multiple operation codes; converting the operation code sequence into an operation code set, wherein the operation code set is an n-gram set; obtaining a first feature set based on the operation code set and the operation code; obtaining static features and dynamic features of the software to be detected; obtaining a second feature set based on the static features and the dynamic features; and obtaining a software detection result based on the first feature set and the second feature set based on an aggregation model.

[0008] In one embodiment of the present disclosure, before obtaining the operation code sequence of the software to be detected, the method further includes: obtaining the software to be detected; and disassembling the software to be detected to extract the operation code sequence.

[0009] In one embodiment of the present disclosure, a first feature set is obtained based on the operation code set and the operation code, including: calculating the importance of each of the operation codes in the operation code set based on word frequency inverse document frequency to obtain a first feature vector; and performing dimensionality reduction processing on the first feature vector using PCA principal component analysis to obtain the first feature set.

[0010] In one embodiment of the present disclosure, before acquiring the static features and dynamic features of the software to be detected, the method further includes: extracting features of the software to be detected based on entropy calculation and code reuse patterns to obtain the static features and dynamic features of the software to be detected.

[0011] In one embodiment of the present disclosure, obtaining a second feature set according to the static features and the dynamic features includes: obtaining a combined feature according to the static features and the dynamic features; and performing dimensionality reduction processing on the combined feature to obtain the second feature set.

[0012] In one embodiment of the present disclosure, the aggregation model is an aggregation model of multiple random forests; wherein, based on the aggregation model, a software detection result is obtained according to the first feature set and the second feature set, including: oversampling the feature space according to the first feature set and the second feature set to obtain balanced features; inputting the balanced features into the aggregation model of the random forest to perform consensus prediction to obtain the software detection result; wherein the consensus prediction is determined by a majority voting mechanism.

[0013] According to another aspect of the present disclosure, a malware detection device is provided, including: an acquisition module, used to acquire an operation code sequence of a software to be detected, wherein the operation code sequence includes multiple operation codes; a conversion module, used to convert the operation code sequence into an operation code set, wherein the operation code set is an n-gram set; a processing module, used to obtain a first feature set according to the operation code set and the operation code; the acquisition module is also used to acquire static features and dynamic features of the software to be detected; the processing module is also used to obtain a second feature set according to the static features and the dynamic features; a detection module, used to obtain a software detection result according to the first feature set and the second feature set based on an aggregation model.

[0014] According to another aspect of the present disclosure, there is provided an electronic device, comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute any of the above-mentioned malware detection methods by executing the executable instructions.

[0015] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, any of the above-mentioned malware detection methods is implemented.

[0016] According to another aspect of the present disclosure, a computer program product is provided, wherein the computer program product includes a computer program or computer instructions, and the computer program or the computer instructions are loaded and executed by a processor so that a computer implements any of the above-mentioned malware detection methods.

[0017] In an embodiment of the present disclosure, an operation code sequence of the software to be detected is first obtained, wherein the operation code sequence includes a plurality of operation codes; the operation code sequence is converted into an operation code set, wherein the operation code set is an n-gram set; a first feature set is obtained according to the operation code set and the operation code; static features and dynamic features of the software to be detected are then obtained; a second feature set is obtained according to the static features and the dynamic features; and a software detection result is obtained according to the first feature set and the second feature set based on an aggregation model. The present disclosure integrates composite features of static, dynamic, and operation code features (assembly features) for analysis, and the consensus prediction provided by the aggregation model can determine malware that has not appeared before, thereby improving the accuracy of software detection (classification accuracy) and reducing false positives.

[0018] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification are used to explain the principles of the present disclosure. Obviously, the accompanying drawings described below are only some embodiments of the present disclosure, and for ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without creative work.

[0020] Figure 1 A schematic diagram showing a malware detection system architecture in an embodiment of the present disclosure.

[0021] Figure 2 A flow chart of a malware detection method in an embodiment of the present disclosure is shown.

[0022] Figure 3 A flowchart of a malware detection method in another embodiment of the present disclosure is shown.

[0023] Figure 4 A schematic diagram of a malware detection device in an embodiment of the present disclosure is shown.

[0024] Figure 5A structural block diagram of an electronic device in an embodiment of the present disclosure is shown.

[0025] Figure 6 A schematic diagram of a computer-readable storage medium provided in an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0026] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that the disclosure will be more comprehensive and complete and to fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0027] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the figures represent the same or similar parts, and their repeated description will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor devices and / or microcontroller devices.

[0028] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.

