Malicious software detection method and device

By decompiling the target software and identifying sensitive interfaces, combined with embedded representation of encryption processing, the problem of low security in the existing technology of malware detection data is solved, and efficient and secure malware detection is achieved.

CN119939584AActive Publication Date: 2025-05-06西交网络空间安全研究院 +3
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510049834.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-13
Publication Date
2025-05-06
Estimated Expiration
2045-01-13

AI Technical Summary

Technical Problem

Existing malware detection methods pose a risk of user privacy data and trained network model data leakage, and the data security is not high.

Method used

By decompiling the software files of the target software, the sensitive application programming interface is determined and the corresponding adjacency matrix is ​​generated. Combining preset variables and encryption keys, embedding representations are calculated and encrypted to avoid data leakage.

Benefits of technology

It realizes malicious detection of target software while maintaining server and client data security, avoiding data leakage and improving the security of user privacy data and network model data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939584A_ABST
    Figure CN119939584A_ABST
Patent Text Reader

Abstract

The invention provides a malicious software detection method and device, and the method comprises the steps: obtaining application programming interfaces of target software at a client through a decompilation method, and obtaining a first adjacent matrix between the application programming interfaces through the relative positions between the application programming interfaces; therefore, a third prediction score corresponding to the first adjacent matrix can be obtained through a homomorphic encryption method of additive secret sharing between the client and the server, and finally malicious judgment can be performed on the target software through the third prediction score and the preset variable at the client to obtain a first judgment result. According to the embodiment of the invention, malicious detection can be carried out on the target software while the target dynamic weight matrix of the server and the data security of the target software of the client are kept, and the first judgment result of the target software is obtained, so that data leakage of the client and the server is avoided; and the data security of the user privacy data of the client and the target dynamic weight matrix data of the server is improved to a certain extent.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data processing technology, and in particular to a malware detection method and device. Background Art

[0002] With the rapid development of mobile Internet, the use of mobile smart terminals has become quite popular. At the same time, the popularity of smart terminals is also accompanied by a surge in related malware. These malware cover a variety of types, such as fee consumption, privacy theft, and malicious control, posing a serious threat to user privacy and property. Therefore, efficient and accurate smart terminal malware detection and identification is particularly important.

[0003] In the related art, a deep learning method can be used to train a deep learning network model using string features in sample software, and the trained deep learning network model can be used to identify malware.

[0004] However, in the above method, there is a risk of leakage of the user's privacy data and the data of the trained network model, and the security of the user's privacy data and the data of the trained network model is not high. Summary of the invention

[0005] In view of the above problems, embodiments of the present application provide a malware detection method, device, electronic device, and readable storage medium to overcome the above problems or at least partially solve the above problems.

[0006] In a first aspect, an embodiment of the present application provides a malware detection method, which is applied to a client, and the method includes: Decompiling the software file of the target software to obtain a first application programming interface of the target software; wherein the first application programming interface includes at least one sub-function program segment; Determining a first sensitive application programming interface from the first application programming interface based on a character string corresponding to a preset sensitive variable; wherein the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable, and a user asset data variable; Based on the relative position of each of the first sensitive application programming interfaces in the main function program segment of the target software, generating a first adjacency matrix of the first sensitive application programming interfaces; Based on the preset variables and the first shared value of the first multiplication triplet stored in the client, a first variable vector is calculated; based on the preset variables and the second shared value of the first multiplication triplet, a second variable vector is calculated; based on the first encrypted dynamic weight matrix sent by the server, the preset variables and the first adjacency matrix, a first embedding representation is calculated; based on the second encrypted dynamic weight matrix sent by the server, the preset variables and the first adjacency matrix, a second embedding representation is calculated; wherein the first encrypted dynamic weight matrix and the second encrypted dynamic weight matrix are generated based on the target dynamic weight matrix and the encryption key stored in the server; Sending the first variable vector, the second variable vector, the first embedded representation, and the second embedded representation to the server, so that the server decrypts the first embedded representation based on the encryption key to obtain a third embedded representation, calculates a fourth embedded representation based on the third embedded representation and a third shared value in a second multiplication triplet stored by the server, decrypts the second embedded representation based on the encryption key to obtain a fifth embedded representation, calculates a sixth embedded representation based on the fifth embedded representation and a fourth shared value in the second multiplication triplet, calculates a seventh embedded representation based on the first variable vector and the fourth embedded representation, calculates an eighth embedded representation based on the second variable vector and the sixth embedded representation, and calculates a ninth embedded representation based on the seventh embedded representation, the eighth embedded representation, and the second multiplication triplet; Calculate a tenth embedding representation based on the first variable vector and the fourth embedding representation sent by the server, calculate an eleventh embedding representation based on the second variable vector and the sixth embedding representation sent by the server, calculate a twelfth embedding representation based on the tenth embedding representation, the eleventh embedding representation and the first multiplication triplet, and calculate an encrypted prediction score based on the preset variables, the encrypted dynamic weight matrix and the twelfth embedding representation; Sending the encrypted prediction score to the server, so that the server decrypts the encrypted prediction score based on the encryption key to obtain a first prediction score, calculating a second prediction score based on the target dynamic weight matrix and the ninth embedding representation, and summing the first prediction score and the second prediction score to obtain a third prediction score; Based on the third prediction score and the preset variable sent by the server, the target software is judged to be malicious to obtain a first judgment result.

[0007] Optionally, the performing malicious determination on the target software based on the third prediction score and the preset variable sent by the server to obtain a first determination result includes: Summing the preset variable and the third prediction score sent by the server to obtain a fourth prediction score; When the fourth prediction score is greater than or equal to the first threshold, determining that the first determination result of the target software is malware; When the fourth prediction score is less than or equal to the first threshold, the first determination result is determined to be normal software.

[0008] In a second aspect, an embodiment of the present application provides a malware detection method, which is applied to a server, and the method includes: Based on the target dynamic weight matrix and the encryption key, a first encrypted dynamic weight matrix and a second encrypted dynamic weight matrix are generated respectively, and the first encrypted dynamic weight matrix and the second encrypted dynamic weight matrix are sent to the client, so that the client calculates a first embedded representation based on the first encrypted dynamic weight matrix, preset variables and the first adjacency matrix, and calculates a second embedded representation based on the second encrypted dynamic weight matrix, the preset variables and the first adjacency matrix; wherein the first adjacency matrix is ​​generated based on the relative position of each first sensitive application programming interface in the main function program segment of the target software; the first sensitive application programming interface is determined from the first application programming interface of the target software based on the character string corresponding to the preset sensitive variable; the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable and a user asset data variable; the first application programming interface is obtained by decompiling the software file of the sample software; the first application programming interface includes at least one sub-function program segment; Based on the encryption key, the first embedded representation sent by the client is decrypted to obtain a third embedded representation, based on the third embedded representation and the third shared value in the second multiplication triplet stored by the server, a fourth embedded representation is calculated, based on the encryption key stored by the server, the second embedded representation sent by the client is decrypted to obtain a fifth embedded representation, based on the fifth embedded representation and the fourth shared value in the second multiplication triplet, a sixth embedded representation is calculated, based on the first variable vector sent by the client and the fourth embedded representation, a seventh embedded representation is calculated, based on the second variable vector sent by the client and the sixth embedded representation, an eighth embedded representation is calculated, Based on the seventh embedding representation, the eighth embedding representation and the second multiplication triplet, a ninth embedding representation is calculated; wherein the first embedding representation is calculated in the client based on the first encrypted dynamic weight matrix sent by the server, the preset variables and the first adjacency matrix; the second embedding representation is calculated in the client based on the second encrypted dynamic weight matrix sent by the server, the preset variables and the first adjacency matrix; the first variable vector is calculated based on the preset variables and the first shared value of the first multiplication triplet stored in the client; the second variable vector is calculated based on the preset variables and the second shared value of the first multiplication triplet; Sending the fourth embedding representation and the sixth embedding representation to the client, so that the client calculates a tenth embedding representation based on the first variable vector and the fourth embedding representation, calculates an eleventh embedding representation based on the second variable vector and the sixth embedding representation, calculates a twelfth embedding representation based on the tenth embedding representation, the eleventh embedding representation and the first multiplication triplet, and calculates an encrypted prediction score based on the preset variables, the encrypted dynamic weight matrix and the twelfth embedding representation; Based on the encryption key, decrypt the encrypted prediction score sent by the client to obtain a first prediction score, calculate a second prediction score based on the target dynamic weight matrix and the ninth embedding representation, and sum the first prediction score and the second prediction score to obtain a third prediction score; The third prediction score is sent to the client, so that the client performs a malicious determination on the target software based on the third prediction score and the preset variable to obtain a first determination result.

[0009] Optionally, sending the third prediction score to the client so that the client makes a malicious determination on the target software based on the third prediction score and the preset variable to obtain a first determination result includes: The third prediction score is sent to the client so that the client sums the preset variable and the third prediction score sent by the server to obtain a fourth prediction score, and when the fourth prediction score is greater than or equal to the first threshold, the first determination result of the target software is determined to be malware, and when the fourth prediction score is less than or equal to the first threshold, the first determination result is determined to be normal software.

[0010] Optionally, the method further comprises: Decompiling the software file of the sample software to obtain a first sample application programming interface of the sample software; wherein the first sample application programming interface includes at least one sub-function program segment; Determine a first sample sensitive application programming interface from the first sample application programming interface based on a character string corresponding to a preset sensitive variable; wherein the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable, and a user asset data variable; Based on the relative position of each of the first sample sensitive application programming interfaces in the main function program segment of the sample software, generating a first sample adjacency matrix of the first sample sensitive application programming interface; Inputting the first sample adjacency matrix into a first graph neural network model to obtain a sample prediction score of the sample software output by the first graph neural network model; Determining a cross entropy loss value of the first graph neural network model based on the sample prediction score and the classification label of the sample software; Based on the cross entropy loss value, adjust the model parameters of the first graph neural network model and the first weight values ​​of each network layer of the first graph neural network model to obtain a target graph neural network model; Obtain the target weight values ​​corresponding to each network layer in the target graph neural network model to obtain the target dynamic weight matrix.

[0011] Optionally, the first graph neural network model includes a multiple relationship aggregation layer, a multi-layer heterogeneous graph convolution layer and a prediction layer, and the first sample adjacency matrix and the first sample dynamic weight matrix are input into the first graph neural network model to obtain the sample prediction score of the sample software output by the first graph neural network model, including: Inputting the first sample adjacency matrix into the multiple relationship aggregation layer to perform weighted aggregation on the first sample adjacency matrix to obtain a second sample adjacency matrix output by the multi-layer relationship aggregation layer; Inputting the second sample adjacency matrix into the multi-layer heterogeneous graph convolution layer to obtain a final embedded representation of the sample output by the multi-layer heterogeneous graph convolution layer; The sample is finally embedded into the representation and input into the prediction layer to obtain the sample prediction score of the sample software output by the prediction layer.

