Malicious program detection and model training method and device, medium and equipment
By extracting target feature data from multiple target feature dimensions of PE sample files and using malicious program detection models for detection, the problem of traditional methods being poor in the face of zero-day attacks and highly mutated malicious code is solved, and high accuracy and rapid malicious program detection is achieved.
Patent Information
- Application Number
- CN202311508953.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-13
- Publication Date
- 2025-05-13
AI Technical Summary
Traditional malicious program detection methods are not effective in the face of zero-day attacks and highly mutated malicious code, making it difficult to effectively identify and detect.
By extracting and combining target feature data from multiple target feature dimensions of PE sample files, using malicious program detection models for detection, improving the accuracy and speed of malicious program detection.
It realizes high accuracy and rapid detection of malicious programs, can identify mutated viruses and zero-day viruses, and improves the detection and killing efficiency.
Smart Images

Figure CN119989344A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a method, device, medium and equipment for detecting and training a malicious program model. Background Art
[0002] With the rapid development of information technology, computer networks have become an indispensable part of daily work and life. However, at the same time, network threats such as malicious programs and viruses are also increasing, posing a serious threat to the computer system security of individuals and organizations, especially for PE (Portable Executable) files under the Windows operating system. Traditional malicious program detection and defense methods are mainly based on feature matching of virus libraries and detection of known signatures, which may be very effective in dealing with known threats; but with the continuous evolution and complexity of malicious attack methods, the limitations of traditional methods are becoming more and more obvious, especially when facing zero-day attacks and highly mutated malicious codes, the effect is obviously not good. Summary of the invention
[0003] The embodiments of the present application provide a method, device, medium and equipment for detecting and training a malicious program model, which can extract and combine target feature data of multiple target feature dimensions of a PE sample file to detect whether a malicious program exists, thereby improving the accuracy and speed of detecting and killing malicious programs. The above technical solution is as follows:
[0004] In a first aspect, an embodiment of the present application provides a method for detecting malicious programs, the method comprising:
[0005] Get the PE sample file;
[0006] The above-mentioned PE sample file is input into the malicious program detection model, the target feature data corresponding to each of the multiple target feature dimensions of the above-mentioned PE sample file are extracted, and the target detection evaluation result corresponding to the above-mentioned PE sample file is output based on the target feature data corresponding to each of the above-mentioned multiple target feature dimensions; the above-mentioned malicious program detection model is trained based on multiple PE sample files with known state labels; the above-mentioned state labels include malicious labels and non-malicious labels.
[0007] In a possible implementation, the multiple target feature dimensions include at least two of the following feature dimensions:
[0008] Rich Header features, Nt Header features, Section features, import table features, export table features, resource table features, code segment features, DotNet features, AutoIt features, NSIS features, digital certificate signature features, string features, structural deformity features and file information entropy features.
[0009] In a possible implementation, the extracting of target feature data corresponding to each of the multiple target feature dimensions of the PE sample file includes:
[0010] Determine a plurality of target feature dimensions corresponding to the PE sample file from the feature dimensions corresponding to the PE sample file;
[0011] The target feature data corresponding to each of the above-mentioned multiple target feature dimensions are extracted.
[0012] In a possible implementation, the extracting of target feature data corresponding to each of the plurality of target feature dimensions includes:
[0013] Extracting a plurality of first feature data based on the target feature dimension according to a preset extraction rule;
[0014] The plurality of first characteristic data are standardized and converted into a target data interval based on a preset mapping function; the target data interval includes a plurality of second characteristic data, and the second characteristic data correspond to the first characteristic data one by one;
[0015] Based on the distribution trend and discreteness of the above-mentioned second feature in the above-mentioned target data interval, the target feature data corresponding to the above-mentioned target feature dimension is determined by a gradient algorithm.
[0016] In a possible implementation, the outputting of the target detection evaluation result corresponding to the PE sample file based on the target feature data corresponding to each of the plurality of target feature dimensions includes:
[0017] Inputting the target feature data of the above-mentioned multiple target feature dimensions into the sub-models of the corresponding feature dimensions for detection and evaluation, respectively, to obtain the detection results corresponding to the above-mentioned multiple target feature dimensions;
[0018] Based on the detection results corresponding to each of the above multiple target feature dimensions, the target detection evaluation result corresponding to the above PE sample file is determined.
[0019] In a second aspect, an embodiment of the present application provides a method for training a malicious program detection model, the method comprising:
[0020] Obtain multiple PE sample files with known status tags; the above status tags include malicious tags and non-malicious tags;
[0021] Input the PE sample file into the malicious program detection model to obtain target feature data corresponding to each of the multiple target feature dimensions of the PE sample file, and output the prediction result corresponding to the PE sample file based on the target feature data corresponding to each of the multiple target feature dimensions;
[0022] The above-mentioned malicious program detection model is updated based on the prediction results and status labels corresponding to the above-mentioned PE sample files; the above-mentioned malicious program detection model is used to implement the malicious program detection method in the first aspect of the embodiment of the present application or any possible implementation method of the first aspect.
[0023] In a possible implementation, the multiple target feature dimensions include at least two of the following feature dimensions:
[0024] Rich Header features, Nt Header features, Section features, import table features, export table features, resource table features, code segment features, DotNet features, AutoIt features, NSIS features, digital certificate signature features, string features, structural deformity features and file information entropy features.
[0025] In a third aspect, an embodiment of the present application provides a malicious program detection device, the device comprising:
[0026] The first acquisition module is used to acquire the PE sample file;
[0027] The detection module is used to input the above-mentioned PE sample file into the malicious program detection model, extract the target feature data corresponding to each of the multiple target feature dimensions of the above-mentioned PE sample file, and output the target detection evaluation result corresponding to the above-mentioned PE sample file based on the target feature data corresponding to each of the above-mentioned multiple target feature dimensions; the above-mentioned malicious program detection model is trained based on multiple PE sample files with known state labels; the above-mentioned state labels include malicious labels and non-malicious labels.