[0029] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0030] It should be noted that the modifications of "one" and "plurality" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more".

[0031] The specific implementation of the embodiment of the present disclosure is described in detail below with reference to the accompanying drawings.

[0032] Figure 1 A schematic diagram of a malware detection system architecture in an embodiment of the present disclosure is shown, and the system can apply the malware detection method or malware detection device in various embodiments of the present disclosure.

[0033] like Figure 1As shown, the system architecture may include a terminal device 101 , a network 102 and a server 103 .

[0034] The terminal device 101 and the server 103 are connected to each other through a network 102, which can be a wired network or a wireless network.

[0035] Optionally, the wireless network or wired network described above uses standard communication technology and / or protocol. The network is usually the Internet, but it can also be any network, including but not limited to a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a dedicated network or any combination of a virtual private network). In some embodiments, technologies and / or formats including Hyper Text Mark-up Language (HTML), Extensible Markup Language (XML), etc. are used to represent data exchanged through the network. In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPsec) can also be used to encrypt all or some links. In other embodiments, customized and / or dedicated data communication technologies can also be used to replace or supplement the above data communication technologies.

[0036] The terminal device 101 can be various electronic devices, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, wearable devices, augmented reality devices, virtual reality devices, etc.

[0037] Optionally, the client of the application installed in different terminal devices 101 is the same, or the client of the same type of application based on different operating systems. Based on the different terminal platforms, the specific form of the client of the application can also be different, for example, the application client can be a mobile client, a PC client, etc.

[0038] The server 103 may be a server that provides various services, such as a background management server that provides support for the device operated by the user using the terminal device 101. The background management server may analyze and process the received request and other data, and feed back the processing results to the terminal device.

[0039] Optionally, the server can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), as well as big data and artificial intelligence platforms.

[0040] It should be noted that the software to be detected can complete the detection of malware on the terminal device 101; it can also complete the detection of malware on the server 103; the software to be detected can also be sent to the server 103 through the terminal device 101, and the detection of malware can be completed on the server 103; the software to be detected can also be sent to the terminal device 101 through the server 103, and the detection of malware can be completed on the terminal device 101.

[0041] Those skilled in the art will know that Figure 1 The number of terminal devices, networks and servers in the embodiment is only for illustration, and any number of terminal devices, networks and servers may be provided according to actual needs, and the embodiments of the present disclosure do not limit this.

[0042] The present exemplary implementation is described in detail below with reference to the accompanying drawings and embodiments.

[0043] A malware detection method is provided in an embodiment of the present disclosure. The method can be executed by any electronic device with computing and processing capabilities.

[0044] Figure 2 A flowchart of a malware detection method according to an embodiment of the present disclosure is shown as follows: Figure 2 As shown, the malware detection method provided in the embodiment of the present disclosure includes the following S201 to S206.

[0045] S201, obtaining an operation code sequence of the software to be detected, where the operation code sequence includes a plurality of operation codes.

[0046] In the embodiments of the present disclosure, there is no specific limitation on how to obtain the operation code sequence of the software to be detected. For example, before obtaining the operation code sequence of the software to be detected, the malware detection method provided by the present disclosure may also include: obtaining the software to be detected; disassembling the software to be detected and extracting the operation code sequence.

[0047] Exemplarily, the sequence is extracted by disassembling the software to be tested, and the operation code (also known as the operation code instruction) instruction s is extracted. 1 ,s 2 ,...,sm , obtained from each file in order. Generate a detailed representation of program behavior at the instruction level. Let S be a set of opcode sequences, where each opcode sequence can be represented as: S = {s 1 ,s 2 ,...,s m}, where m is the total number of opcodes.

[0048] The disclosed embodiment can obtain the assembly features of the software to be detected by extracting the operation code, thereby improving the accuracy of software detection and reducing false positives.

[0049] S202, converting the operation code sequence into an operation code set, where the operation code set is an n-gram set.

[0050] In the disclosed embodiment, the opcode sequence is converted into an opcode set, thereby achieving data structuring. The opcode sequence is segmented into n-grams to capture local dependencies and sequence patterns in the executable file. In other words, n-grams are local patterns in the opcode sequence.

[0051] For example, the n-gram set can be expressed as: P = {p 1 ,p 2 ,...,p i ,...,p k}, where p i is a subsequence of opcodes, p i =(s i ,s i+1 ,...,s i+n-1 ), the conversion results in k overlapping n-grams for each opcode sequence, where k = m-n+1, ​​k is the total number of opcode subsequences, and n is the length of the opcode subsequence. The n-grams may contain patterns that indicate malware behavior.