[0012] In a third aspect, an embodiment of the present application provides a malware detection device, which is applied to a client, and the method includes: A decompiling module, used for decompiling a software file of the target software to obtain a first application programming interface of the target software; wherein the first application programming interface includes at least one sub-function program segment; A determination module, configured to determine a first sensitive application programming interface from the first application programming interface based on a character string corresponding to a preset sensitive variable; wherein the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable, and a user asset data variable; A generating module, configured to generate a first adjacency matrix of the first sensitive application programming interfaces based on the relative positions of the first sensitive application programming interfaces in the main function program segment of the target software; A first calculation module is used to calculate a first variable vector based on a preset variable and a first shared value of a first multiplication triplet stored in the client, calculate a second variable vector based on the preset variable and a second shared value of the first multiplication triplet, calculate a first embedded representation based on a first encrypted dynamic weight matrix sent by a server, the preset variable and the first adjacency matrix, and calculate a second embedded representation based on a second encrypted dynamic weight matrix sent by the server, the preset variable and the first adjacency matrix; wherein the first encrypted dynamic weight matrix and the second encrypted dynamic weight matrix are generated based on a target dynamic weight matrix and an encryption key stored in the server; a first sending module, configured to send the first variable vector, the second variable vector, the first embedded representation, and the second embedded representation to the server, so that the server decrypts the first embedded representation based on the encryption key to obtain a third embedded representation, calculates a fourth embedded representation based on the third embedded representation and a third shared value in a second multiplication triplet stored by the server, decrypts the second embedded representation based on the encryption key to obtain a fifth embedded representation, calculates a sixth embedded representation based on the fifth embedded representation and a fourth shared value in the second multiplication triplet, calculates a seventh embedded representation based on the first variable vector and the fourth embedded representation, calculates an eighth embedded representation based on the second variable vector and the sixth embedded representation, and calculates a ninth embedded representation based on the seventh embedded representation, the eighth embedded representation, and the second multiplication triplet; a second calculation module, configured to calculate a tenth embedding representation based on the first variable vector and the fourth embedding representation sent by the server, calculate an eleventh embedding representation based on the second variable vector and the sixth embedding representation sent by the server, calculate a twelfth embedding representation based on the tenth embedding representation, the eleventh embedding representation and the first multiplication triplet, and calculate an encrypted prediction score based on the preset variables, the encrypted dynamic weight matrix and the twelfth embedding representation; a second sending module, configured to send the encrypted prediction score to the server, so that the server decrypts the encrypted prediction score based on the encryption key to obtain a first prediction score, calculates a second prediction score based on the target dynamic weight matrix and the ninth embedding representation, and sums the first prediction score and the second prediction score to obtain a third prediction score; The malicious determination module is used to perform malicious determination on the target software based on the third prediction score sent by the server and the preset variable to obtain a first determination result.

[0013] In a fourth aspect, an embodiment of the present application provides a malware detection device, which is applied to a server, and the device includes: A first generation module is used to generate a first encrypted dynamic weight matrix and a second encrypted dynamic weight matrix respectively based on a target dynamic weight matrix and an encryption key, and send the first encrypted dynamic weight matrix and the second encrypted dynamic weight matrix to a client, so that the client calculates a first embedded representation based on the first encrypted dynamic weight matrix, preset variables and a first adjacency matrix, and calculates a second embedded representation based on the second encrypted dynamic weight matrix, the preset variables and the first adjacency matrix; wherein the first adjacency matrix is ​​generated based on the relative position of each first sensitive application programming interface in the main function program segment of the target software; the first sensitive application programming interface is determined from the first application programming interface of the target software based on the character string corresponding to the preset sensitive variable; the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable and a user asset data variable; the first application programming interface is obtained by decompiling the software file of the sample software; the first application programming interface includes at least one sub-function program segment; a first decryption calculation module, configured to decrypt the first embedded representation sent by the client based on the encryption key to obtain a third embedded representation, calculate a fourth embedded representation based on the third embedded representation and a third shared value in the second multiplication triplet stored by the server, decrypt the second embedded representation sent by the client based on the encryption key stored by the server to obtain a fifth embedded representation, calculate a sixth embedded representation based on the fifth embedded representation and the fourth shared value in the second multiplication triplet, calculate a seventh embedded representation based on the first variable vector sent by the client and the fourth embedded representation, and calculate a seventh embedded representation based on the second variable vector sent by the client and the sixth embedded representation. Eight embedding representations, calculating a ninth embedding representation based on the seventh embedding representation, the eighth embedding representation and the second multiplication triplet; wherein the first embedding representation is calculated in the client based on the first encrypted dynamic weight matrix sent by the server, the preset variables and the first adjacency matrix; the second embedding representation is calculated in the client based on the second encrypted dynamic weight matrix sent by the server, the preset variables and the first adjacency matrix; the first variable vector is calculated based on the preset variables and the first shared value of the first multiplication triplet stored in the client; the second variable vector is calculated based on the preset variables and the second shared value of the first multiplication triplet; a first sending module, configured to send the fourth embedding representation and the sixth embedding representation to the client, so that the client calculates a tenth embedding representation based on the first variable vector and the fourth embedding representation, calculates an eleventh embedding representation based on the second variable vector and the sixth embedding representation, calculates a twelfth embedding representation based on the tenth embedding representation, the eleventh embedding representation and the first multiplication triplet, and calculates an encrypted prediction score based on the preset variables, the encrypted dynamic weight matrix and the twelfth embedding representation; a second decryption calculation module, configured to decrypt the encrypted prediction score sent by the client based on the encryption key to obtain a first prediction score, calculate a second prediction score based on the target dynamic weight matrix and the ninth embedding representation, and sum the first prediction score and the second prediction score to obtain a third prediction score; The second sending module is used to send the third prediction score to the client, so that the client makes a malicious determination on the target software based on the third prediction score and the preset variable to obtain a first determination result.

[0014] In a fifth aspect, an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the malware detection method as described in any one of the above.

[0015] In a sixth aspect, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored, and when the program or instruction is executed by a processor, the malware detection method as described in any one of the above is implemented.

[0016] The specific beneficial effects are: The embodiment of the present application obtains a first application programming interface of the target software by decompiling the software file of the target software; wherein the first application programming interface includes at least one sub-function program segment, and a first sensitive application programming interface is determined from the first application programming interface based on a character string corresponding to a preset sensitive variable; wherein the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable, or a user asset data variable, and a first adjacency matrix of the first sensitive application programming interface is generated based on the relative position of each first sensitive application programming interface in the main function program segment of the target software, a first variable vector is calculated based on the preset variable and a first shared value of a first multiplication triple stored by the client, a second variable vector is calculated based on the preset variable and a second shared value of the first multiplication triple, a first embedded representation is calculated based on a first encrypted dynamic weight matrix sent by the server, the preset variable, and the first adjacency matrix, and a second embedded representation is calculated based on a second encrypted dynamic weight matrix sent by the server, the preset variable, and the first adjacency matrix;The encrypted dynamic weight matrix is ​​generated based on the target dynamic weight matrix and the encryption key stored in the server, and the first variable vector, the second variable vector, the first embedded representation and the second embedded representation are sent to the server, so that the server decrypts the first embedded representation based on the encryption key to obtain a third embedded representation, and calculates the fourth embedded representation based on the third embedded representation and the third shared value in the second multiplication triplet stored in the server, and decrypts the second embedded representation based on the encryption key to obtain a fifth embedded representation, and calculates the sixth embedded representation based on the fifth embedded representation and the fourth shared value in the second multiplication triplet, and calculates the sixth embedded representation based on the first variable vector and the fourth embedding representation, calculate the seventh embedding representation, calculate the eighth embedding representation based on the second variable vector and the sixth embedding representation, calculate the ninth embedding representation based on the seventh embedding representation, the eighth embedding representation and the second multiplication triplet, calculate the tenth embedding representation based on the first variable vector and the fourth embedding representation sent by the server, calculate the eleventh embedding representation based on the second variable vector and the sixth embedding representation sent by the server, calculate the twelfth embedding representation based on the tenth embedding representation, the eleventh embedding representation and the first multiplication triplet, calculate the encrypted prediction score based on the preset variables, the encrypted dynamic weight matrix and the twelfth embedding representation, and send it to the server Send the encrypted prediction score so that the server can decrypt the encrypted prediction score based on the encryption key to obtain the first prediction score, calculate the second prediction score based on the target dynamic weight matrix and the ninth embedding representation, and sum the first prediction score and the second prediction score to obtain the third prediction score, and make a malicious judgment on the target software based on the third prediction score and the preset variable sent by the server to obtain the first judgment result, and the application programming interface of the target software can be obtained by the decompilation method on the client, and the first adjacency matrix between each application programming interface can be obtained by the relative position between each application programming interface, so that the third prediction score corresponding to the first adjacency matrix can be obtained by the homomorphic encryption method of additive secret sharing between the client and the server, and finally, the target software can be maliciously judged on the client through the third prediction score and the preset variable to obtain the first judgment result, and the target software can be maliciously detected while maintaining the data security of the target dynamic weight matrix of the server and the target software of the client to obtain the first judgment result of the target software, thereby avoiding the data leakage of the client and the server, and improving the data security of the user privacy data of the client and the network model data and the target dynamic weight matrix data of the server to a certain extent. ; BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the description of the embodiments of the present application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0018] Figure 1 It is a flowchart of a malware detection method provided by an embodiment of the present application; Figure 2 is a flowchart of another malware detection method provided in an embodiment of the present application; Figure 3 It is a flow chart of a method for obtaining a target dynamic weight matrix provided in an embodiment of the present application; Figure 4 It is a flowchart of a specific implementation method of a malware detection method provided in an embodiment of the present application; Figure 5 is a logic block diagram of a malware detection device provided in an embodiment of the present application; Figure 6 is a logic block diagram of another malware detection device provided in an embodiment of the present application; Figure 7 It is a schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0019] The exemplary embodiments of the present application will be described in more detail below in conjunction with the accompanying drawings in the embodiments of the present application. Although the exemplary embodiments of the present application are shown in the accompanying drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided in order to enable a more thorough understanding of the present application and to enable the scope of the present application to be fully communicated to those skilled in the art.

[0020] Reference Figure 1 , Figure 1 A flowchart of a malware detection method provided in an embodiment of the present application is applied to a client, and the method includes: Step 101, decompile the software file of the target software to obtain the first application programming interface of the target software; wherein the first application programming interface includes at least one sub-function program segment.

[0021] In the embodiments of the present application, decompilation is also called computer software reverse engineering (Reverse engineering), which refers to the work of "reverse analysis and research" on the target program (such as an executable program) of other people's software to derive the design elements such as ideas, principles, structures, algorithms, processing procedures, and operation methods used by other people's software products. In certain specific cases, the source code may be derived. The target software can be an executable program formed using a certain programming language, and the software file of the target software can be an executable file of the target software. The process of decompiling the software file is the process from the executable file to the source code. For example, if the target software is written in Easy Language, the target software can be decompiled using the Easy Format Executable File Analyzer (program name is E-Code Explorer.exe) to obtain the source code; if the target software is an Android application installation package (usually in APK format), the SMALI / BAKSMAL editing tool or the APKTOOL tool and other commonly used decompilation tools can be used to decompile the Android application installation package. After decompilation, all function program segments of the target software can be obtained, which are embodied in the form of an application programming interface (Application Programming Interface, API). Generally, the main function program segment cannot form an application programming interface, but plays the role of an application programming interface scheduling. Therefore, in the first application programming interface of the target software, at least one sub-function program segment may be included. Among them, the sub-functions may be nested with each other.

[0022] Step 102, based on the character string corresponding to the preset sensitive variable, determine the first sensitive application programming interface from the first application programming interface; wherein the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable and a user asset data variable.