[0028] In a possible implementation, the multiple target feature dimensions include at least two of the following feature dimensions:
[0029] Rich Header features, Nt Header features, Section features, import table features, export table features, resource table features, code segment features, DotNet features, AutoIt features, NSIS features, digital certificate signature features, string features, structural deformity features and file information entropy features.
[0030] In a possible implementation, the detection module includes:
[0031] A determination unit, configured to determine a plurality of target feature dimensions corresponding to the PE sample file from the feature dimensions corresponding to the PE sample file;
[0032] The extraction unit is used to extract the target feature data corresponding to each of the above multiple target feature dimensions.
[0033] In a possible implementation, the extraction unit is specifically used to:
[0034] Extracting a plurality of first feature data based on the target feature dimension according to a preset extraction rule;
[0035] The plurality of first characteristic data are standardized and converted into a target data interval based on a preset mapping function; the target data interval includes a plurality of second characteristic data, and the second characteristic data correspond to the first characteristic data one by one;
[0036] Based on the distribution trend and discreteness of the above-mentioned second feature in the above-mentioned target data interval, the target feature data corresponding to the above-mentioned target feature dimension is determined by a gradient algorithm.
[0037] In a possible implementation, the detection module includes:
[0038] A first detection unit is used to input the target feature data of the above-mentioned multiple target feature dimensions into the sub-models of the corresponding feature dimensions for detection and evaluation, so as to obtain the detection results corresponding to the above-mentioned multiple target feature dimensions respectively;
[0039] The second detection unit is used to determine the target detection evaluation result corresponding to the above-mentioned PE sample file based on the detection results corresponding to each of the above-mentioned multiple target feature dimensions.
[0040] In a fourth aspect, an embodiment of the present application provides a training device for a malicious program detection model, the device comprising:
[0041] The second acquisition module is used to acquire a plurality of PE sample files with known status labels; the above status labels include malicious labels and non-malicious labels;
[0042] A first training module is used to input the PE sample file into a malicious program detection model, obtain target feature data corresponding to each of the multiple target feature dimensions of the PE sample file, and output a prediction result corresponding to the PE sample file based on the target feature data corresponding to each of the multiple target feature dimensions;
[0043] The second training module is used to update the above-mentioned malicious program detection model based on the prediction results and status labels corresponding to the above-mentioned PE sample files; the above-mentioned malicious program detection model is used to implement the malicious program detection method in the first aspect of the embodiment of the present application or any possible implementation method of the first aspect.
[0044] In a possible implementation, the multiple target feature dimensions include at least two of the following feature dimensions:
[0045] Rich Header features, Nt Header features, Section features, import table features, export table features, resource table features, code segment features, DotNet features, AutoIt features, NSIS features, digital certificate signature features, string features, structural deformity features and file information entropy features.
[0046] In a fifth aspect, an embodiment of the present application provides a computer storage medium, which stores multiple instructions, and the instructions are suitable for being loaded by a processor and executing the method provided by the first aspect of the embodiment of the present application or any possible implementation of the first aspect or the second aspect or any possible implementation of the second aspect.
[0047] In a sixth aspect, an embodiment of the present application provides an electronic device, including: a processor and a memory;
[0048] The processor is connected to the memory;
[0049] The above-mentioned memory is used to store executable program code;
[0050] The above-mentioned processor runs the program corresponding to the above-mentioned executable program code by reading the executable program code stored in the above-mentioned memory, so as to execute the method provided by the first aspect or any possible implementation of the first aspect or the second aspect or any possible implementation of the second aspect of the embodiment of the present application.
[0051] In one or more embodiments of the present application, a PE sample file is obtained; the PE sample file is input into a malicious program detection model, target feature data corresponding to each of the multiple target feature dimensions of the PE sample file is extracted, and target detection evaluation results corresponding to the PE sample file are output based on the target feature data corresponding to each of the multiple target feature dimensions; the malicious program detection model is trained based on PE sample files with multiple known state labels; the state labels include malicious labels and non-malicious labels. The malicious program detection model can extract and combine target feature data corresponding to each of the multiple target feature dimensions of the PE sample file to detect malicious programs. The detection process does not need to rely on a virus library, can identify mutant viruses and zero-day viruses, and has a higher detection accuracy and faster detection speed. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0053] Figure 1 A schematic diagram of the architecture of a malicious program detection system provided for an exemplary embodiment of the present application;
[0054] Figure 2 A flowchart of a malicious program detection method provided by an exemplary embodiment of the present application;
[0055] Figure 3 A schematic diagram of a feature extraction component structure included in a malicious program detection model provided by an exemplary embodiment of the present application;
[0056] Figure 4 A schematic diagram of the structure of a malicious program detection model provided for an exemplary embodiment of the present application;
[0057] Figure 5 A flowchart of a method for training a malicious program detection model provided by an exemplary embodiment of the present application;
[0058] Figure 6 A schematic diagram of a training and prediction process of a malicious program detection model provided for an exemplary embodiment of the present application;
[0059] Figure 7 A schematic diagram of the structure of a malicious program detection device provided by an exemplary embodiment of the present application;
[0060] Figure 8 A schematic diagram of the structure of a training device for a malicious program detection model provided by an exemplary embodiment of the present application;
[0061] Fig. 9 A schematic structural diagram of an electronic device provided as an exemplary embodiment of the present application. DETAILED DESCRIPTION
[0062] When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. Instead, they are only examples of devices and methods consistent with some aspects of the present application as detailed in the attached claims.