[0052] For example, there are 5 opcodes in the opcode sequence, n = 3, then each p i It will be a combination of 3 consecutive opcodes (i.e., a subsequence of opcodes), which can generate 3 n-grams, which are p 1 =(s 1 ,s 2 ,s 3 ), p 2 =(s 2 ,s 3 ,s 4 ) and p 3 =(s 3 ,s 4 ,s 5 ).

[0053] S203: Obtain a first feature set according to the operation code set and the operation code.

[0054] In the disclosed embodiment, the first feature set is a set for representing assembly characteristics. The disclosed embodiment does not limit how to obtain the first feature set from the operation code set and the operation code. For example, the importance of each operation code in the operation code set is calculated to obtain a high-dimensional feature vector, and then the high-dimensional feature vector is reduced in dimension by a dimensionality reduction algorithm to obtain the first feature set. The disclosed embodiment converts the high-dimensional feature vector to a low-dimensional space, improves the model efficiency, and reduces the risk of overfitting.

[0055] S204, obtaining static features and dynamic features of the software to be detected.

[0056] In the embodiments of the present disclosure, static features are features that do not depend on the execution state of the software to be detected, and can be obtained before the program is loaded or when it is not running. Static features describe information such as the structure, content, and dependencies of the program. For malware detection, static features can preliminarily determine whether a program may be malicious. For example, the present disclosure can use static analysis technology to extract static features such as the file header, section name, and import library of the software to be detected, and analyze the structure and dependencies of the binary file of the software to be detected.

[0057] In the disclosed embodiment, the dynamic feature is the behavior exhibited by the software to be detected during execution, which is collected when the software to be detected is running. Dynamic features can verify whether the potential malicious behavior inferred in static analysis will occur in actual execution. For example, a certain API (Application Programming Interface) call may indicate that the program will perform file operations or network communications. However, static analysis cannot fully reveal the behavior of the program in actual execution. Dynamic analysis provides actual behavioral data by monitoring the running process of the program to help verify whether the potential threats revealed by static analysis will be triggered when the program is executed. Regarding how to obtain dynamic features, the disclosed embodiment does not make specific restrictions. For example, the software to be detected is dynamically run in a controlled environment, and the running behavior is recorded and analyzed to obtain dynamic features, such as recording the running file system interaction, network communication and registry modification, capturing the behavior of API calls and encryption routines, etc., and analyzing to obtain dynamic features.

[0058] For example, the software to be detected may frequently perform memory allocation and release operations, or generate abnormal behaviors such as stack overflow, which may indicate the presence of malware.

[0059] S205: Obtain a second feature set according to the static features and the dynamic features.

[0060] In the embodiment of the present disclosure, the second feature set is a set for representing the combination of static and dynamic characteristics. The embodiment of the present disclosure does not limit how to obtain the second feature set based on the static features and dynamic features. For example, the static features and dynamic features are input into the machine learning model, and the second feature set is output. The present disclosure combines the static features and dynamic features and inputs them into the machine learning model, which can not only make full use of the information of both and improve the prediction ability, but also enhance the generalization ability, stability and robustness of the model.

[0061] S206, obtaining a software detection result based on the aggregation model and the first feature set and the second feature set.

[0062] The disclosed embodiment first obtains the opcode sequence of the software to be detected, the opcode sequence includes multiple opcodes; converts the opcode sequence into an opcode set, the opcode set is an n-gram set; obtains a first feature set based on the opcode set and the opcode; then obtains static features and dynamic features of the software to be detected; obtains a second feature set based on the static features and the dynamic features; and obtains software detection results based on the first feature set and the second feature set based on the aggregation model. The disclosed embodiment integrates the composite features of static, dynamic, and opcode features for analysis, and the consensus prediction provided by the aggregation model can determine malware that has not appeared before, improve the accuracy of software detection, and reduce false positives.

[0063] In addition, the present disclosure can realize automatic detection without relying on human participation.

[0064] The present disclosure is further described below through four exemplary embodiments.

[0065] In an exemplary embodiment, the malware detection method provided by the present disclosure may include the following steps A1 and A2 to obtain the first feature set according to the operation code set and the operation code.

[0066] Step A1, calculating the importance of each operation code in the operation code set based on the inverse document frequency of the word frequency to obtain a first feature vector.

[0067] In the disclosed embodiment, the term frequency inverse document frequency is the product of the term frequency and the inverse document frequency. The calculation formula of the term frequency inverse document frequency is shown in the following formula 1.