[0023] In the embodiment of the present application, in the application programming interface of the target software, some application programming interfaces may have functions such as accessing user personal information, using sensitive data input devices, or consuming user property, and these application programming interfaces may be defined as sensitive application programming interfaces. On this basis, at least one of the user personal information variable, the sensitive data input device, and the user asset data variable may be set as a preset sensitive variable, so that the first application programming interface may be string identified, and when there is a string corresponding to the preset sensitive variable in the program segment of the first application programming interface, the first application programming interface may be determined as a first sensitive application programming interface.

[0024] Step 103: Generate a first adjacency matrix of the first sensitive application programming interfaces based on the relative positions of the first sensitive application programming interfaces in the main function program segment of the target software.

[0025] In an embodiment of the present application, each first sensitive application programming interface can be embodied in the main function program segment of the target software in the form of a function call, and is classified and defined according to the common function call behavior of malware. The relative position of each first sensitive application programming interface in the main function program segment of the target software may refer to the relative position of the called code of each first sensitive application programming interface in the main function program segment, and the relative position may include the following: if the first sensitive application programming interface in the same code block is directly adjacent to another sensitive application programming interface, then the relative position between the above two first sensitive application programming interfaces can be defined as directly adjacent, represented by R0, where a code block may refer to a set of codes contained in a complete symbol "{}"; if the first sensitive application programming interface in the same code block is adjacent to another sensitive application programming interface through code that does not involve function calls, then the relative position between the above two first sensitive application programming interfaces can be defined as first interval code adjacent, represented by R1; if the two first sensitive application programming interfaces are adjacent to each other through code that does not involve function calls, then the relative position between the above two first sensitive application programming interfaces can be defined as first interval code adjacent, represented by R1; If the interface appears in two adjacent code blocks and there is only code that does not involve function calls in between, the relative position between the two first sensitive application programming interfaces can be defined as second interval code adjacency, represented by R2; if the two first sensitive application programming interfaces are adjacent through a user-defined function of a non-application programming interface type and there is only code that does not involve function calls in between, the relative position between the two first sensitive application programming interfaces can be defined as third interval code adjacency, represented by R3; if the two first sensitive application programming interfaces belong to the same class (which can be determined by the call name of the interface call, if the first segment of the name in the call name is the same, it can be considered that the two first sensitive application programming interfaces belong to the same class), the relative position between the two first sensitive application programming interfaces can be defined as same-type adjacency, represented by R4; if the relative position between the two first sensitive application programming interfaces does not meet any of the above conditions, the relative position between the two first sensitive application programming interfaces can be defined as no relative position, represented by 0. Thus, according to the relative positions of the first sensitive application programming interfaces in the main function program segment of the target software, the generated first adjacency matrix of the first sensitive application programming interfaces may contain six elements, namely "0, R0, R1, R2, R3, R4". The first adjacency matrix may represent the relative positional relationship between the first sensitive application programming interfaces.

[0026] Step 104, based on the preset variables and the first shared value of the first multiplication triplet stored in the client, calculate the first variable vector, based on the preset variables and the second shared value of the first multiplication triplet, calculate the second variable vector, based on the first encrypted dynamic weight matrix sent by the server, the preset variables and the first adjacency matrix, calculate the first embedded representation, based on the second encrypted dynamic weight matrix sent by the server, the preset variables and the first adjacency matrix, calculate the second embedded representation; wherein the first encrypted dynamic weight matrix and the second encrypted dynamic weight matrix are generated based on the target dynamic weight matrix and the encryption key stored in the server.

[0027] In an embodiment of the present application, the preset variable is private data held by the client, which can be generated in the client by a random algorithm. Multiplication triples are a form of data used in two-party secure computing, usually generated by each party alone. For example, the first multiplication triple in the client can be generated by the client, and in the first multiplication triple, three sharing values ​​are included, wherein the product of the first sharing value and the second sharing value is equal to the product sharing value. In this way, in the client, the following calculations can be carried out: according to the preset variables and the first sharing value of the first multiplication triple, the first variable vector is calculated; according to the preset variables and the second sharing value of the first multiplication triple, the second variable vector is calculated; according to the preset variables and the first adjacency matrix, the second adjacency matrix is ​​calculated. In addition, the client can also receive the first encrypted dynamic weight matrix and the second encrypted dynamic weight matrix sent by the server, so that the first embedded representation can be calculated according to the first encrypted dynamic weight matrix, combined with the preset variables and the first adjacency matrix, and the second embedded representation can be calculated according to the second encrypted dynamic weight matrix, combined with the preset variables and the first adjacency matrix. Among them, the encrypted dynamic weight matrix can be generated by the server according to the target dynamic weight matrix and encryption key stored in the server. The first encrypted dynamic weight matrix can be obtained by an encryption algorithm based on the first column elements of the target dynamic weight matrix, and the second encrypted dynamic weight matrix can be obtained by an encryption algorithm based on all elements of the target dynamic weight matrix. The encryption key referred to here can be any homomorphic encryption key that supports additive secret sharing, and another encryption key that matches the encryption key is also held in the client, so that the client can perform a certain degree of calculation on the encrypted ciphertext sent by the server. The target dynamic weight matrix stored in the server can be obtained by training the first graph neural network model by the server, and the dimension of the target dynamic weight matrix can be determined based on the number of training samples and the number of network layers of the first graph neural network model.

[0028] For example, let the first multiplication triple be ( ), the preset variable is , the first encrypted dynamic weight matrix is , the second encrypted dynamic weight matrix is , , then the first variable vector can be expressed as , the second variable vector can be expressed as , the first embedding representation can be , the second embedding representation can be , where M represents the number of columns of the target dynamic weight matrix, = Among them, the first share value is , the second share value is .

[0029] Step 105: Send the first variable vector, the second variable vector, the first embedded representation, and the second embedded representation to the server, so that the server calculates a fourth embedded representation based on the first embedded representation and a third shared value in a second multiplication triplet stored by the server, decrypts the second embedded representation based on the encryption key to obtain a fifth embedded representation, calculates a sixth embedded representation based on the fifth embedded representation and the fourth shared value in the second multiplication triplet, calculates a seventh embedded representation based on the first variable vector and the fourth embedded representation, calculates an eighth embedded representation based on the second variable vector and the sixth embedded representation, and calculates a ninth embedded representation based on the seventh embedded representation, the eighth embedded representation, and the second multiplication triplet.

[0030] In an embodiment of the present application, the client may send a first variable vector, a second variable vector, a first embedded representation, and a second embedded representation to the server, so that the server may calculate a fourth embedded representation based on the first embedded representation and a third shared value in a second multiplication triplet stored by the server, decrypt the second embedded representation based on an encryption key to obtain a fifth embedded representation, calculate a sixth embedded representation based on the fifth embedded representation and the fourth shared value in the second multiplication triplet, calculate a seventh embedded representation based on the first variable vector and the fourth embedded representation, calculate an eighth embedded representation based on the second variable vector and the sixth embedded representation, and calculate a ninth embedded representation based on the seventh embedded representation, the eighth embedded representation, and the second multiplication triplet.

[0031] Continuing with the above example, if the second multiplication triplet held by the server is ( ), Represents the first embedding representation The third embedding representation obtained after decryption is, Represents the second embedding representation The fifth embedded representation obtained after decryption, then, the fourth embedded representation can be expressed as , the sixth embedding representation can be expressed as , the seventh embedding representation can be , the eighth embedding representation can be expressed as , the ninth embedding representation can be expressed as ,in, , , the third sharing value is , the fourth share value is .

[0032] Step 106: Calculate a tenth embedding representation based on the first variable vector and the fourth embedding representation sent by the server; calculate an eleventh embedding representation based on the second variable vector and the sixth embedding representation sent by the server; calculate a twelfth embedding representation based on the tenth embedding representation, the eleventh embedding representation and the first multiplication triplet; and calculate an encrypted prediction score based on the preset variables, the encrypted dynamic weight matrix and the twelfth embedding representation.

[0033] In an embodiment of the present application, the client can receive the fourth embedding representation and the sixth embedding representation sent by the server, and thus can calculate the tenth embedding representation based on the first variable vector and the fourth embedding representation, calculate the eleventh embedding representation based on the second variable vector and the sixth embedding representation, calculate the twelfth embedding representation based on the tenth embedding representation, the eleventh embedding representation and the first multiplication triplet, and calculate the encrypted prediction score based on the preset variables, the encrypted dynamic weight matrix and the twelfth embedding representation.

[0034] Continuing with the above example, the tenth embedding representation can be , the eleventh embedding representation can be , the twelfth embedding representation can be ,in, The encrypted prediction score can be expressed as .

[0035] Step 107: Send the encrypted prediction score to the server, so that the server decrypts the encrypted prediction score based on the encryption key to obtain a first prediction score, calculates a second prediction score based on the target dynamic weight matrix and the ninth embedding representation, and sums the first prediction score and the second prediction score to obtain a third prediction score.

[0036] In an embodiment of the present application, an encrypted prediction score can be sent to a server so that the server can decrypt the encrypted prediction score based on an encryption key to obtain a first prediction score, calculate a second prediction score based on the target dynamic weight matrix and a ninth embedding representation, and sum the first prediction score and the second prediction score to obtain a third prediction score.

[0037] Continuing with the above example, the first prediction score can be expressed as , by encrypted prediction score The second prediction score can be obtained by decryption. , the third prediction score can be expressed as ,in Represents the target dynamic weight matrix.

[0038] Step 108: Based on the third prediction score sent by the server and the preset variables, the target software is judged to be malicious, and a first judgment result is obtained.

[0039] In an embodiment of the present application, the server may send a third prediction score to the client, and the client may make a malicious determination on the target software based on the third prediction score and the preset variable to obtain a first determination result. For example, another prediction score corresponding to the third prediction score and the preset variable may be calculated, and the target software may be determined to be malicious based on the magnitude relationship between the prediction score and the preset threshold, thereby obtaining a first determination result. If the prediction score is greater than or equal to the preset threshold, the first determination result may be "the target software is malware", and if the prediction score is less than the preset threshold, the first determination result may be "the target software is normal software".

[0040] Optionally, step 108 may include the following sub-steps: Sub-step 1081, summing the preset variable and the third prediction score sent by the server to obtain a fourth prediction score.

[0041] In an embodiment of the present application, since the preset variables and the third prediction score are expressed in the same form, the client can sum the preset variables and the third prediction score after receiving the third prediction score sent by the server, so that the summation result can be used as the fourth prediction score.

[0042] Sub-step 1082, when the fourth prediction score is greater than or equal to the first threshold, determining that the first determination result of the target software is malware.

[0043] In an embodiment of the present application, the first threshold can be set manually, and when the fourth prediction score is greater than or equal to the first threshold, the first determination result of the target software can be determined to be malware. Since malicious detection of the target software is actually a binary classification process, the first threshold can be set to 50%. In addition, in order to appropriately improve the accuracy of determining the target software as malware, the value of the first threshold can be appropriately adjusted to be greater than 50%.

[0044] Sub-step 1083, when the fourth prediction score is less than or equal to the first threshold, determining that the first determination result is normal software.

[0045] In an embodiment of the present application, when the fourth prediction score is less than or equal to the first threshold, it can be determined that the first determination result of the target software is normal software.