[0063] In the description of the present application, it should be understood that the terms "first", "second", etc. are used for descriptive purposes only and should not be understood as indicating or implying relative importance. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood according to the specific circumstances. In addition, in the description of the present application, unless otherwise specified, "multiple" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the objects associated before and after are in an "or" relationship.
[0064] The present application is described in detail below with reference to specific embodiments.
[0065] Please refer to Figure 1 , Figure 1 The following is a schematic diagram of the architecture of a malicious program detection system provided by an exemplary embodiment of the present application. Figure 1 As shown, the malicious program detection system may include a terminal 110 and a server 120 .
[0066] The terminal 110 is connected to the server 120 via the network 130. Optionally, the terminal 110 may be a laptop, a desktop computer, a smart phone, a tablet computer, a smart watch, etc., but is not limited thereto. The terminal 110 may install and run an application program that supports malicious program detection. The network 130 may be a wireless network or a wired network.
[0067] The server 120 may be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, distribution networks (Content Delivery Network, CDN), and big data and artificial intelligence platforms. The server 120 may provide background services for applications running on the terminal 110, for example, the server 120 provides corresponding services for applications running on the terminal 110. In the embodiment of the present application, the server 120 may provide background services for applications running on the terminal that support malicious program detection, such as training a malicious program detection model.
[0068] Those skilled in the art will appreciate that the number of the above-mentioned terminals 110 and servers 120 may be more or less. For example, there is only one terminal 110 and server 120, or there are dozens or hundreds of terminals 110 and servers 120, or more. In this case, the above-mentioned system architecture also includes other terminals and servers. In addition, in some embodiments, only the terminal 110 or the server 120 may be deployed separately. The embodiment of the present application does not limit the number of terminals and device types.
[0069] The malicious program detection method involved in one or more embodiments of the present application can be implemented by a computer program and can be run on a malicious program detection device based on the von Neumann system. The computer program can be integrated into an application or run as an independent tool application. The execution subject corresponding to the malicious program detection method can be the above-mentioned terminal 110, and the server 120 can be responsible for training the malicious program detection model and sending it to the terminal 110; the execution subject corresponding to the malicious program detection method can also be the server 120, and the terminal 110 can be responsible for uploading PE sample files to the server 120 for malicious program detection. It is specifically determined based on the actual application environment, and the embodiments of the present application do not limit this.
[0070] Next, combine Figure 1 , introduces the malicious program detection method provided by the embodiment of this application. For details, please refer to Figure 2 , which is a flowchart of a malicious program detection method provided by an exemplary embodiment of the present application. Figure 2 As shown, the malicious program detection method includes the following steps:
[0071] S201, obtaining a PE sample file.
[0072] Specifically, the PE (Portable Executable) format is a data structure that stores the necessary information about how a program is loaded and run in memory. It is a file format used for executable files, object codes, DLLs (dynamic link libraries), FONs (font files), etc. in the Windows operating system. A PE sample file is a collection of one or more PE format files. In the context of malware analysis, a PE sample file is a file that may include malicious programs or suspicious files. By detecting malicious programs in PE sample files, malicious behaviors, vulnerability exploits, and other harmful activities can be effectively identified to prevent computers and personal information from being invaded by malicious programs.
[0073] PE sample files can be obtained by scanning NVM (non-volatile memory), such as scanning the mechanical hard disk, solid-state hard disk and other storage devices of the terminal to find the PE sample files stored therein; PE sample files can also be monitored and intercepted at the network level, such as by monitoring email attachments or file downloads to find the PE sample files being transmitted. The method for obtaining PE sample files can be specifically set according to the specific implementation scenario, and is not specifically limited here.
[0074] S202, inputting the PE sample file into the malicious program detection model, extracting target feature data corresponding to each of the multiple target feature dimensions of the PE sample file, and outputting the target detection evaluation result corresponding to the PE sample file based on the target feature data corresponding to each of the multiple target feature dimensions.
[0075] Specifically, the acquired PE sample files are input into the malicious program detection model. The malicious program detection model can extract feature data corresponding to multiple feature dimensions by scanning and analyzing the PE sample files. Feature dimensions are used to describe and quantify various aspects of the PE sample files, such as file headers, code segments, data segments, import tables, export tables, and other aspects. Dividing the PE sample files into multiple feature dimensions can provide a deeper understanding of the PE sample files, so as to extract more detailed and rich feature data and improve the accuracy of detecting and killing malicious programs in PE sample files. The malicious program detection model is a machine learning model trained based on multiple PE sample files with known state labels. For example, machine learning models such as random forests, support vector machines, and deep learning can be selected. The above-mentioned state labels include malicious labels and non-malicious labels, which respectively characterize whether there are malicious programs; for example, a PE sample file with a malicious label is a PE sample file containing a malicious program, and a PE sample file with a non-malicious label is a PE sample file that does not contain a malicious program. After training, the malicious program detection model can discover more subtle changes in PE sample files through feature data of multiple feature dimensions, classify and judge PE sample files, and output the detection and evaluation results corresponding to the PE sample files. The detection and evaluation results include the status labels corresponding to the PE sample files to characterize whether the PE sample files contain malicious programs. The detection and evaluation results can be used for further analysis and response, such as isolating malicious files, warning users, updating security policies, etc.
[0076] In some embodiments, the plurality of target feature dimensions include at least two of the following feature dimensions:
[0077] Rich Header features, Nt Header features, Section features, import table features, export table features, resource table features, code segment features, DotNet features, AutoIt features, NSIS features, digital certificate signature features, string features, structural deformity features and file information entropy features.