[0068]

[0069] Among them, G(s j ) is the importance of the jth opcode in the opcode sequence S in the opcode set P, count(s j ,s) indicates operation code s jThe frequency in the subsequence p of the opcode, |p| is the total number of opcodes in p, |P| is the total number of subsequences p of the opcode in the opcode set P, dp is the frequency of the subsequence p of the opcode, indicating the occurrence of opcode s j The number of subsequences p of all operation codes. It should be noted that p can be any subset (subsequence of operation codes) in the operation code set P.

[0070] The above formula 1 can be used to calculate the importance of each opcode in the opcode sequence S in the opcode set P, and the first eigenvector Vec s = {G(s 1 ),G(s 2 ),...,G(s m )}, where m is the total number of opcodes.

[0071] Step A2: Perform dimensionality reduction processing on the first eigenvector using PCA principal component analysis to obtain a first feature set.

[0072] PCA (Principal Component Analysis) is a dimensionality reduction method used for data dimensionality reduction, feature extraction and feature selection. PCA maps data from the original high-dimensional space to a new low-dimensional space so that each dimension (i.e., principal component) in the new space retains the variance (i.e., amount of information) of the original data as much as possible, thereby achieving the purpose of compressing data.

[0073] In the embodiment of the present disclosure, the first feature set is obtained by reducing the dimension of the first feature vector using PCA principal component analysis, but the dimension reduction method used in the embodiment of the present disclosure is not limited thereto. It is sufficient to select a suitable dimension reduction method to process the data according to the actual application scenario and specific application experience.

[0074] The present invention improves model efficiency and reduces overfitting risk by converting high-dimensional operation code vectors into low-dimensional space, reduces the dimension of feature space by principal component analysis, and retains the part with the largest amount of information in the operation code data to obtain the first feature set F 1 .

[0075] In another exemplary embodiment, before acquiring the static features and dynamic features of the software to be detected, the malware detection method provided by the present disclosure may further include the following step B1.

[0076] Step B1, extracting features of the software to be detected based on entropy calculation and code reuse patterns to obtain static features and dynamic features of the software to be detected.

[0077] In the disclosed embodiment, entropy calculation can better identify encryption and obfuscation in malware. Obfuscation is usually used to hide the actual intention of the code, which makes static analysis more difficult. When obtaining static features according to static analysis technology, static analysis can identify the hidden code parts by calculating the entropy value of the software to be detected. The calculation formula for entropy calculation is shown in Formula 2 below.

[0078]

[0079] Among them, E is information entropy, x is a random variable, p(x z ) represents the probability distribution of byte values ​​in the binary file of the software to be detected, o is the number of possible values ​​of the random variable, and z takes values ​​in [1,o].

[0080] In the disclosed embodiments, code reuse patterns are used to reveal similarities between malware families, which may share some of the same code snippets between multiple variants or use some known malicious code libraries. Therefore, code reuse patterns help identify similarities between different malware. By comparing code blocks or behavior patterns, it can help associate new malware samples with known malware families.

[0081] In the disclosed embodiment, the feature extraction process involves identifying the code reuse pattern through a cross-correlation function, which is defined as shown in Formula 3.

[0082] pattern(x)=∫c 1 (t)c 2 (t+x)dt (3)

[0083] Among them, pattern(x) represents the code reuse value (the degree of correlation), c 1 (t) and c 2 (t+x) represents the different parts of the code to be compared, x represents the offset between the two code snippets, and t represents the time variable used to represent the value of the code snippet at different positions.

[0084] The embodiment of the present disclosure extracts features of the software to be detected based on entropy calculation and code reuse mode to obtain static features and dynamic features of the software to be detected. The present disclosure can accurately extract static features and dynamic features from the software to be detected, thereby improving the accuracy of software detection.

[0085] It should be noted that the embodiments of the present disclosure may directly obtain static features and dynamic features through the software to be detected, or may obtain static features and dynamic features through step B1, and the embodiments of the present disclosure are not limited to this.

[0086] In yet another exemplary embodiment, in the malware detection method provided by the present disclosure, obtaining the second feature set according to static features and dynamic features may include the following steps C1 and C2.

[0087] Step C1, obtaining a combined feature according to the static feature and the dynamic feature.

[0088] In the embodiment of the present disclosure, the combined feature may be a feature obtained by fusing static features and dynamic features. For example, the static features and dynamic features are input into a neural network model for feature fusion to obtain the combined feature. The combined feature may also be a feature obtained by merging static features and dynamic features. For example, the static features and dynamic features are combined (or performed or operated) to obtain the combined feature.