[0046] In an embodiment of the present application, a fourth prediction score is obtained by summing the preset variables and the third prediction score sent by the server. When the fourth prediction score is greater than or equal to the first threshold, the first judgment result of the target software is determined to be malware. When the fourth prediction score is less than or equal to the first threshold, the first judgment result is determined to be normal software. The target software can be judged maliciously on the client through the relationship between the sum of the preset variables and the third prediction score and the first threshold, which can avoid the leakage of the detection data of the target software to a certain extent, improve the data security of the target software to a certain extent, and at the same time improve the detection efficiency of the target software.

[0047] In an embodiment of the present application, a first application programming interface of the target software is obtained by decompiling a software file of the target software; wherein the first application programming interface includes at least one sub-function program segment, and a first sensitive application programming interface is determined from the first application programming interface based on a character string corresponding to a preset sensitive variable; wherein the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable, or a user asset data variable, and based on the relative position of each first sensitive application programming interface in the main function program segment of the target software, a first adjacency matrix of the first sensitive application programming interface is generated, a first variable vector is calculated based on the preset variable and a first shared value of a first multiplication triple stored by the client, a second variable vector is calculated based on the preset variable and a second shared value of the first multiplication triple, a first embedded representation is calculated based on the first encrypted dynamic weight matrix, the preset variable, and the first adjacency matrix sent by the server, and a second embedded representation is calculated based on the second encrypted dynamic weight matrix, the preset variable, and the first adjacency matrix sent by the server;The encrypted dynamic weight matrix is ​​generated based on the target dynamic weight matrix and the encryption key stored in the server, and the first variable vector, the second variable vector, the first embedded representation and the second embedded representation are sent to the server, so that the server decrypts the first embedded representation based on the encryption key to obtain a third embedded representation, and calculates the fourth embedded representation based on the third embedded representation and the third shared value in the second multiplication triplet stored in the server, and decrypts the second embedded representation based on the encryption key to obtain a fifth embedded representation, and calculates the sixth embedded representation based on the fifth embedded representation and the fourth shared value in the second multiplication triplet, and calculates the sixth embedded representation based on the first variable vector and the fourth embedding representation, calculate the seventh embedding representation, calculate the eighth embedding representation based on the second variable vector and the sixth embedding representation, calculate the ninth embedding representation based on the seventh embedding representation, the eighth embedding representation and the second multiplication triplet, calculate the tenth embedding representation based on the first variable vector and the fourth embedding representation sent by the server, calculate the eleventh embedding representation based on the second variable vector and the sixth embedding representation sent by the server, calculate the twelfth embedding representation based on the tenth embedding representation, the eleventh embedding representation and the first multiplication triplet, calculate the encrypted prediction score based on the preset variables, the encrypted dynamic weight matrix and the twelfth embedding representation, and send it to the server Send the encrypted prediction score so that the server can decrypt the encrypted prediction score based on the encryption key to obtain the first prediction score, calculate the second prediction score based on the target dynamic weight matrix and the ninth embedding representation, and sum the first prediction score and the second prediction score to obtain the third prediction score, and make a malicious judgment on the target software based on the third prediction score and the preset variable sent by the server to obtain the first judgment result, and the application programming interface of the target software can be obtained by the decompilation method on the client, and the first adjacency matrix between each application programming interface can be obtained by the relative position between each application programming interface, so that the third prediction score corresponding to the first adjacency matrix can be obtained by the homomorphic encryption method of additive secret sharing between the client and the server, and finally, the target software can be maliciously judged on the client through the third prediction score and the preset variable to obtain the first judgment result, and the target software can be maliciously detected while maintaining the data security of the target dynamic weight matrix of the server and the target software of the client to obtain the first judgment result of the target software, thereby avoiding the data leakage of the client and the server, and improving the data security of the user privacy data of the client and the network model data and the target dynamic weight matrix data of the server to a certain extent. ;

[0048] Reference Figure 2 , Figure 2 A flowchart of another malware detection method provided in an embodiment of the present application is applied to a server. The method may include: Step 201, based on the target dynamic weight matrix and the encryption key, generate a first encrypted dynamic weight matrix and a second encrypted dynamic weight matrix respectively, and send the first encrypted dynamic weight matrix and the second encrypted dynamic weight matrix to the client, so that the client calculates a first embedded representation based on the first encrypted dynamic weight matrix, preset variables and a first adjacency matrix, and calculates a second embedded representation based on the second encrypted dynamic weight matrix, the preset variables and the first adjacency matrix; wherein the first adjacency matrix is ​​generated based on the relative position of each first sensitive application programming interface in the main function program segment of the target software; the first sensitive application programming interface is determined from the first application programming interface of the target software based on the character string corresponding to the preset sensitive variable; the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable and a user asset data variable; the first application programming interface is obtained by decompiling the software file of the sample software; the first application programming interface includes at least one sub-function program segment.

[0049] In the embodiments of the present application, decompilation is also called computer software reverse engineering (Reverse engineering), which refers to the work of "reverse analysis and research" on the target program (such as an executable program) of other people's software to derive the design elements such as ideas, principles, structures, algorithms, processing procedures, and operation methods used by other people's software products. In certain specific cases, the source code may be derived. The target software can be an executable program formed using a certain programming language, and the software file of the target software can be an executable file of the target software. The process of decompiling the software file is the process from the executable file to the source code. For example, if the target software is written in Easy Language, the target software can be decompiled using the Easy Format Executable File Analyzer (program name is E-Code Explorer.exe) to obtain the source code; if the target software is an Android application installation package (usually in APK format), the SMALI / BAKSMAL editing tool or the APKTOOL tool and other commonly used decompilation tools can be used to decompile the Android application installation package. After decompilation, all function program segments of the target software can be obtained, which are embodied in the form of an application programming interface (Application Programming Interface, API). Generally, the main function program segment cannot form an application programming interface, but plays the role of an application programming interface scheduling. Therefore, in the first application programming interface of the target software, at least one sub-function program segment may be included. Among them, the sub-functions may be nested with each other.

[0050] In the embodiment of the present application, in the application programming interface of the target software, some application programming interfaces may have functions such as accessing user personal information, using sensitive data input devices, or consuming user property, and these application programming interfaces may be defined as sensitive application programming interfaces. On this basis, at least one of the user personal information variable, the sensitive data input device, and the user asset data variable may be set as a preset sensitive variable, so that the first application programming interface may be string identified, and when there is a string corresponding to the preset sensitive variable in the program segment of the first application programming interface, the first application programming interface may be determined as a first sensitive application programming interface.

[0051] In an embodiment of the present application, each first sensitive application programming interface can be embodied in the main function program segment of the target software in the form of a function call. According to the classification definition of the common function call behavior of malware, the relative position of each first sensitive application programming interface being called may include the following: If the first sensitive application programming interface in the same code block is directly adjacent to another sensitive application programming interface, then the relative position between the above two first sensitive application programming interfaces can be defined as directly adjacent, represented by R0, where the code block can refer to the code contained in a set of complete symbols "{}"; If the first sensitive application programming interface in the same code block is adjacent to another sensitive application programming interface through code that does not involve function calls, then the relative position between the above two first sensitive application programming interfaces can be defined as first interval code adjacent, represented by R1; If two first sensitive application programming interfaces appear in two adjacent code blocks and there is only code that does not involve function calls in between code, the relative position between the two first sensitive application programming interfaces can be defined as the second interval code adjacent, represented by R2; if the two first sensitive application programming interfaces are adjacent through a user-defined function of a non-application programming interface type, and there is only code that does not involve function calls between the two, the relative position between the two first sensitive application programming interfaces can be defined as the third interval code adjacent, represented by R3; if the two first sensitive application programming interfaces belong to the same class (which can be determined by the call name of the interface call, if the first segment name in the call name is the same, it can be considered that the two first sensitive application programming interfaces belong to the same class), the relative position between the two first sensitive application programming interfaces can be defined as the same class adjacent, represented by R4; if the relative position between the two first sensitive application programming interfaces does not meet any of the above conditions, the relative position between the two first sensitive application programming interfaces can be defined as no relative position, represented by 0. Therefore, according to the relative position of each first sensitive application programming interface in the main function program segment of the target software, the first adjacency matrix of the generated first sensitive application programming interface can contain six elements, namely "0, R0, R1, R2, R3, R4". The first adjacency matrix may represent the relative positional relationship between the first sensitive application programming interfaces.

[0052] In an embodiment of the present application, the server can generate a first encrypted dynamic weight matrix and a second encrypted dynamic weight matrix according to the target dynamic weight matrix and encryption key stored in the server. Among them, the first encrypted dynamic weight matrix can be a matrix obtained by encrypting the weight values ​​of the first column of the target dynamic weight matrix based on the encryption key, and the second encrypted dynamic weight matrix can be a matrix obtained by encrypting the weight values ​​of at least two consecutive columns of the target dynamic weight matrix starting from the first column of weight values ​​based on the encryption key. That is, if the target weight matrix has N columns of weight values, there are N-1 second encrypted dynamic weight matrices and N first encrypted dynamic weight matrices. The encryption key referred to here can be any homomorphic encryption key that supports additive secret sharing, and another encryption key that matches the encryption key is also held in the client, so that the client can perform a certain degree of operation on the encrypted ciphertext sent by the server. The target dynamic weight matrix stored in the server can be obtained by training the first graph neural network model by the server, and the dimension of the target dynamic weight matrix can be determined according to the number of training samples and the number of network layers of the first graph neural network model. The server can send the first encrypted dynamic weight matrix and the second encrypted dynamic weight matrix to the client, so that the client can calculate the first embedded representation based on the first encrypted dynamic weight matrix, the preset variables and the first adjacency matrix, and calculate the second embedded representation based on the second encrypted dynamic weight matrix, the preset variables and the first adjacency matrix. The preset variables are private data held by the client and can be generated by a random algorithm in the client. In addition, the calculation method of the first embedded representation and the second embedded representation can refer to the embodiment and examples of step 104, which will not be repeated here.

[0053] Step 202: decrypt the first embedded representation sent by the client based on the encryption key to obtain a third embedded representation; calculate a fourth embedded representation based on the third embedded representation and the third shared value in the second multiplication triplet stored by the server; decrypt the second embedded representation sent by the client based on the encryption key stored by the server to obtain a fifth embedded representation; calculate a sixth embedded representation based on the fifth embedded representation and the fourth shared value in the second multiplication triplet; calculate a seventh embedded representation based on the first variable vector sent by the client and the fourth embedded representation; calculate an eighth embedded representation based on the second variable vector sent by the client and the sixth embedded representation. Representation, based on the seventh embedding representation, the eighth embedding representation and the second multiplication triplet, a ninth embedding representation is calculated; wherein the first embedding representation is calculated in the client based on the first encrypted dynamic weight matrix sent by the server, the preset variables and the first adjacency matrix; the second embedding representation is calculated in the client based on the second encrypted dynamic weight matrix sent by the server, the preset variables and the first adjacency matrix; the first variable vector is calculated based on the preset variables and the first shared value of the first multiplication triplet stored in the client; the second variable vector is calculated based on the preset variables and the second shared value of the first multiplication triplet.