[0078] Specifically, the embodiment of the present application refines the PE sample file into 14 feature dimensions, so that the malicious program detection model can more fully and deeply understand the PE sample file, extract the feature data of the PE sample file, realize the classification prediction of the PE sample file, and quickly and accurately identify whether the PE sample file contains malicious programs. Since different PE sample files have different data structures, the feature dimension (i.e., the target feature dimension) of the feature data that actually needs to be extracted from the PE sample file can be determined according to the actual data structure type of the PE sample file. For example, a PE sample file does not contain the import table and export table structures, so its target feature dimension does not include the import table features and export table features. In a specific implementation scenario, the part feature dimension among the above 14 feature dimensions can also be selected as the target feature dimension of the PE sample file according to the specific implementation method.
[0079] In some embodiments, the above-mentioned extraction of target feature data corresponding to each of the multiple target feature dimensions of the PE sample file includes: determining the multiple target feature dimensions corresponding to the above-mentioned PE sample file from the feature dimensions corresponding to the above-mentioned PE sample file; and extracting the target feature data corresponding to each of the above-mentioned multiple target feature dimensions.
[0080] Specifically, the existing feature dimensions of the PE sample file are determined according to its data structure, all or part of its feature dimensions are selected as target feature dimensions, and the data structure containing the corresponding feature data is located based on the target feature dimensions. By parsing these data structures, specific feature data is extracted.
[0081] For example, Figure 3 As shown, the malware detection model can include the following feature dimension extraction components to extract feature data:
[0082] Rich Header feature extraction component: used to locate the Rich Header, read the content of the Rich Header structure, and parse it according to the predetermined format. It extracts various feature parameters based on the parsing results, providing important data support for identifying and defending against malicious PE files.
[0083] Nt Header feature extraction component: used to locate the position of Nt Header, read the Nt Header structure, and parse it according to the predetermined format. According to the parsing results, various feature parameters are extracted, such as PE time information, system resource information, compiler information, etc.
[0084] Section feature extraction component: used to locate the position of each Section, read each Section structure, and parse it according to the predetermined format, and extract various feature parameters based on the parsing results, such as the nature of the section, such as whether it is executable, readable, writable, etc., the virtual address, physical address, data address and offset in the section, etc. PE Section is an important part of the PE file, which describes the content, attributes and size of each segment in the PE file, including code segment, data segment, resource segment, etc.
[0085] Import table feature extraction component: used to locate the import table, read the import table, parse the DLL files and corresponding function names and addresses, and extract these dependencies as features, which helps analyze the behavior and functions of PE files.
[0086] Export table feature extraction component: used to locate the location of the export table, read the export table, parse the function name, address information, etc., and extract this export information as features, which helps to understand how PE files interact with the import tables of other PE files.
[0087] Resource table feature extraction component: used to locate the location of the resource table, traverse the resource table, and extract resources such as icons, bitmaps, strings, version information, etc. as features, which helps to understand the visual features and metadata of PE files. The resource table is an internal structure of Windows executable files, which contains the resources required by the binary file.
[0088] Code segment feature extraction component: used to locate the location of the code segment, read the code segment, analyze and extract the location, size, byte instruction code and constant string features, which helps to identify the executable code and functions in the binary file. The code segment usually contains the executable code in the program, which can be some custom functions or library functions.
[0089] DotNet feature extraction component: used to locate the CLR header and metadata table, parse the CLR header, obtain DotNet version number, assembly flag, assembly entry point and other features; parse the metadata table to obtain the type definition, method definition, field definition and other features of the assembly; obtain the features of the IL code in the .NET assembly. DotNet is a cross-platform application framework developed and maintained by Microsoft. The DotNet framework consists of multiple components and libraries, the most important of which is the Common Language Runtime (CLR), which is the execution engine of the DotNet application and is responsible for tasks such as managing memory, executing code and handling exceptions. The CLR header is the header information unique to the DotNet assembly, the metadata table contains various metadata information of the assembly, and the IL code is the core code that implements various functions in the .NET assembly.
[0090] AutoIt feature extraction component: used to find AutoIt script information and obtain features such as script name, size, version, encryption information, etc.
[0091] NSIS feature extraction component: used to extract relevant information from NSIS-packed executable files, such as the title of the installer, whether a script is used, script information, etc. NSIS is an extensible, freely downloadable software tool for creating program installation packages for the Windows platform. Malicious developers commonly use NSIS to create malicious installation packages in order to perform their attacks and control on user computers. The NSIS feature extraction component also needs to distinguish between legitimate installers and malicious installers so that the antivirus engine can detect and clean malicious installers. The NSIS feature extraction component can also be used in combination with other feature extraction technologies to effectively prevent the spread of malicious installers by comparing them.
[0092] Digital certificate signature (Cert) feature extraction component: used to obtain digital certificate signatures in PE files, and obtain software vendor information and signature key features from digital certificate signatures.
[0093] String feature extraction component: used to parse and extract string features from executable files, scripts and other code files through n-grams or regular expressions. For example, n-grams can be used to use n consecutive characters or words as features to determine whether it is malicious code based on the frequency of occurrence and other rules; and regular expressions can be used to match URL or IP address features contained in the code.
[0094] Structural deformity feature extraction component: used to check the header, section table, import / export table, etc. of the PE file, find abnormal or deformed structural parts that do not conform to the PE file specifications, and extract features from the deformed structure, such as tampered code areas, inserted malicious code, modified API calls, specific API names, tampered paths, etc.
[0095] File information entropy feature extraction component: used to calculate the information entropy of binary files and obtain some feature information for classifying and identifying binary files. Information entropy refers to the uncertainty or dispersion measurement of a system or data source, which can be used to quantify the randomness or complexity of data or files.
[0096] In some embodiments, the target feature dimension of the PE sample file can be determined by setting the type and number of feature extraction components in the malware detection model; if the PE sample file does not have a data structure of the corresponding feature dimension, the feature data extracted by the corresponding feature extraction component is empty.