[0089] Step C2, performing dimensionality reduction processing on the combined features to obtain a second feature set.

[0090] In the embodiments of the present disclosure, the embodiments of the present disclosure do not specifically limit which method is used for dimensionality reduction processing. For example, the present disclosure further refines the combined features through dimensionality reduction technology to obtain a structured and de-correlated effective feature set (second feature set), which combines static features and dynamic features. It should be noted that the dimensionality reduction technology can be a technique such as principal component analysis (PCA) or linear discriminant analysis (LDA), which can help remove redundant features and retain some of the features that are most useful for classification. This helps to reduce computational overhead and improve efficiency and accuracy.

[0091] Exemplarily, through the dimension reduction transformation T(X), the combined feature (X) is converted into a second feature set F 2 , the dimension reduction formula is shown in Formula 4 below.

[0092] F 2 =WX (4)

[0093] Among them, X is the centralized data matrix (combined features), and W is the eigenvector matrix of the covariance matrix of X. The redundant or non-informative features are removed through the dimensionality reduction process, thereby improving the efficiency and accuracy of the machine learning model.

[0094] The disclosed embodiment obtains a combined feature based on static features and dynamic features, and performs dimensionality reduction processing on the combined feature to obtain a second feature set. In other words, the dimensionality reduction technology can extract an effective and redundant second feature set after combining the static feature set and the dynamic feature set. The second feature set is more suitable for training the aggregation model and detecting malware.

[0095] In another exemplary embodiment, the aggregation model is an aggregation model of multiple random forests; wherein, the malware detection method provided in the present disclosure is based on the aggregation model, and obtaining the software detection result according to the first feature set and the second feature set may include the following steps D1 and D2.

[0096] Step D1, oversampling the feature space according to the first feature set and the second feature set to obtain balanced features.

[0097] In the disclosed embodiment, feature space oversampling is used to solve the problem of class imbalance in the first feature set and the second feature set, that is, malware samples are usually far less than benign software samples.

[0098] In the embodiment of the present disclosure, the first feature set and the second feature set may be subjected to feature space oversampling to obtain balanced features, or the first feature set and the second feature set may be subjected to a union operation to obtain balanced features. Exemplarily, the first feature set and the second feature set are subjected to a union operation to obtain a union F through the following formula 5, and then the union F is subjected to feature space oversampling to obtain balanced features.

[0099] F=F 1 ∪F 2 (5)

[0100] Among them, F is the union of the first feature set and the second feature set, F 1 is the first feature set, F 2 is the second feature set.

[0101] It should be noted that the problem of class imbalance often occurs for malware detection. When one class dominates another, it is challenging to train classifiers (such as aggregation models) equally for each class, which has a great impact on the evaluation criteria and classification accuracy. During the training process, the classifier may have enough knowledge of the major class (main class) and ignore the lower class (minority class), resulting in an increase in the accuracy of the major class and a decrease in the accuracy of the lower class. Therefore, the present invention performs class rebalancing, calculates the neighbor value of each minority class, randomly selects the feature vector of a nearest neighbor in a set of q neighbor values, and generates a new sample according to the following formula 6.

[0102]

[0103] Among them, F new is the generated new sample, F i is the feature vector of the minority class, F j is the feature vector of the nearest neighbor, and δ∈[0,1] is a random factor that controls the position of the newly generated sample. After category rebalancing, the number of malware features and benign software features is redistributed.

[0104] It should be noted that the balanced features in the embodiment of the present disclosure include the feature vectors of the main class in the union F, the feature vectors of the minority class in the union F, and the new samples.

[0105] The disclosed embodiment calculates neighboring samples of minority class samples in the first feature set and the second feature set, and generates new samples by interpolation. By balancing the number of samples, it avoids excessive bias towards majority class samples during the aggregation model training process, thereby further improving the accuracy of aggregation model recognition.

[0106] It should be noted that during the training process, the aggregation model is trained through the balanced features and validation set as mentioned above, so as to solve the problem of excessive bias towards majority class samples (main class samples) during the training process of the aggregation model.

[0107] Step D2, input the balanced features into the random forest aggregation model for consensus prediction to obtain the software detection result, wherein the consensus prediction is determined by a majority voting mechanism.

[0108] In the disclosed embodiments, the software detection results may include the type of malware (such as viruses, Trojans, worms, ransomware, spyware, adware, rootkits, etc.), and may also include one or more of the source of the malware, the level of hazard, the time of infection, the infected files, and the behavior of the malware.