[0054] In an embodiment of the present application, the server may receive a first variable vector, a second variable vector, a first embedded representation, and a second embedded representation sent by a client, so that a fourth embedded representation may be calculated based on the first embedded representation and the third shared value in the second multiplication triple stored by the server, the second embedded representation may be decrypted based on the encryption key to obtain a fifth embedded representation, a sixth embedded representation may be calculated based on the fifth embedded representation and the fourth shared value in the second multiplication triple, a seventh embedded representation may be calculated based on the first variable vector and the fourth embedded representation, an eighth embedded representation may be calculated based on the second variable vector and the sixth embedded representation, and a ninth embedded representation may be calculated based on the seventh embedded representation, the eighth embedded representation, and the second multiplication triple. The multiplication triple is a data form used in two-party secure computing, and is usually generated by each party alone. For example, the first multiplication triple in the client may be generated by the client, and the first multiplication triple includes three shared values, wherein the product of the first shared value and the second shared value is equal to the product shared value. In this way, the following calculations can be performed in the client: the first variable vector is calculated according to the preset variable and the first shared value of the first multiplication triplet; the second variable vector is calculated according to the preset variable and the second shared value of the first multiplication triplet. In addition, the first multiplication triplet, the first shared value, the second shared value, the first variable vector, and the second variable vector can be referred to the example part under step 104, which will not be repeated here.

[0055] Continuing with the above example, if the second multiplication triplet held by the server is ( ), Represents the first embedding representation The third embedding representation obtained after decryption is, Represents the second embedding representation The fifth embedded representation obtained after decryption, then, the fourth embedded representation can be expressed as , the sixth embedding representation can be expressed as , the seventh embedding representation can be , the eighth embedding representation can be expressed as , the ninth embedding representation can be expressed as ,in, , , the third sharing value is , the fourth share value is .

[0056] Step 203: Send the fourth embedding representation and the sixth embedding representation to the client, so that the client calculates a tenth embedding representation based on the first variable vector and the fourth embedding representation, calculates an eleventh embedding representation based on the second variable vector and the sixth embedding representation, calculates a twelfth embedding representation based on the tenth embedding representation, the eleventh embedding representation and the first multiplication triplet, and calculates an encrypted prediction score based on the preset variables, the encrypted dynamic weight matrix and the twelfth embedding representation.

[0057] In an embodiment of the present application, the server may send a fourth embedding representation and a sixth embedding representation to the client, so that the client may calculate a tenth embedding representation based on the first variable vector and the fourth embedding representation, calculate an eleventh embedding representation based on the second variable vector and the sixth embedding representation, calculate a twelfth embedding representation based on the tenth embedding representation, the eleventh embedding representation and the first multiplication triplet, and calculate an encrypted prediction score based on preset variables, the encrypted dynamic weight matrix and the twelfth embedding representation.

[0058] Continuing with the above example, the tenth embedding representation can be , the eleventh embedding representation can be , the twelfth embedding representation can be ,in, The encrypted prediction score can be expressed as .

[0059] Step 204: based on the encryption key, decrypt the encrypted prediction score sent by the client to obtain a first prediction score, calculate a second prediction score based on the target dynamic weight matrix and the ninth embedding representation, and sum the first prediction score and the second prediction score to obtain a third prediction score.

[0060] In an embodiment of the present application, the server can receive the encrypted prediction score sent by the client, so that the encrypted prediction score can be decrypted based on the encryption key to obtain a first prediction score, and the second prediction score can be calculated based on the target dynamic weight matrix and the ninth embedding representation, and the first prediction score and the second prediction score can be summed to obtain a third prediction score.

[0061] Continuing with the above example, the first prediction score can be expressed as , by encrypted prediction score The second prediction score can be obtained by decryption. , the third prediction score can be expressed as ,in Represents the target dynamic weight matrix.

[0062] Step 205: Send the third prediction score to the client, so that the client makes a malicious determination on the target software based on the third prediction score and the preset variable to obtain a first determination result.

[0063] In an embodiment of the present application, the server may send a third prediction score to the client, so that the client may make a malicious determination on the target software based on the third prediction score and preset variables to obtain a first determination result.

[0064] Optionally, step 205 may include the following sub-steps: Sub-step 2051, sending the third prediction score to the client, so that the client sums the preset variable and the third prediction score sent by the server to obtain a fourth prediction score, and when the fourth prediction score is greater than or equal to the first threshold, determining that the first judgment result of the target software is malware, and when the fourth prediction score is less than or equal to the first threshold, determining that the first judgment result is normal software.

[0065] In an embodiment of the present application, the server may send a third prediction score to the client. Since the preset variable and the third prediction score have the same form of expression, the client may sum the preset variable and the third prediction score after receiving the third prediction score sent by the server, so that the result of the sum may be used as the fourth prediction score. The first threshold may be set manually, and when the fourth prediction score is greater than or equal to the first threshold, it may be determined that the first determination result of the target software is malware. When the fourth prediction score is less than or equal to the first threshold, it may be determined that the first determination result of the target software is normal software. Among them, since malicious detection of the target software is actually a binary classification process, the first threshold may be set to 50%. In addition, in order to appropriately improve the accuracy of determining the target software as malware, the value of the first threshold may be appropriately adjusted to be greater than 50%.

[0066] In an embodiment of the present application, a third prediction score is sent to the client so that the client sums the preset variable and the third prediction score sent by the server to obtain a fourth prediction score. When the fourth prediction score is greater than or equal to the first threshold, the first judgment result of the target software is determined to be malware. When the fourth prediction score is less than or equal to the first threshold, the first judgment result is determined to be normal software. The target software can be judged maliciously on the client through the relationship between the sum of the preset variable and the third prediction score and the first threshold, which can avoid the leakage of detection data of the target software to a certain extent, improve the data security of the target software to a certain extent, and at the same time improve the detection efficiency of the target software.

[0067] In an embodiment of the present application, a first encrypted dynamic weight matrix and a second encrypted dynamic weight matrix are generated respectively based on a target dynamic weight matrix and an encryption key, and the first encrypted dynamic weight matrix and the second encrypted dynamic weight matrix are sent to a client, so that the client calculates a first embedded representation based on the first encrypted dynamic weight matrix, a preset variable and a first adjacency matrix, calculates a second embedded representation based on the second encrypted dynamic weight matrix, the preset variable and the first adjacency matrix, decrypts the first embedded representation sent by the client based on the encryption key to obtain a third embedded representation, calculates a fourth embedded representation based on the third embedded representation and a third shared value in a second multiplication triplet stored on the server, decrypts the second embedded representation sent by the client based on the encryption key stored on the server to obtain a fifth embedded representation, calculates a sixth embedded representation based on the fifth embedded representation and the fourth shared value in the second multiplication triplet, calculates a seventh embedded representation based on the first variable vector sent by the client and the fourth embedded representation, calculates an eighth embedded representation based on the second variable vector sent by the client and the sixth embedded representation, and calculates an eighth embedded representation based on the seventh embedded representation, the eighth ... The embedding representation and the second multiplication triplet are used to calculate the ninth embedding representation; wherein the first embedding representation is calculated in the client based on the first encrypted dynamic weight matrix, preset variables and the first adjacency matrix sent by the server; the second embedding representation is calculated in the client based on the second encrypted dynamic weight matrix, preset variables and the first adjacency matrix sent by the server; the first variable vector is calculated based on the preset variables and the first shared value of the first multiplication triplet stored in the client; the second variable vector is calculated based on the preset variables and the second shared value of the first multiplication triplet; the first adjacency matrix is ​​generated based on the relative position of each first sensitive application programming interface in the main function program segment of the target software; the first dynamic weight matrix is ​​generated based on the preset weight values ​​corresponding to each relative position; the first sensitive application programming interface is determined from the first application programming interface of the target software based on the string corresponding to the preset sensitive variable; the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable or a user asset data variable; the first application programming interface is obtained by decompiling the software file of the sample software;The first application programming interface includes at least one sub-function program segment, which sends a fourth embedding representation and a sixth embedding representation to the client, so that the client calculates a tenth embedding representation based on the first variable vector and the fourth embedding representation, calculates an eleventh embedding representation based on the second variable vector and the sixth embedding representation, calculates a twelfth embedding representation based on the tenth embedding representation, the eleventh embedding representation and the first multiplication triplet, calculates an encrypted prediction score based on preset variables, an encrypted dynamic weight matrix and the twelfth embedding representation, decrypts the encrypted prediction score sent by the client based on the encryption key to obtain a first prediction score, calculates a second prediction score based on the target dynamic weight matrix and the ninth embedding representation, and sums the first prediction score and the second prediction score to obtain a third prediction score, and sends the third prediction score to the client, so that the client performs a target software based on the third prediction score and the preset variables. Malicious judgment, obtain the first judgment result, the client can obtain the application programming interface of the target software by decompilation method, and obtain the first adjacency matrix between each application programming interface by the relative position between each application programming interface, so that the third prediction score corresponding to the first adjacency matrix can be obtained by the homomorphic encryption method of additive secret sharing between the client and the server, and finally the target software can be judged maliciously by the third prediction score and preset variables on the client to obtain the first judgment result, and the target software can be detected maliciously while maintaining the data security of the target dynamic weight matrix of the server and the target software of the client to obtain the first judgment result of the target software, thereby avoiding the data leakage of the client and the server, and improving the data security of the user privacy data of the client and the network model data and the target dynamic weight matrix data of the server to a certain extent. ;

[0068] Based on the above implementation, Figure 3 , Figure 3 A flow chart of a method for obtaining a target dynamic weight matrix provided in an embodiment of the present application. Before step 201, the method may further include: Step 206, decompile the software file of the sample software to obtain a first sample application programming interface of the sample software; wherein the first sample application programming interface includes at least one sub-function program segment.

[0069] In an embodiment of the present application, the software file of the sample software can be decompiled in the server, so as to obtain the first sample application programming interface of the sample software. The first sample application programming interface includes at least one sub-function program segment. The implementation content of the decompilation can refer to the implementation content of step 101. The first sample application programming interface is similar to the first application programming interface, and the implementation content of step 101 can be referred to, which will not be repeated here.

[0070] Step 207, based on the character string corresponding to the preset sensitive variable, determine the first sample sensitive application programming interface from the first sample application programming interface; wherein the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable and a user asset data variable.

[0071] In an embodiment of the present application, in the application programming interface of the sample software, some application programming interfaces may have functions such as accessing user personal information, using sensitive data input devices, or consuming user property, and these application programming interfaces may be defined as sensitive application programming interfaces. On this basis, at least one of the user personal information variable, the sensitive data input device, and the user asset data variable may be set as a preset sensitive variable, so that the server may determine the first sample sensitive application programming interface from the first sample application programming interface based on the character string corresponding to the preset sensitive variable. The preset sensitive variable may include at least one of the user personal information variable, the sensitive data input device variable, and the user asset data variable.

[0072] Step 208: Generate a first sample adjacency matrix of the first sample sensitive application programming interface based on the relative position of each of the first sample sensitive application programming interfaces in the main function program segment of the sample software.

[0073] In an embodiment of the present application, the server can generate a first sample adjacency matrix of the first sample sensitive application programming interface based on the relative position of each first sample sensitive application programming interface in the main function program segment of the sample software. The process of generating the first sample adjacency matrix is ​​similar to the process of generating the first adjacency matrix, and the embodiment content of step 103 can be referred to, which will not be repeated here.