[0097] In some embodiments, the above-mentioned extraction of target feature data corresponding to each of the multiple target feature dimensions includes: extracting multiple first feature data based on the above-mentioned target feature dimensions according to preset extraction rules; standardizing the above-mentioned multiple first feature data, and converting them into a target data interval based on a preset mapping function; the above-mentioned target data interval includes multiple second feature data, and the above-mentioned second feature data corresponds one-to-one to the above-mentioned first feature data; based on the distribution trend and discrete situation of the above-mentioned second features in the above-mentioned target data interval, determining the target feature data corresponding to the above-mentioned target feature dimensions through a gradient algorithm.
[0098] Specifically, when extracting feature data, since the feature volume of PE sample files is large, the information is rich, and the format is not uniform, it is necessary to unify the format and standardize the features of PE sample files so that subsequent work can be more efficient and accurate. Among them, the first feature data is the original feature data extracted according to the preset extraction rules based on the target feature dimension; standardizing or normalizing the first feature data can make them have the same data format and data structure. For example, a name rule library is established to classify and process function names, function library names, etc. in the import table. According to the name rule library, different types of names are classified and converted into corresponding feature values for processing and analysis in the model.
[0099] Then the first feature data after standardization or normalization is merged and converted to the target data interval based on the preset mapping function. For example, some PE sample files may contain dozens of modules, each module contains several to hundreds of functions. Through the preset mapping function, the extracted feature data can be converted and mapped to a unified data interval. Among them, the second feature data is the feature data mapped to the target data interval after the first feature data after standardization or normalization, and the second feature data corresponds to the first feature data one by one.
[0100] In the target data interval, in order to optimize the value of the feature data, the overall distribution trend and discreteness of the second feature data can be analyzed, and the value of the target feature data can be iteratively updated using the gradient descent algorithm, so that the value of the target feature data is more consistent with the overall distribution trend of the sample data. In this way, the overall distribution characteristics of the feature data are retained without losing the details of the individual features, and the target feature data that best represents the characteristics of the target feature dimension can be screened out.
[0101] In some embodiments, the target detection evaluation result corresponding to the PE sample file is output based on the target feature data corresponding to each of the multiple target feature dimensions, including: inputting the target feature data of the multiple target feature dimensions into the sub-models of the corresponding feature dimensions for detection and evaluation, and obtaining the detection results corresponding to each of the multiple target feature dimensions; based on the detection results corresponding to each of the multiple target feature dimensions, determining the target detection evaluation result corresponding to the PE sample file.
[0102] Specifically, Figure 4 As shown, the malicious program detection model includes multiple sub-models, each of which corresponds to a feature dimension. After extracting the feature data of multiple feature dimensions of the PE sample file, the feature data is input into the corresponding sub-model for detection and evaluation according to the different feature dimensions to which the feature data belongs, and a detection result of the feature dimension is obtained; finally, the detection results of multiple feature dimensions can be integrated based on statistical decision-making or weighted average, and the target detection and evaluation results corresponding to the PE sample file can be determined to determine whether the PE sample file contains malicious programs. For example, the target feature dimensions of a PE sample file are 14; the detection results of each target feature dimension are counted as the number of malicious labels. When the number exceeds 8, it is considered that the target detection and evaluation result of the PE sample file is a PE sample file with a malicious label, that is, there is a malicious program.
[0103] In an embodiment of the present application, a PE sample file is obtained; the PE sample file is input into a malicious program detection model, target feature data corresponding to each of the multiple target feature dimensions of the PE sample file is extracted, and a target detection evaluation result corresponding to the PE sample file is output based on the target feature data corresponding to each of the multiple target feature dimensions; the malicious program detection model is trained based on PE sample files with multiple known state labels; the state labels include malicious labels and non-malicious labels. The malicious program detection model can extract and combine target feature data corresponding to each of the multiple target feature dimensions of the PE sample file to detect malicious programs. The detection process does not need to rely on a virus library, can identify mutant viruses and zero-day viruses, and has a higher detection accuracy rate (more than 88%) and a faster detection speed.
[0104] Next, combine Figure 1 , taking the training of the malicious program detection model executed by the server 120 as an example, a training method of a malicious program detection model provided by an exemplary embodiment of the present application is introduced. Figure 5 As shown, the training method of the malware detection model includes the following steps:
[0105] S501, obtaining a plurality of PE sample files with known status labels.
[0106] Specifically, Figure 6 As shown, before performing malicious program detection, the server 120 can be used to train a malicious program detection model (training phase), and then the trained malicious program detection model can be deployed on the terminal 110 or the server 120 to perform malicious program detection (prediction phase) for PE sample files with unknown labels (unknown files). When training the malicious program detection model, the server 120 can obtain multiple PE sample files with known status labels, and the above status labels include malicious labels and non-malicious labels. The above status labels are used to characterize whether the PE sample file contains malicious programs; PE sample files with malicious labels are virus files containing malicious programs, and PE sample files with non-malicious labels are white files without malicious programs.
[0107] S502, inputting the PE sample file into the malicious program detection model, obtaining target feature data corresponding to each of the multiple target feature dimensions of the PE sample file, and outputting the prediction result corresponding to the PE sample file based on the target feature data corresponding to each of the multiple target feature dimensions.
[0108] Specifically, PE sample files are refined into multiple target feature dimensions, so that the malware detection model can understand the PE sample files more fully and deeply, extract richer feature data, and improve the prediction accuracy of PE sample files with malicious labels.
[0109] In some embodiments, the plurality of target feature dimensions include at least two of the following feature dimensions:
[0110] Rich Header features, Nt Header features, Section features, import table features, export table features, resource table features, code segment features, DotNet features, AutoIt features, NSIS features, digital certificate signature features, string features, structural deformity features and file information entropy features.
[0111] Specifically, the steps for extracting target feature data under each target feature dimension are consistent with step S202 and will not be repeated here.