[0109] In the disclosed embodiment, the aggregation model adopts the aggregation technology of decision trees, fully utilizing the advantages of multiple decision trees to improve the accuracy and robustness of software detection.

[0110] In the disclosed embodiment, the operation is performed by constructing a set of decision trees, and each tree is trained on a random subset of the data. During the tree construction process, the randomly selected features at each division introduce diversity between trees to prevent the aggregate model from over-relying on any single feature. The diversity of trees in each forest is further enhanced by bootstrap sampling, so that the aggregate model can capture a wide range of software malicious behaviors. The prediction is determined by a majority voting mechanism. Since the aggregation of multiple models provides a consensus prediction, it is more resilient to noise and outliers in the data and can reduce the overfitting risks associated with a single model. Optimization is performed by adjusting hyperparameters such as the number of trees, the depth of the tree, and the feature selection of each node. The resulting aggregate model improves detection capabilities by generalizing and adapting to new threats in different malware families, and the aggregate model ultimately outputs malicious or benign prediction results.

[0111] It should be noted that the diversity of the model is improved by building multiple decision trees. Each tree is trained on different data subsets and feature subsets, thereby reducing the dependence on a single feature or data subset.

[0112] It should be noted that bootstrap sampling is used to increase the diversity between trees and ensure that the model can capture different malicious behavior patterns.

[0113] It should be noted that the prediction results of all decision trees are integrated through voting to finally determine the prediction result. The majority voting mechanism can effectively reduce the impact of noise and outliers on the final prediction.

[0114] It should be noted that the hyperparameters such as the number of decision trees, depth, and feature selection of each node are tuned to ensure that the model can generalize across different malware families and adapt to new threats.

[0115] The disclosed embodiment analyzes composite features by balancing features (integrating static, dynamic, and opcode features), and provides consensus predictions through an aggregate model, which can determine malware that has never appeared before, improve the accuracy of software detection, and reduce false positives.

[0116] The present disclosure is described below through a specific embodiment.

[0117] In one embodiment, Figure 3 A flowchart of a malware detection method in another embodiment of the present disclosure is shown as follows: Figure 3 As shown, the malware detection method provided by the present disclosure may include the following S301 to S306.

[0118] S301, disassemble the software to be detected to obtain an operation code sequence. The operation code sequence includes multiple operation codes, and the operation code sequence is converted into an operation code set, which is an n-gram set.

[0119] S302, calculating the importance of each operation code in the operation code set based on the word frequency inverse document frequency to obtain a first feature vector, and performing dimensionality reduction processing on the first feature vector using PCA principal component analysis to obtain a first feature set.

[0120] S303: Obtain static features and dynamic features of the software to be detected.

[0121] S304, obtaining combined features according to the static features and the dynamic features, and performing dimensionality reduction processing on the combined features to obtain a second feature set.

[0122] S305 , performing feature space oversampling according to the first feature set and the second feature set to obtain balanced features.

[0123] S306, inputting the balanced features into the aggregation model of the random forest to perform consensus prediction and obtain software detection results, wherein the consensus prediction is determined by a majority voting mechanism.

[0124] In summary, the present disclosure can be used for malware detection, and can also realize fully automated detection without relying on human participation. In addition, the present disclosure integrates the composite features of static, dynamic, and compilation features for analysis, and provides consensus predictions by the aggregation model. The present disclosure can judge malware that has never appeared before, improve classification accuracy, and reduce false positives.

[0125] Based on the same inventive concept, the present disclosure also provides a malware detection device, as described in the following embodiments. Since the principle of solving the problem in the device embodiment is similar to that in the above method embodiment, the implementation of the device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.

[0126] Figure 4 A schematic diagram of a malware detection device according to an embodiment of the present disclosure is shown. Figure 4 As shown, the malware detection device includes: an acquisition module 41, a conversion module 42, a processing module 43 and a detection module 44. The acquisition module 41 can be used to acquire an operation code sequence of the software to be detected, and the operation code sequence includes multiple operation codes; the conversion module 42 can be used to convert the operation code sequence into an operation code set, and the operation code set is an n-gram set; the processing module 43 can be used to obtain a first feature set according to the operation code set and the operation code; the acquisition module 41 can also be used to acquire static features and dynamic features of the software to be detected; the processing module 42 can also be used to obtain a second feature set according to the static features and the dynamic features; the detection module 44 can be used to obtain a software detection result according to the first feature set and the second feature set based on an aggregation model.