[0074] Step 209: input the first sample adjacency matrix into the first graph neural network model to obtain the sample prediction score of the sample software output by the first graph neural network model.

[0075] In an embodiment of the present application, the first graph neural network model can be any common graph model, such as lightGCN, SGL, NCL, SimGCL, etc. The first sample adjacency matrix can be input into the first graph neural network model for propagation, so as to obtain the sample prediction score of the sample software output by the first graph neural network model. In each propagation layer of the first graph neural network model, an initial weight value can be provided, which can participate in the propagation process of the first graph neural network model and can be adjusted as a model parameter through the training process of the first graph neural network model.

[0076] Optionally, step 209 may include the following sub-steps: Sub-step 2091: input the first sample adjacency matrix into the multiple relationship aggregation layer to perform weighted aggregation on the first sample adjacency matrix to obtain a second sample adjacency matrix output by the multiple relationship aggregation layer.

[0077] In an embodiment of the present application, the first graph neural network model includes a multi-relation aggregation layer, a multi-layer heterogeneous graph convolution layer and a prediction layer. In the multi-relation aggregation layer, weighted aggregation can be performed based on the first sample adjacency matrix and combined with the weights of each layer of the multi-relation aggregation layer, so that after the first sample adjacency matrix is ​​input into the multi-relation aggregation layer, the second sample adjacency matrix output by the multi-layer relationship aggregation layer can be obtained.

[0078] Sub-step 2092: input the second sample adjacency matrix into the multi-layer heterogeneous graph convolution layer to obtain the final embedded representation of the sample output by the multi-layer heterogeneous graph convolution layer.

[0079] In an embodiment of the present application, the multi-layer heterogeneous graph convolution layer can take the second sample adjacency matrix as input and perform matrix operations with the dynamic weight matrix of the model to obtain the sample embedding representation ,in Indicates The dynamic weight matrix of the convolutional layer, Representative The node features output by the convolutional layer. Through neighborhood aggregation calculation, we get , and so on, each convolutional layer models the paths of different lengths and types in the heterogeneous graph, thereby generating a new sample embedding representation Finally, the weighted sum of these sample embedding representations is used to obtain the final sample embedding representation .

[0080] Sub-step 2093, the sample is finally embedded into the representation input into the prediction layer, and the sample prediction score of the sample software output by the prediction layer is obtained.

[0081] In the embodiment of the present application, the sample can be finally embedded into the representation input prediction layer, so that the sample prediction score of the sample software output by the prediction layer can be obtained. Specifically, the activation function of the prediction layer can be a softmax function, and the prediction layer uses a linear transformation to calculate the sample prediction score ,in represents the sample prediction score, are the model parameters of the prediction layer, is the bias vector, which can be set manually. The final embedded representation of samples corresponding to all first sample-sensitive application programming interfaces is represented, where N represents the number of first sample-sensitive application programming interfaces.

[0082] In an embodiment of the present application, the first sample adjacency matrix is ​​input into a multiple relationship aggregation layer to perform weighted aggregation on the first sample adjacency matrix to obtain a second sample adjacency matrix output by the multi-layer relationship aggregation layer, and the second sample adjacency matrix is ​​input into a multi-layer heterogeneous graph convolution layer to obtain a final embedded representation of the sample output by the multi-layer heterogeneous graph convolution layer, and the final embedded representation of the sample is input into a prediction layer to obtain a sample prediction score of the sample software output by the prediction layer. The first sample adjacency data can be processed by different types of network layers of the first graph neural network model to obtain a sample prediction score, which improves the accuracy of the sample prediction score to a certain extent.

[0083] Step 210, determining the cross entropy loss value of the first graph neural network model based on the sample prediction score and the classification label of the sample software.

[0084] In an embodiment of the present application, the calculation method of the cross entropy loss value can be shown in the following formula 1: (Formula 1) In the above formula 1, L represents the cross entropy loss value, N represents the number of training samples, and j represents the classification category. represents the sample prediction score, Indicates The samples belong to kind, 0 means The samples do not belong to The class can be determined based on the sample prediction score and the classification label of the sample software. For example, if the sample prediction score is greater than 50%, and the classification label of sample i is j=2, indicating that it is malware, then =1. In other cases, 0.

[0085] Step 211: Based on the cross entropy loss value, adjust the model parameters of the first graph neural network model and the first weight values ​​of each network layer of the first graph neural network model to obtain a target graph neural network model.

[0086] In an embodiment of the present application, the model parameters of the first graph neural network model and the first weight values ​​of each network layer can be adjusted according to the cross entropy loss value, so as to obtain the target graph neural network model. The adjustment direction of the model parameters and the first weight value can be the direction to reduce the cross entropy loss value.

[0087] Step 212, obtain the target weight value corresponding to each network layer in the target graph neural network model, and obtain the target dynamic weight matrix.

[0088] In an embodiment of the present application, the weight values ​​corresponding to each network layer in the target graph neural network model can be obtained, so as to obtain a target dynamic weight matrix. Specifically, the weight values ​​corresponding to each network layer can be arranged in the order of propagation in the target graph neural network model, so as to obtain a target dynamic weight matrix.

[0089] In an embodiment of the present application, a first sample application programming interface of the sample software is obtained by decompiling the software file of the sample software; wherein the first sample application programming interface includes at least one sub-function program segment, and based on the character string corresponding to the preset sensitive variable, the first sample sensitive application programming interface is determined from the first sample application programming interface; wherein the preset sensitive variables include at least one of a user personal information variable, a sensitive data input device variable and a user asset data variable, and based on the relative position of each first sample sensitive application programming interface in the main function program segment of the sample software, a first sample adjacency matrix of the first sample sensitive application programming interface is generated, and the first sample adjacency matrix is ​​input into the first graph neural network model to obtain a sample prediction score of the sample software output by the first graph neural network model, and based on the sample prediction score and the classification label of the sample software, a cross entropy loss value of the first graph neural network model is determined, and based on the cross entropy loss value, the model parameters of the first graph neural network model are adjusted to obtain a target graph neural network model, and the weight values ​​corresponding to each network layer in the target graph neural network model are obtained to obtain a target dynamic weight matrix, and the target dynamic weight matrix can be obtained by a graph neural network training method, which improves the accuracy of the target dynamic weight matrix to a certain extent.

[0090] Reference Figure 4 , Figure 4A flowchart of a specific implementation method of a malware detection method provided by an embodiment of the present application. In the figure, in the client, the software to be detected can be decompiled to obtain multiple API interfaces, and then the API interface can be subjected to sensitivity detection to obtain sensitive APIs, and then the first adjacency matrix is ​​generated according to the relative position between the sensitive API call statements in the main function program. In the server, the sample software data can be decompiled to obtain a sample API interface, and then the sample API interface can be subjected to sensitivity detection to obtain a sample sensitive API interface, and then the first sample adjacency matrix can be generated according to the relative position between the call statements of each sample sensitive API in the main function program, and the first sample adjacency matrix is ​​trained by the first sample adjacency matrix to obtain the target graph neural network model, and then the weight values ​​of each network layer of the target graph neural network model can be obtained, so as to obtain the target dynamic weight matrix. After that, a secure two-party cooperative malicious detection can be carried out between the client and the server, that is, the encryption method of additive secret sharing provided in the embodiment of the present application is used for calculation to obtain a malicious score, and a malicious detection result is generated by the malicious score. If the malicious score is greater than or equal to the preset threshold, the malicious detection result is malware, and if the malicious score is less than the preset threshold, the malicious detection result is normal software.

[0091] Reference Figure 5 , Figure 5 A logic block diagram of a malware detection device provided in an embodiment of the present application, which is applied to a client, the malware detection device 500 may include: The decompile module 501 is used to decompile the software file of the target software to obtain a first application programming interface of the target software; wherein the first application programming interface includes at least one sub-function program segment; A determination module 502, configured to determine a first sensitive application programming interface from the first application programming interface based on a character string corresponding to a preset sensitive variable; wherein the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable, and a user asset data variable; A generating module 503, configured to generate a first adjacency matrix of the first sensitive application programming interfaces based on the relative positions of the first sensitive application programming interfaces in the main function program segment of the target software; A first calculation module 504 is used to calculate a first variable vector based on a preset variable and a first shared value of a first multiplication triple stored in the client, calculate a second variable vector based on the preset variable and a second shared value of the first multiplication triple, calculate a first embedded representation based on a first encrypted dynamic weight matrix sent by the server, the preset variable and the first adjacency matrix, and calculate a second embedded representation based on a second encrypted dynamic weight matrix sent by the server, the preset variable and the first adjacency matrix; wherein the first encrypted dynamic weight matrix and the second encrypted dynamic weight matrix are generated based on a target dynamic weight matrix and an encryption key stored in the server; A first sending module 505 is configured to send the first variable vector, the second variable vector, the first embedded representation, and the second embedded representation to the server, so that the server decrypts the first embedded representation based on the encryption key to obtain a third embedded representation, calculates a fourth embedded representation based on the third embedded representation and a third shared value in a second multiplication triplet stored by the server, decrypts the second embedded representation based on the encryption key to obtain a fifth embedded representation, calculates a sixth embedded representation based on the fifth embedded representation and a fourth shared value in the second multiplication triplet, calculates a seventh embedded representation based on the first variable vector and the fourth embedded representation, calculates an eighth embedded representation based on the second variable vector and the sixth embedded representation, and calculates a ninth embedded representation based on the seventh embedded representation, the eighth embedded representation, and the second multiplication triplet; A second calculation module 506 is used to calculate a tenth embedding representation based on the first variable vector and the fourth embedding representation sent by the server, calculate an eleventh embedding representation based on the second variable vector and the sixth embedding representation sent by the server, calculate a twelfth embedding representation based on the tenth embedding representation, the eleventh embedding representation and the first multiplication triplet, and calculate an encrypted prediction score based on the preset variables, the encrypted dynamic weight matrix and the twelfth embedding representation; A second sending module 507 is used to send the encrypted prediction score to the server, so that the server decrypts the encrypted prediction score based on the encryption key to obtain a first prediction score, calculates a second prediction score based on the target dynamic weight matrix and the ninth embedding representation, and sums the first prediction score and the second prediction score to obtain a third prediction score; The malicious determination module 508 is used to perform malicious determination on the target software based on the third prediction score and the preset variable sent by the server to obtain a first determination result.

[0092] Optionally, the malicious determination module 508 includes: a summing submodule, configured to sum the preset variable and the third prediction score sent by the server to obtain a fourth prediction score; A first determination submodule, configured to determine, when the fourth prediction score is greater than or equal to a first threshold, that the first determination result of the target software is malware; The second determination submodule is configured to determine that the first determination result is normal software when the fourth prediction score is less than or equal to a first threshold.

[0093] The malware detection device in the embodiment of the present application can be an electronic device, or a component in the electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal, or it can be other devices other than a terminal. Exemplarily, the electronic device can be a GPU BOX, a mobile phone, a tablet computer, a laptop computer, a PDA, a vehicle-mounted electronic device, a mobile Internet device (Mobile Internet Device, MID), an augmented reality (augmented reality, AR) / virtual reality (virtual reality, VR) device, a robot, a wearable device, an ultra-mobile personal computer (ultra-mobile personal computer, UMPC), a netbook or a personal digital assistant (personal digital assistant, PDA), etc. It can also be a server, a network attached storage (Network Attached Storage, NAS), a personal computer (personal computer, PC), a television (television, TV), a teller machine or a self-service machine, etc., which is not specifically limited in the embodiment of the present application.