[0112] S503: Update the malicious program detection model based on the prediction result and status label corresponding to the PE sample file.
[0113] Specifically, the malware detection model can be optimized by gradient descent method and other methods. For example, the model is used to predict PE samples (i.e., training data) with known state labels, and the prediction results are obtained, and the loss between the prediction results and the actual state labels is calculated; the gradient of the loss to the model parameters is calculated by the back propagation algorithm; the model parameters are updated in the direction of the gradient to reduce the loss; the above steps are repeated until the model parameters reach the preset number of iterations, or the performance of the model meets the preset standards.
[0114] It should be noted that the above malware detection model is used to implement the malware detection method described in the embodiments of this specification. The specific structure or configuration of the malware detection model can be found in the above Figure 2 The content of the malicious program detection method in will not be repeated here.
[0115] Please refer to the following Figure 7 , Figure 7 A malicious program detection device is provided as an exemplary embodiment of the present application. Figure 7 As shown, the malicious program detection device 700 includes:
[0116] A first acquisition module 710, used to acquire a PE sample file;
[0117] The detection module 720 is used to input the above-mentioned PE sample file into the malicious program detection model, extract the target feature data corresponding to each of the multiple target feature dimensions of the above-mentioned PE sample file, and output the target detection evaluation result corresponding to the above-mentioned PE sample file based on the target feature data corresponding to each of the above-mentioned multiple target feature dimensions; the above-mentioned malicious program detection model is trained based on multiple PE sample files with known state labels; the above-mentioned state labels include malicious labels and non-malicious labels.
[0118] In some possible embodiments, the multiple target feature dimensions include at least two of the following feature dimensions:
[0119] Rich Header features, Nt Header features, Section features, import table features, export table features, resource table features, code segment features, DotNet features, AutoIt features, NSIS features, digital certificate signature features, string features, structural deformity features and file information entropy features.
[0120] In some possible embodiments, the detection module 720 includes:
[0121] A determination unit, configured to determine a plurality of target feature dimensions corresponding to the PE sample file from the feature dimensions corresponding to the PE sample file;
[0122] The extraction unit is used to extract the target feature data corresponding to each of the above multiple target feature dimensions.
[0123] In some possible embodiments, the extraction unit is specifically used for:
[0124] Extracting a plurality of first feature data based on the target feature dimension according to a preset extraction rule;
[0125] The plurality of first characteristic data are standardized and converted into a target data interval based on a preset mapping function; the target data interval includes a plurality of second characteristic data, and the second characteristic data correspond to the first characteristic data one by one;
[0126] Based on the distribution trend and discreteness of the above-mentioned second feature in the above-mentioned target data interval, the target feature data corresponding to the above-mentioned target feature dimension is determined by a gradient algorithm.
[0127] In some possible embodiments, the detection module 720 includes:
[0128] A first detection unit is used to input the target feature data of the above-mentioned multiple target feature dimensions into the sub-models of the corresponding feature dimensions for detection and evaluation, so as to obtain detection results corresponding to the above-mentioned multiple target feature dimensions respectively;
[0129] The second detection unit is used to determine the target detection evaluation result corresponding to the above-mentioned PE sample file based on the detection results corresponding to each of the above-mentioned multiple target feature dimensions.
[0130] The division of the modules in the above-mentioned malicious program detection device is only for illustration. In other embodiments, the malicious program detection device can be divided into different modules as needed to complete all or part of the functions of the above-mentioned malicious program detection device. The implementation of each module in the malicious program detection device provided in the embodiment of the present application can be in the form of a computer program. The computer program can be run on a terminal or a server. The program modules constituted by the computer program can be stored in the memory of the terminal or the server. When the computer program is executed by the processor, all or part of the steps of the malicious program detection method described in the embodiment of the present application are implemented.
[0131] Please refer to the following Figure 8 , Figure 8 A training device for a malicious program detection model is provided as an exemplary embodiment of the present application. Figure 8 As shown, the training device 800 of the malicious program detection model includes:
[0132] The second acquisition module 810 is used to acquire a plurality of PE sample files with known status labels; the status labels include malicious labels and non-malicious labels;
[0133] A first training module 820 is used to input the PE sample file into a malicious program detection model, obtain target feature data corresponding to each of the multiple target feature dimensions of the PE sample file, and output a prediction result corresponding to the PE sample file based on the target feature data corresponding to each of the multiple target feature dimensions;
[0134] The second training module 830 is used to update the above-mentioned malicious program detection model based on the prediction results and status labels corresponding to the above-mentioned PE sample files; the above-mentioned malicious program detection model is used to implement the malicious program detection method described in the embodiment of the present application.
[0135] In some possible embodiments, the multiple target feature dimensions include at least two of the following feature dimensions:
[0136] Rich Header features, Nt Header features, Section features, import table features, export table features, resource table features, code segment features, DotNet features, AutoIt features, NSIS features, digital certificate signature features, string features, structural deformity features and file information entropy features.
[0137] The division of the modules in the training device of the above-mentioned malicious program detection model is only for illustration. In other embodiments, the training device of the malicious program detection model can be divided into different modules as needed to complete all or part of the functions of the training device of the above-mentioned malicious program detection model. The implementation of each module in the training device of the malicious program detection model provided in the embodiment of the present application can be in the form of a computer program. The computer program can be run on a terminal or a server. The program modules constituted by the computer program can be stored in the memory of the terminal or the server. When the computer program is executed by the processor, all or part of the steps of the training method of the malicious program detection model described in the embodiment of the present application are implemented.
[0138] See also Fig. 9 , Fig. 9 The following is a schematic diagram of the structure of an electronic device provided by an exemplary embodiment of the present application. Fig. 9 As shown, the electronic device 900 may include: at least one processor 910, at least one communication bus 920, a user interface 930, at least one network interface 940, and a memory 950. The communication bus 920 may be used to realize the connection and communication of the above components.