[0127] In one embodiment, before obtaining the operation code sequence of the software to be detected, the acquisition module 41 can also be used to obtain the software to be detected; disassemble the software to be detected and extract the operation code sequence.

[0128] In one embodiment, the processing module 43 can also be used to calculate the importance of each operation code in the operation code set based on the word frequency inverse document frequency to obtain a first feature vector; use PCA principal component analysis to reduce the dimension of the first feature vector to obtain a first feature set.

[0129] In one embodiment, before obtaining the static features and dynamic features of the software to be detected, the processing module 43 can also be used to extract features of the software to be detected based on entropy calculation and code reuse mode to obtain the static features and dynamic features of the software to be detected.

[0130] In one embodiment, the processing module 43 may also be used to obtain combined features according to the static features and the dynamic features; and perform dimensionality reduction processing on the combined features to obtain a second feature set.

[0131] In one embodiment, the aggregation model is an aggregation model of multiple random forests; the detection module 44 can also be used to oversample the feature space according to the first feature set and the second feature set to obtain balanced features; the balanced features are input into the aggregation model of the random forest for consensus prediction to obtain software detection results; wherein the consensus prediction is determined by a majority voting mechanism.

[0132] The malware detection device disclosed in the present disclosure integrates the composite features of static, dynamic, and operation code features (assembly features) for analysis, and the consensus prediction provided by the aggregation model can determine malware that has never appeared, improve the accuracy of software detection (classification accuracy) and reduce false alarms.

[0133] Those skilled in the art will appreciate that various aspects of the present disclosure may be implemented as systems, methods or program products. Therefore, various aspects of the present disclosure may be specifically implemented in the following forms, namely: complete hardware implementation, complete software implementation (including firmware, microcode, etc.), or a combination of hardware and software, which may be collectively referred to herein as "circuits", "modules" or "systems".

[0134] Refer to the following Figure 5 The electronic device 500 according to this embodiment of the present disclosure is described. Figure 5 The electronic device 500 shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0135] like Figure 5 As shown, the electronic device 500 is in the form of a general computing device. The components of the electronic device 500 may include but are not limited to: at least one processing unit 510, at least one storage unit 520, and a bus 530 connecting different system components (including the storage unit 520 and the processing unit 510).

[0136] The storage unit stores a program code, and the program code can be executed by the processing unit 510, so that the processing unit 510 executes the steps described in the "Exemplary Method" section of the specification according to various exemplary embodiments of the present disclosure. For example, the processing unit 510 can execute the following steps of the above method embodiment: obtaining an operation code sequence of the software to be detected, the operation code sequence includes multiple operation codes; converting the operation code sequence into an operation code set, the operation code set is an n-gram set; obtaining a first feature set based on the operation code set and the operation code; obtaining static features and dynamic features of the software to be detected; obtaining a second feature set based on the static features and the dynamic features; obtaining a software detection result based on the first feature set and the second feature set based on the aggregation model.

[0137] The storage unit 520 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 5201 and / or a cache storage unit 5202 , and may further include a read-only storage unit (ROM) 5203 .

[0138] The storage unit 520 may also include a program / utility 5204 having a set (at least one) of program modules 5205, such program modules 5205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.

[0139] Bus 530 may represent one or more of several types of bus structures, including a memory unit bus or memory unit controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0140] The electronic device 500 may also communicate with one or more external devices 540 (e.g., keyboards, pointing devices, Bluetooth devices, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 500, and / or communicate with any device that enables the electronic device 500 to communicate with one or more other computing devices (e.g., routers, modems, etc.). Such communication may be performed via an input / output (I / O) interface 550. Furthermore, the electronic device 500 may also communicate with one or more networks (e.g., local area networks (LANs), wide area networks (WANs), and / or public networks, such as the Internet) via a network adapter 560. As shown, the network adapter 560 communicates with other modules of the electronic device 500 via a bus 530. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 500, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0141] Through the description of the above implementation, it is easy for those skilled in the art to understand that the example implementation described here can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the implementation of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the implementation of the present disclosure.

[0142] In the disclosed exemplary embodiments, a computer-readable storage medium is also provided, which may be a readable signal medium or a readable storage medium. Figure 6 A schematic diagram of a computer-readable storage medium in an embodiment of the present disclosure is shown. Figure 6 As shown, the computer-readable storage medium 600 stores a program product capable of implementing the above method of the present disclosure.

[0143] In some possible implementations, various aspects of the present disclosure may also be implemented in the form of a program product, which includes program code. When the program product is run on a terminal device, the program code is used to enable the terminal device to execute the steps of various exemplary implementations of the present disclosure described in the above "Specific Implementation Methods" section of this specification.