[0094] The malware detection device in the embodiment of the present application may be a device having an operating system. The operating system may be an Android operating system, a Linux operating system, a Windows operating system, or other possible operating systems, which are not specifically limited in the embodiment of the present application.

[0095] The malware detection device provided in the embodiment of the present application can achieve Figures 1 to 4 To avoid repetition, the various processes implemented by the method embodiment are not described here.

[0096] Reference Figure 6 , Figure 6 A malware detection device provided in an embodiment of the present application is applied to a server, and the malware detection device 600 includes: The first generation module 601 is used to generate a first encrypted dynamic weight matrix and a second encrypted dynamic weight matrix respectively based on the target dynamic weight matrix and the encryption key, and send the first encrypted dynamic weight matrix and the second encrypted dynamic weight matrix to the client, so that the client calculates a first embedded representation based on the first encrypted dynamic weight matrix, preset variables and the first adjacency matrix, and calculates a second embedded representation based on the second encrypted dynamic weight matrix, the preset variables and the first adjacency matrix; wherein the first adjacency matrix is ​​generated based on the relative position of each first sensitive application programming interface in the main function program segment of the target software; the first sensitive application programming interface is determined from the first application programming interface of the target software based on the string corresponding to the preset sensitive variable; the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable and a user asset data variable; the first application programming interface is obtained by decompiling the software file of the sample software; the first application programming interface includes at least one sub-function program segment; The first decryption calculation module 602 is used to decrypt the first embedded representation sent by the client based on the encryption key to obtain a third embedded representation, calculate a fourth embedded representation based on the third embedded representation and a third shared value in the second multiplication triplet stored by the server, decrypt the second embedded representation sent by the client based on the encryption key stored by the server to obtain a fifth embedded representation, calculate a sixth embedded representation based on the fifth embedded representation and the fourth shared value in the second multiplication triplet, calculate a seventh embedded representation based on the first variable vector sent by the client and the fourth embedded representation, and calculate a seventh embedded representation based on the second variable vector sent by the client and the sixth embedded representation. An eighth embedding representation, based on the seventh embedding representation, the eighth embedding representation and the second multiplication triplet, a ninth embedding representation is calculated; wherein the first embedding representation is calculated in the client based on the first encrypted dynamic weight matrix sent by the server, the preset variables and the first adjacency matrix; the second embedding representation is calculated in the client based on the second encrypted dynamic weight matrix sent by the server, the preset variables and the first adjacency matrix; the first variable vector is calculated based on the preset variables and the first shared value of the first multiplication triplet stored in the client; the second variable vector is calculated based on the preset variables and the second shared value of the first multiplication triplet; A first sending module 603 is configured to send the fourth embedding representation and the sixth embedding representation to the client, so that the client calculates a tenth embedding representation based on the first variable vector and the fourth embedding representation, calculates an eleventh embedding representation based on the second variable vector and the sixth embedding representation, calculates a twelfth embedding representation based on the tenth embedding representation, the eleventh embedding representation and the first multiplication triplet, and calculates an encrypted prediction score based on the preset variables, the encrypted dynamic weight matrix and the twelfth embedding representation; A second decryption calculation module 604 is used to decrypt the encrypted prediction score sent by the client based on the encryption key to obtain a first prediction score, calculate a second prediction score based on the target dynamic weight matrix and the ninth embedding representation, and sum the first prediction score and the second prediction score to obtain a third prediction score; The second sending module 605 is used to send the third prediction score to the client, so that the client makes a malicious determination on the target software based on the third prediction score and the preset variable to obtain a first determination result.

[0097] Optionally, the second sending module 605 includes: A sending submodule is used to send the third prediction score to the client, so that the client sums the preset variable and the third prediction score sent by the server to obtain a fourth prediction score, and when the fourth prediction score is greater than or equal to the first threshold, determine that the first judgment result of the target software is malware, and when the fourth prediction score is less than or equal to the first threshold, determine that the first judgment result is normal software.

[0098] Optionally, the device 600 further includes: A decompiling module, used to decompile the software file of the sample software to obtain a first sample application programming interface of the sample software; wherein the first sample application programming interface includes at least one sub-function program segment; A first determination module, configured to determine a first sample sensitive application programming interface from the first sample application programming interface based on a character string corresponding to a preset sensitive variable; wherein the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable, and a user asset data variable; A second generating module, configured to generate a first sample adjacency matrix of the first sample sensitive application programming interface based on the relative position of each of the first sample sensitive application programming interfaces in the main function program segment of the sample software; An input-output module, used for inputting the first sample adjacency matrix into a first graph neural network model to obtain a sample prediction score of the sample software output by the first graph neural network model; A second determination module, configured to determine a cross entropy loss value of the first graph neural network model based on the sample prediction score and the classification label of the sample software; An adjustment module, used to adjust the model parameters of the first graph neural network model and the first weight values ​​of each network layer of the first graph neural network model based on the cross entropy loss value to obtain a target graph neural network model; The acquisition module is used to obtain the target weight value corresponding to each network layer in the target graph neural network model to obtain the target dynamic weight matrix.

[0099] Optionally, the first graph neural network model includes a multi-relation aggregation layer, a multi-layer heterogeneous graph convolution layer and a prediction layer, and the input and output module includes: A first input-output submodule, configured to input the first sample adjacency matrix into the multiple relationship aggregation layer, so as to perform weighted aggregation on the first sample adjacency matrix, and obtain a second sample adjacency matrix output by the multiple relationship aggregation layer; A second input-output submodule, used for inputting the second sample adjacency matrix into the multi-layer heterogeneous graph convolution layer to obtain a final embedded representation of the sample output by the multi-layer heterogeneous graph convolution layer; The third input-output submodule is used to input the final embedding representation of the sample into the prediction layer to obtain the sample prediction score of the sample software output by the prediction layer.

[0100] The malware detection device in the embodiment of the present application can be an electronic device, or a component in the electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal, or it can be other devices other than a terminal. Exemplarily, the electronic device can be a GPU BOX, a mobile phone, a tablet computer, a laptop computer, a PDA, a vehicle-mounted electronic device, a mobile Internet device (Mobile Internet Device, MID), an augmented reality (augmented reality, AR) / virtual reality (virtual reality, VR) device, a robot, a wearable device, an ultra-mobile personal computer (ultra-mobile personal computer, UMPC), a netbook or a personal digital assistant (personal digital assistant, PDA), etc. It can also be a server, a network attached storage (Network Attached Storage, NAS), a personal computer (personal computer, PC), a television (television, TV), a teller machine or a self-service machine, etc., which is not specifically limited in the embodiment of the present application.

[0101] The malware detection device in the embodiment of the present application may be a device having an operating system. The operating system may be an Android operating system, a Linux operating system, a Windows operating system, or other possible operating systems, which are not specifically limited in the embodiment of the present application.

[0102] The malware detection device provided in the embodiment of the present application can achieve Figures 1 to 3 To avoid repetition, the various processes implemented by the method embodiment are not described here.

[0103] The present application embodiment provides an electronic device, see Figure 7 The electronic device 70 includes: a processor 701, a memory 702, and a computer program 7021 stored in the memory 702 and executable on the processor 701. When the processor 701 executes the program, the malware detection method of the aforementioned embodiment is implemented.

[0104] The embodiment of the present application also provides a computer-readable storage medium on which a computer program / instruction is stored. When the computer program / instruction is executed by a processor, the steps in the malware detection method disclosed in the embodiment of the present application are implemented.

[0105] The embodiment of the present application also provides a computer program product. When the computer program product is run on an electronic device, the processor is enabled to implement the steps in the malware detection method disclosed in the embodiment of the present application.

[0106] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0107] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, devices, electronic devices, and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0108] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0109] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable terminal device to implement the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0110] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present application.

[0111] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or terminal device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or terminal device. In the absence of further restrictions, the elements defined by the sentence "including one..." do not exclude the existence of other identical elements in the process, method, article or terminal device including the elements.

[0112] The above is a detailed introduction to a malware detection method and device provided by the present application. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for those skilled in the art, according to the idea of ​​the present application, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. A malware detection method, characterized in that: Applied to a client, the method comprises: Decompiling the software file of the target software to obtain a first application programming interface of the target software; wherein the first application programming interface includes at least one sub-function program segment; Determining a first sensitive application programming interface from the first application programming interface based on a character string corresponding to a preset sensitive variable; wherein the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable, and a user asset data variable; Based on the relative position of each of the first sensitive application programming interfaces in the main function program segment of the target software, generating a first adjacency matrix of the first sensitive application programming interfaces; Based on the preset variables and the first shared value of the first multiplication triplet stored in the client, a first variable vector is calculated; based on the preset variables and the second shared value of the first multiplication triplet, a second variable vector is calculated; based on the first encrypted dynamic weight matrix sent by the server, the preset variables and the first adjacency matrix, a first embedding representation is calculated; based on the second encrypted dynamic weight matrix sent by the server, the preset variables and the first adjacency matrix, a second embedding representation is calculated; wherein the first encrypted dynamic weight matrix and the second encrypted dynamic weight matrix are generated based on the target dynamic weight matrix and the encryption key stored in the server; Sending the first variable vector, the second variable vector, the first embedded representation, and the second embedded representation to the server, so that the server decrypts the first embedded representation based on the encryption key to obtain a third embedded representation, calculates a fourth embedded representation based on the third embedded representation and a third shared value in a second multiplication triplet stored by the server, decrypts the second embedded representation based on the encryption key to obtain a fifth embedded representation, calculates a sixth embedded representation based on the fifth embedded representation and a fourth shared value in the second multiplication triplet, calculates a seventh embedded representation based on the first variable vector and the fourth embedded representation, calculates an eighth embedded representation based on the second variable vector and the sixth embedded representation, and calculates a ninth embedded representation based on the seventh embedded representation, the eighth embedded representation, and the second multiplication triplet; Calculate a tenth embedding representation based on the first variable vector and the fourth embedding representation sent by the server, calculate an eleventh embedding representation based on the second variable vector and the sixth embedding representation sent by the server, calculate a twelfth embedding representation based on the tenth embedding representation, the eleventh embedding representation and the first multiplication triplet, and calculate an encrypted prediction score based on the preset variables, the encrypted dynamic weight matrix and the twelfth embedding representation; Sending the encrypted prediction score to the server, so that the server decrypts the encrypted prediction score based on the encryption key to obtain a first prediction score, calculating a second prediction score based on the target dynamic weight matrix and the ninth embedding representation, and summing the first prediction score and the second prediction score to obtain a third prediction score; Based on the third prediction score and the preset variable sent by the server, the target software is judged to be malicious to obtain a first judgment result.

2. The method according to claim 1, characterized in that The step of performing malicious determination on the target software based on the third prediction score and the preset variable sent by the server to obtain a first determination result includes: Summing the preset variable and the third prediction score sent by the server to obtain a fourth prediction score; When the fourth prediction score is greater than or equal to the first threshold, determining that the first determination result of the target software is malware; When the fourth prediction score is less than or equal to the first threshold, the first determination result is determined to be normal software.