[0139] The user interface 930 may include a display screen (Display) and a camera (Camera), and the optional user interface may also include a standard wired interface and a wireless interface.
[0140] The network interface 940 may optionally include a Bluetooth module, a Near Field Communication (NFC) module, a Wireless Fidelity (Wi-Fi) module, and the like.
[0141] Among them, the processor 910 may include one or more processing cores. The processor 910 uses various interfaces and lines to connect various parts within the entire electronic device 900, and executes various functions and processes data of the routing electronic device 900 by running or executing instructions, programs, code sets or instruction sets stored in the memory 950, and calling data stored in the memory 950. Optionally, the processor 910 can be implemented in at least one hardware form of digital signal processing (Digital Signal Processing, DSP), field programmable gate array (Field-Programmable Gate Array, FPGA), and programmable logic array (Programmable Logic Array, PLA). The processor 910 can integrate one or more combinations of a processor (Central Processing Unit, CPU), a graphics processor (Graphics Processing Unit, GPU), and a modem. Among them, the CPU mainly processes the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; and the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 910, but may be implemented separately through a chip.
[0142] The memory 950 may include a random access memory (RAM) or a read-only memory (ROM). Optionally, the memory 950 includes a non-transitory computer-readable medium. The memory 950 may be used to store instructions, programs, codes, code sets or instruction sets. The memory 950 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as an acquisition function, a detection function, etc.), instructions for implementing the above-mentioned method embodiments, etc.; the data storage area may store data involved in the above-mentioned method embodiments, etc. The memory 950 may optionally be at least one storage device located away from the aforementioned processor 910. As Fig. 9 As shown, the memory 950 as a computer storage medium may include an operating system, a network communication module, a user interface module, and program instructions.
[0143] Specifically, the processor 910 may be used to call the program instructions stored in the memory 950, and specifically perform the following operations:
[0144] Get the PE sample file;
[0145] The above-mentioned PE sample file is input into the malicious program detection model, the target feature data corresponding to each of the multiple target feature dimensions of the above-mentioned PE sample file are extracted, and the target detection evaluation result corresponding to the above-mentioned PE sample file is output based on the target feature data corresponding to each of the above-mentioned multiple target feature dimensions; the above-mentioned malicious program detection model is trained based on multiple PE sample files with known state labels; the above-mentioned state labels include malicious labels and non-malicious labels.
[0146] In some possible embodiments, the multiple target feature dimensions include at least two of the following feature dimensions:
[0147] Rich Header features, Nt Header features, Section features, import table features, export table features, resource table features, code segment features, DotNet features, AutoIt features, NSIS features, digital certificate signature features, string features, structural deformity features and file information entropy features.
[0148] In some possible embodiments, when the processor 910 executes the extraction of target feature data corresponding to each of the multiple target feature dimensions of the PE sample file, the processor 910 is specifically configured to execute:
[0149] Determine a plurality of target feature dimensions corresponding to the PE sample file from the feature dimensions corresponding to the PE sample file;
[0150] The target feature data corresponding to each of the above multiple target feature dimensions are extracted.
[0151] In some possible embodiments, when the processor 910 executes the extracting of the target feature data corresponding to each of the plurality of target feature dimensions, the processor 910 is specifically configured to execute:
[0152] Extracting a plurality of first feature data based on the target feature dimension according to a preset extraction rule;
[0153] The plurality of first characteristic data are standardized and converted into a target data interval based on a preset mapping function; the target data interval includes a plurality of second characteristic data, and the second characteristic data correspond to the first characteristic data one by one;
[0154] Based on the distribution trend and discreteness of the above-mentioned second feature in the above-mentioned target data interval, the target feature data corresponding to the above-mentioned target feature dimension is determined by a gradient algorithm.
[0155] In some possible embodiments, when the processor 910 executes the output of the target detection evaluation result corresponding to the PE sample file based on the target feature data corresponding to each of the multiple target feature dimensions, the processor 910 is specifically configured to execute:
[0156] Inputting the target feature data of the above-mentioned multiple target feature dimensions into the sub-models of the corresponding feature dimensions for detection and evaluation, respectively, to obtain the detection results corresponding to the above-mentioned multiple target feature dimensions;
[0157] Based on the detection results corresponding to each of the above multiple target feature dimensions, the target detection evaluation result corresponding to the above PE sample file is determined.
[0158] In some possible embodiments, the electronic device 900 may be a training device for the malicious program detection model, and the processor 910 may further specifically execute:
[0159] Obtain multiple PE sample files with known status tags; the above status tags include malicious tags and non-malicious tags;
[0160] Input the PE sample file into the malicious program detection model to obtain target feature data corresponding to each of the multiple target feature dimensions of the PE sample file, and output the prediction result corresponding to the PE sample file based on the target feature data corresponding to each of the multiple target feature dimensions;
[0161] The above-mentioned malicious program detection model is updated based on the prediction results and status labels corresponding to the above-mentioned PE sample files; the above-mentioned malicious program detection model is used to implement the malicious program detection method described in the embodiments of the present application.
[0162] In some possible embodiments, the multiple target feature dimensions include at least two of the following feature dimensions:
[0163] Rich Header features, Nt Header features, Section features, import table features, export table features, resource table features, code segment features, DotNet features, AutoIt features, NSIS features, digital certificate signature features, string features, structural deformity features and file information entropy features.
[0164] The embodiment of the present application also provides a computer-readable storage medium, which stores instructions, and when the instructions are executed on a computer or a processor, the computer or the processor executes one or more steps in the above embodiment. If the various component modules of the above malicious program detection device or the training device of the malicious program detection model are implemented in the form of software functional units and sold or used as independent products, they can be stored in the above computer-readable storage medium.