[0144] More specific examples of computer-readable storage media in the present disclosure may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0145] In the present disclosure, a computer readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, wherein a readable program code is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A readable signal medium may also be any readable medium other than a readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0146] Alternatively, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the foregoing.

[0147] In a specific implementation, the program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, C++, etc., and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., using an Internet service provider to connect through the Internet).

[0148] The embodiments of the present disclosure provide a computer program product or a computer program, which includes a computer instruction, and the computer instruction is stored in a computer-readable storage medium. The processor of the computer device reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes the malware detection method provided in various optional ways in any embodiment of the present disclosure.

[0149] It should be noted that, although several modules or units of the device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. On the contrary, the features and functions of one module or unit described above can be further divided into multiple modules or units to be embodied.

[0150] In addition, although the steps of the method in the present disclosure are described in a specific order in the drawings, this does not require or imply that the steps must be performed in this specific order, or that all the steps shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps, etc.

[0151] Through the description of the above implementation, it is easy for those skilled in the art to understand that the example implementation described here can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the implementation of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the implementation of the present disclosure.

[0152] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the specification and practicing the invention disclosed herein. The present disclosure is intended to cover any variations, uses or adaptations of the present disclosure, which follow the general principles of the present disclosure and include common knowledge or customary technical means in the art that are not disclosed in the present disclosure. The description and examples are to be regarded as exemplary only, and the true scope of the present disclosure is indicated by the appended claims.

Claims

1. A malware detection method, characterized in that: include: Acquire an operation code sequence of the software to be detected, wherein the operation code sequence includes a plurality of operation codes; Converting the operation code sequence into an operation code set, wherein the operation code set is an n-gram set; Obtaining a first feature set according to the operation code set and the operation code; Obtaining static features and dynamic features of the software to be detected; Obtaining a second feature set according to the static features and the dynamic features; Based on the aggregation model, a software detection result is obtained according to the first feature set and the second feature set.

2. The method according to claim 1, characterized in that: Before obtaining the output operation code sequence of the software to be detected, the method further includes: Get the software to be tested; The software to be detected is disassembled to extract the operation code sequence.

3. The method according to claim 1, characterized in that According to the operation code set and the operation code, a first feature set is obtained, including: Calculate the importance of each of the operation codes in the operation code set based on the word frequency inverse document frequency to obtain a first feature vector; The first feature vector is subjected to dimensionality reduction processing by using PCA principal component analysis to obtain the first feature set.

4. The method according to claim 1, characterized in that: Before acquiring the static features and dynamic features of the software to be detected, the method further includes: Based on entropy calculation and code reuse mode, feature extraction is performed on the software to be detected to obtain static features and dynamic features of the software to be detected.

5. The method according to claim 1, characterized in that: According to the static features and the dynamic features, a second feature set is obtained, including: Obtaining a combined feature according to the static feature and the dynamic feature; Perform dimensionality reduction processing on the combined features to obtain the second feature set.

6. The method according to claim 1, characterized in that The aggregation model is an aggregation model of multiple random forests; Wherein, based on the aggregation model, according to the first feature set and the second feature set, a software detection result is obtained, including: Performing feature space oversampling according to the first feature set and the second feature set to obtain balanced features; Inputting the balance feature into the aggregation model of the random forest to perform consensus prediction and obtain software detection results; Wherein, the consensus prediction is determined by a majority voting mechanism.

7. A malware detection device, characterized in that: include: An acquisition module, used for acquiring an operation code sequence of the software to be detected, wherein the operation code sequence includes a plurality of operation codes; A conversion module, used for converting the operation code sequence into an operation code set, wherein the operation code set is an n-gram set; A processing module, configured to obtain a first feature set according to the operation code set and the operation code; The acquisition module is further used to acquire the static features and dynamic features of the software to be detected; The processing module is further used to obtain a second feature set according to the static feature and the dynamic feature; The detection module is used to obtain a software detection result based on the aggregation model according to the first feature set and the second feature set.

8. An electronic device, characterized in that: include: processor; as well as A memory, configured to store executable instructions of the processor; Wherein, the processor is configured to perform the malware detection method described in any one of claims 1-6 by executing the executable instructions.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the malware detection method according to any one of claims 1 to 6 is implemented.

10. A computer program product, comprising computer instructions, wherein the computer instructions are stored in a computer-readable storage medium, and when the computer instructions are executed by a processor, they implement the operation instructions of the malware detection method according to any one of claims 1 to 6.