3. A malware detection method, characterized in that: Applied to the server, the method includes: Based on the target dynamic weight matrix and the encryption key, a first encrypted dynamic weight matrix and a second encrypted dynamic weight matrix are generated respectively, and the first encrypted dynamic weight matrix and the second encrypted dynamic weight matrix are sent to the client, so that the client calculates a first embedded representation based on the first encrypted dynamic weight matrix, preset variables and the first adjacency matrix, and calculates a second embedded representation based on the second encrypted dynamic weight matrix, the preset variables and the first adjacency matrix; wherein the first adjacency matrix is ​​generated based on the relative position of each first sensitive application programming interface in the main function program segment of the target software; the first sensitive application programming interface is determined from the first application programming interface of the target software based on the character string corresponding to the preset sensitive variable; the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable and a user asset data variable; the first application programming interface is obtained by decompiling the software file of the sample software; the first application programming interface includes at least one sub-function program segment; Based on the encryption key, the first embedded representation sent by the client is decrypted to obtain a third embedded representation, based on the third embedded representation and the third shared value in the second multiplication triplet stored by the server, a fourth embedded representation is calculated, based on the encryption key stored by the server, the second embedded representation sent by the client is decrypted to obtain a fifth embedded representation, based on the fifth embedded representation and the fourth shared value in the second multiplication triplet, a sixth embedded representation is calculated, based on the first variable vector sent by the client and the fourth embedded representation, a seventh embedded representation is calculated, based on the second variable vector sent by the client and the sixth embedded representation, an eighth embedded representation is calculated, Based on the seventh embedding representation, the eighth embedding representation and the second multiplication triplet, a ninth embedding representation is calculated; wherein the first embedding representation is calculated in the client based on the first encrypted dynamic weight matrix sent by the server, the preset variables and the first adjacency matrix; the second embedding representation is calculated in the client based on the second encrypted dynamic weight matrix sent by the server, the preset variables and the first adjacency matrix; the first variable vector is calculated based on the preset variables and the first shared value of the first multiplication triplet stored in the client; the second variable vector is calculated based on the preset variables and the second shared value of the first multiplication triplet; Sending the fourth embedding representation and the sixth embedding representation to the client, so that the client calculates a tenth embedding representation based on the first variable vector and the fourth embedding representation, calculates an eleventh embedding representation based on the second variable vector and the sixth embedding representation, calculates a twelfth embedding representation based on the tenth embedding representation, the eleventh embedding representation and the first multiplication triplet, and calculates an encrypted prediction score based on the preset variables, the encrypted dynamic weight matrix and the twelfth embedding representation; Based on the encryption key, decrypt the encrypted prediction score sent by the client to obtain a first prediction score, calculate a second prediction score based on the target dynamic weight matrix and the ninth embedding representation, and sum the first prediction score and the second prediction score to obtain a third prediction score; The third prediction score is sent to the client, so that the client performs a malicious determination on the target software based on the third prediction score and the preset variable to obtain a first determination result.

4. The method according to claim 3, characterized in that The sending the third prediction score to the client so that the client makes a malicious determination on the target software based on the third prediction score and the preset variable to obtain a first determination result includes: The third prediction score is sent to the client so that the client sums the preset variable and the third prediction score sent by the server to obtain a fourth prediction score, and when the fourth prediction score is greater than or equal to the first threshold, the first determination result of the target software is determined to be malware, and when the fourth prediction score is less than or equal to the first threshold, the first determination result is determined to be normal software.

5. The method according to claim 3, characterized in that: The method further comprises: Decompiling the software file of the sample software to obtain a first sample application programming interface of the sample software; wherein the first sample application programming interface includes at least one sub-function program segment; Determine a first sample sensitive application programming interface from the first sample application programming interface based on a character string corresponding to a preset sensitive variable; wherein the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable, and a user asset data variable; Based on the relative position of each of the first sample sensitive application programming interfaces in the main function program segment of the sample software, generating a first sample adjacency matrix of the first sample sensitive application programming interface; Inputting the first sample adjacency matrix into a first graph neural network model to obtain a sample prediction score of the sample software output by the first graph neural network model; Determining a cross entropy loss value of the first graph neural network model based on the sample prediction score and the classification label of the sample software; Based on the cross entropy loss value, adjust the model parameters of the first graph neural network model and the first weight values ​​of each network layer of the first graph neural network model to obtain a target graph neural network model; Obtain the target weight values ​​corresponding to each network layer in the target graph neural network model to obtain the target dynamic weight matrix.

6. The method according to claim 5, characterized in that The first graph neural network model includes a multi-relation aggregation layer, a multi-layer heterogeneous graph convolution layer and a prediction layer. The first sample adjacency matrix and the first sample dynamic weight matrix are input into the first graph neural network model to obtain the sample prediction score of the sample software output by the first graph neural network model, including: Inputting the first sample adjacency matrix into the multiple relationship aggregation layer to perform weighted aggregation on the first sample adjacency matrix to obtain a second sample adjacency matrix output by the multi-layer relationship aggregation layer; Inputting the second sample adjacency matrix into the multi-layer heterogeneous graph convolution layer to obtain a final embedded representation of the sample output by the multi-layer heterogeneous graph convolution layer; The sample is finally embedded into the representation and input into the prediction layer to obtain the sample prediction score of the sample software output by the prediction layer.

7. A malware detection device, characterized in that: Applied to a client, the device comprises: A decompiling module, used for decompiling a software file of the target software to obtain a first application programming interface of the target software; wherein the first application programming interface includes at least one sub-function program segment; A determination module, configured to determine a first sensitive application programming interface from the first application programming interface based on a character string corresponding to a preset sensitive variable; wherein the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable, and a user asset data variable; A generating module, configured to generate a first adjacency matrix of the first sensitive application programming interfaces based on the relative positions of the first sensitive application programming interfaces in the main function program segment of the target software; A first calculation module is used to calculate a first variable vector based on a preset variable and a first shared value of a first multiplication triplet stored in the client, calculate a second variable vector based on the preset variable and a second shared value of the first multiplication triplet, calculate a first embedded representation based on a first encrypted dynamic weight matrix sent by a server, the preset variable and the first adjacency matrix, and calculate a second embedded representation based on a second encrypted dynamic weight matrix sent by the server, the preset variable and the first adjacency matrix; wherein the first encrypted dynamic weight matrix and the second encrypted dynamic weight matrix are generated based on a target dynamic weight matrix and an encryption key stored in the server; a first sending module, configured to send the first variable vector, the second variable vector, the first embedded representation, and the second embedded representation to the server, so that the server decrypts the first embedded representation based on the encryption key to obtain a third embedded representation, calculates a fourth embedded representation based on the third embedded representation and a third shared value in a second multiplication triplet stored by the server, decrypts the second embedded representation based on the encryption key to obtain a fifth embedded representation, calculates a sixth embedded representation based on the fifth embedded representation and a fourth shared value in the second multiplication triplet, calculates a seventh embedded representation based on the first variable vector and the fourth embedded representation, calculates an eighth embedded representation based on the second variable vector and the sixth embedded representation, and calculates a ninth embedded representation based on the seventh embedded representation, the eighth embedded representation, and the second multiplication triplet; a second calculation module, configured to calculate a tenth embedding representation based on the first variable vector and the fourth embedding representation sent by the server, calculate an eleventh embedding representation based on the second variable vector and the sixth embedding representation sent by the server, calculate a twelfth embedding representation based on the tenth embedding representation, the eleventh embedding representation and the first multiplication triplet, and calculate an encrypted prediction score based on the preset variables, the encrypted dynamic weight matrix and the twelfth embedding representation; a second sending module, configured to send the encrypted prediction score to the server, so that the server decrypts the encrypted prediction score based on the encryption key to obtain a first prediction score, calculates a second prediction score based on the target dynamic weight matrix and the ninth embedding representation, and sums the first prediction score and the second prediction score to obtain a third prediction score; The malicious determination module is used to perform malicious determination on the target software based on the third prediction score sent by the server and the preset variable to obtain a first determination result.

8. A malware detection device, characterized in that: Applied to the server, the device comprises: A first generation module is used to generate a first encrypted dynamic weight matrix and a second encrypted dynamic weight matrix respectively based on a target dynamic weight matrix and an encryption key, and send the first encrypted dynamic weight matrix and the second encrypted dynamic weight matrix to a client, so that the client calculates a first embedded representation based on the first encrypted dynamic weight matrix, preset variables and a first adjacency matrix, and calculates a second embedded representation based on the second encrypted dynamic weight matrix, the preset variables and the first adjacency matrix; wherein the first adjacency matrix is ​​generated based on the relative position of each first sensitive application programming interface in the main function program segment of the target software; the first sensitive application programming interface is determined from the first application programming interface of the target software based on the character string corresponding to the preset sensitive variable; the preset sensitive variable includes at least one of a user personal information variable, a sensitive data input device variable and a user asset data variable; the first application programming interface is obtained by decompiling the software file of the sample software; the first application programming interface includes at least one sub-function program segment; a first decryption calculation module, configured to decrypt the first embedded representation sent by the client based on the encryption key to obtain a third embedded representation, calculate a fourth embedded representation based on the third embedded representation and a third shared value in the second multiplication triplet stored by the server, decrypt the second embedded representation sent by the client based on the encryption key stored by the server to obtain a fifth embedded representation, calculate a sixth embedded representation based on the fifth embedded representation and the fourth shared value in the second multiplication triplet, calculate a seventh embedded representation based on the first variable vector sent by the client and the fourth embedded representation, and calculate a seventh embedded representation based on the second variable vector sent by the client and the sixth embedded representation. Eight embedding representations, calculating a ninth embedding representation based on the seventh embedding representation, the eighth embedding representation and the second multiplication triplet; wherein the first embedding representation is calculated in the client based on the first encrypted dynamic weight matrix sent by the server, the preset variables and the first adjacency matrix; the second embedding representation is calculated in the client based on the second encrypted dynamic weight matrix sent by the server, the preset variables and the first adjacency matrix; the first variable vector is calculated based on the preset variables and the first shared value of the first multiplication triplet stored in the client; the second variable vector is calculated based on the preset variables and the second shared value of the first multiplication triplet; a first sending module, configured to send the fourth embedding representation and the sixth embedding representation to the client, so that the client calculates a tenth embedding representation based on the first variable vector and the fourth embedding representation, calculates an eleventh embedding representation based on the second variable vector and the sixth embedding representation, calculates a twelfth embedding representation based on the tenth embedding representation, the eleventh embedding representation and the first multiplication triplet, and calculates an encrypted prediction score based on the preset variables, the encrypted dynamic weight matrix and the twelfth embedding representation; a second decryption calculation module, configured to decrypt the encrypted prediction score sent by the client based on the encryption key to obtain a first prediction score, calculate a second prediction score based on the target dynamic weight matrix and the ninth embedding representation, and sum the first prediction score and the second prediction score to obtain a third prediction score; The second sending module is used to send the third prediction score to the client, so that the client makes a malicious determination on the target software based on the third prediction score and the preset variable to obtain a first determination result.

Citation Information

Patent Citations

  • Multi-malicious-software hybrid detection method, system and device with privacy protection

    CN111417121A

  • Android malicious software detection system and method based on heterogeneous graph learning

    CN113761529A

  • Intelligent contract fuzzy test method and system based on ant colony algorithm

    CN118764158A

  • Techniques for securing, accessing, and interfacing with enterprise resources

    WO2024091682A1