[0165] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The above-mentioned computer program product includes one or more computer instructions. When the above-mentioned computer program instructions are loaded and executed on a computer, the above-mentioned process or function according to the embodiment of the present application is generated in whole or in part. The above-mentioned computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable devices. The above-mentioned computer instructions can be stored in a computer-readable storage medium or transmitted by the above-mentioned computer-readable storage medium. The above-mentioned computer instructions can be transmitted from a website site, a computer, a server or a data center to another website site, a computer, a server or a data center by wired (such as coaxial cable, optical fiber, digital subscriber line (Digital Subscriber Line, DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The above-mentioned computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server, a data center, etc. that contains one or more available media integrated. The above-mentioned available media can be magnetic media (for example, floppy disks, hard disks, tapes), optical media (for example, digital versatile discs (DVD)), or semiconductor media (for example, solid state disks (SSD)), etc.
[0166] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods. The aforementioned storage medium includes: ROM, RAM, magnetic disk or optical disk and other media that can store program codes. In the absence of conflict, the technical features in this embodiment and the implementation scheme can be combined arbitrarily.
[0167] The embodiments described above are merely preferred embodiments of the present application and are not intended to limit the scope of the present application. Without departing from the design spirit of the present application, various modifications and improvements made to the technical solutions of the present application by ordinary technicians in this field should fall within the protection scope determined by the claims.
[0168] The above describes a specific embodiment of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims and the specification can be performed in an order different from the order in the embodiments recorded in the specification and still achieve the desired results. In addition, the process depicted in the drawings does not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
Claims
1. A method for detecting malicious programs, characterized in that: The method comprises: Get the PE sample file; The PE sample file is input into a malicious program detection model, target feature data corresponding to each of multiple target feature dimensions of the PE sample file are extracted, and a target detection evaluation result corresponding to the PE sample file is output based on the target feature data corresponding to each of the multiple target feature dimensions; the malicious program detection model is trained based on multiple PE sample files with known state labels; the state labels include malicious labels and non-malicious labels.
2. The method according to claim 1, characterized in that The multiple target feature dimensions include at least two of the following feature dimensions: Rich Header features, Nt Header features, Section features, import table features, export table features, resource table features, code segment features, DotNet features, AutoIt features, NSIS features, digital certificate signature features, string features, structural deformity features and file information entropy features.
3. The method according to claim 1 or 2, characterized in that: The extracting target feature data corresponding to each of the multiple target feature dimensions of the PE sample file includes: Determine a plurality of target feature dimensions corresponding to the PE sample file from the feature dimensions corresponding to the PE sample file; Target feature data corresponding to each of the multiple target feature dimensions are extracted.
4. The method according to claim 3, characterized in that The extracting target feature data corresponding to each of the plurality of target feature dimensions includes: Extracting a plurality of first feature data based on the target feature dimension according to a preset extraction rule; The plurality of first feature data are standardized and converted into a target data interval based on a preset mapping function; the target data interval includes a plurality of second feature data, and the second feature data correspond to the first feature data one by one; Based on the distribution trend and discreteness of the second feature in the target data interval, the target feature data corresponding to the target feature dimension is determined by a gradient algorithm.
5. The method according to claim 1, characterized in that The outputting the target detection evaluation result corresponding to the PE sample file based on the target feature data corresponding to each of the multiple target feature dimensions includes: Inputting the target feature data of the multiple target feature dimensions into the sub-models of the corresponding feature dimensions for detection and evaluation respectively, and obtaining detection results corresponding to the multiple target feature dimensions respectively; Based on the detection results corresponding to each of the multiple target feature dimensions, the target detection evaluation result corresponding to the PE sample file is determined.
6. A method for training a malware detection model, characterized in that: The method comprises: Obtain a plurality of PE sample files with known status labels; the status labels include malicious labels and non-malicious labels; Input the PE sample file into a malicious program detection model to obtain target feature data corresponding to each of the multiple target feature dimensions of the PE sample file, and output a prediction result corresponding to the PE sample file based on the target feature data corresponding to each of the multiple target feature dimensions; The malicious program detection model is updated based on the prediction result and status label corresponding to the PE sample file; the malicious program detection model is used to implement the malicious program detection method according to any one of claims 1-5.
7. A malicious program detection device, characterized in that: The device comprises: The first acquisition module is used to acquire the PE sample file; A detection module is used to input the PE sample file into a malicious program detection model, extract target feature data corresponding to each of multiple target feature dimensions of the PE sample file, and output a target detection evaluation result corresponding to the PE sample file based on the target feature data corresponding to each of the multiple target feature dimensions; the malicious program detection model is trained based on multiple PE sample files with known state labels; the state labels include malicious labels and non-malicious labels.
8. A training device for a malware detection model, characterized in that: The device comprises: A second acquisition module is used to acquire a plurality of PE sample files with known status labels; the status labels include malicious labels and non-malicious labels; A first training module is used to input the PE sample file into a malicious program detection model, obtain target feature data corresponding to each of the multiple target feature dimensions of the PE sample file, and output a prediction result corresponding to the PE sample file based on the target feature data corresponding to each of the multiple target feature dimensions; The second training module is used to update the malicious program detection model based on the prediction result and status label corresponding to the PE sample file; the malicious program detection model is used to implement the malicious program detection method as described in any one of claims 1-5.
9. A computer storage medium, characterized in that The computer storage medium stores a plurality of instructions, which are suitable for being loaded by a processor and executing the method steps according to any one of claims 1 to 6.
10. An electronic device, characterized in that: include: Processor and memory; The processor is connected to the memory; The memory is used to store executable program code; The processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to execute the method steps according to any one of claims 1 to 6.