Executable file characterization method and system for resisting aging of malicious software detection model
By using radare2 to extract the control flowchart and function call diagram of the executable file, and combining with the BERT model for feature extraction, the problem of rapid aging of the malware detection model in the prior art is solved, and more accurate and robust malware detection is achieved.
Patent Information
- Application Number
- CN202510184819.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-19
- Publication Date
- 2025-05-16
AI Technical Summary
Existing PE malware detectors tend to lose detection effects when facing malware variants, causing the model to age quickly.
By using radare2 to extract the functions and function call diagrams in the executable file, classify the functions into local functions and external functions, extract the basic blocks and control flow charts from the local functions, preprocess the assembly instructions and input the BERT model for feature extraction, and generate a multi-level feature representation.
It improves the richness and accuracy of feature expression, enhances the robustness of malware detection, realizes executable file characterization that resists the rapid aging of the malware detection model, and improves the detection effect.
Smart Images

Figure CN120012086A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to an executable file characterization method and system for resisting aging of malware detection models. Background Art
[0002] In recent years, with the development of artificial intelligence in various fields, especially the detection of malware has become a research hotspot, how to characterize executable programs in order to efficiently and accurately distinguish malware from benign software has become a key issue. However, for existing PE (Portable Executable) file detectors, while improving the detection rate, the durability of the detector is ignored.
[0003] The detection rate of the detector will decrease rapidly over time. Most of the existing PE malware detectors only consider the current malware features, and do not take into account the various variants of malware. They can easily lose their detection effect when facing malware variants. In previous studies, the detectors that use CFG (Control Flow Graph) to represent files often focus on the extraction of file structures. For example, various malware detectors based on GNN (Graph Neural Network) ignore the rich semantic information of the opcodes in the file and the connection between the contexts, causing some adversarial attacks against CFG to easily bypass the GNN detector, resulting in rapid aging of the model.
[0004] In view of the above analysis, the technical problems that need to be solved urgently in the existing technology are: most of the existing PE malware detectors only consider the current malware features, and do not consider the various variants of malware, and are likely to lose their detection effect when facing malware variants. Some adversarial attack methods against CFG can easily bypass the GNN detector, causing the model to age quickly. Summary of the invention
[0005] The present invention provides an executable file characterization method and system for resisting the aging of malware detection models, so as to solve the defects of rapid aging of malware detection models and poor detection effect in the prior art, realize the executable file characterization for resisting the rapid aging of malware detection models and improve the detection effect.
[0006] The present invention provides an executable file characterization method for resisting malware detection model aging, comprising:
[0007] Use radare2 to extract functions and function call graphs in the executable file to be detected, classify the functions into local functions and external functions, and extract basic blocks and control flow graphs from the local functions;
[0008] After preprocessing the assembly instructions in the basic block, input them into the BERT model for feature extraction to obtain a feature vector and a tag vector of the basic block;
[0009] The feature vector and the tag vector of the basic block and the control flow graph are used as the features of the local function, and the features of the local function and the function call graph are used as the features of the executable file to be detected, so as to use a malware detection model to detect whether there is malicious behavior based on the features of the executable file to be detected.
[0010] According to an executable file characterization method for resisting malware detection model aging provided by the present invention, the functions are classified into local functions and external functions, including:
[0011] Using the radare2 to classify the functions in the executable file to be detected, and obtaining the prefix name of the function;
[0012] The functions with prefix names of fcn and loc are regarded as the local functions, and the functions with prefix names other than fcn or loc are regarded as the external functions.
[0013] According to an executable file characterization method for resisting malware detection model aging provided by the present invention, the assembly instructions in the basic block are preprocessed and then input into the BERT model for feature extraction, including:
[0014] Performing vocabulary splitting on each statement of the assembly instruction;
[0015] If the address information obtained after splitting is greater than 0xfff, the address information is replaced with const;
[0016] Reorganize the split and replaced statements, and remove the preset instruction set in the assembly instructions;
[0017] The statements of two adjacent assembly instructions in the basic block are combined and input into the BERT model for feature extraction.
[0018] According to an executable file characterization method for resisting malware detection model aging provided by the present invention, before preprocessing the assembly instructions in the basic block and inputting them into the BERT model for feature extraction, the method further includes:
[0019] Use radare2 to extract the basic blocks of local functions in the executable file sample;
[0020] Preprocessing the assembly instructions of the basic blocks of the local functions in the executable file sample;
[0021] Combining two adjacent preprocessed assembly instruction statements in a basic block of a local function in the executable file sample as a single positive sample;
[0022] Keep the last statement in each training positive sample and replace it with a random statement in a random line of the next executable file sample as a single negative sample;
[0023] Deduplication processing is performed on the positive samples and negative samples as training data;
[0024] According to the longest sentence length in the training data, pad the sentences in the training data after deduplication processing to the same length to obtain final training data;
[0025] The BERT model is trained according to the final training data.
[0026] According to an executable file characterization method for resisting malware detection model aging provided by the present invention, the BERT model is trained according to the final training data, including:
[0027] Using the unique mapping relationship between binary and assembly instructions, a fixed-length word list is constructed, wherein the word list contains x86 opcodes, prefixes, ModRM, and all operands in the range of 0x0 to 0xfff except AVX, SSE, MMX, and FMA;
[0028] The BERT model is trained using the final training data and the vocabulary.
[0029] According to an executable file characterization method for resisting malware detection model aging provided by the present invention, before preprocessing the assembly instructions in the basic block and inputting them into the BERT model for feature extraction, the method further includes:
[0030] Use the MLM task and the CSP task to build the BERT model.
[0031] According to an executable file characterization method for resisting malware detection model aging provided by the present invention, the characteristics of the executable file to be detected also include the name, hash value and number of functions in the executable file to be detected.
[0032] According to the method for characterizing an executable file for resisting aging of a malware detection model provided by the present invention, after taking the features of the local function and the function call graph as the features of the executable file to be detected, the method further includes:
[0033] Calculating the similarity between the feature vector and the label vector of the basic block, and using the similarity as the weight of the basic block;
[0034] Taking the basic block as a node of the control flow graph, constructing a first graph neural network based on the control flow graph according to the edge information between the nodes of the control flow graph, adding the weight of the basic block to the node aggregation operation of the first graph neural network, and obtaining the characteristics of each node of the first graph neural network;
[0035] Taking the nodes of the first graph neural network as nodes, constructing a second graph neural network based on the function call graph according to the edge information corresponding to the nodes in the function call graph, and obtaining the feature representation of the executable file to be detected using the second graph neural network according to the features of the nodes;
[0036] A multi-layer perceptron is used to perform binary classification based on the feature representation of the executable file to be detected to detect whether there is malicious behavior.
[0037] The present invention also provides an executable file characterization system for resisting malware detection model aging, comprising:
[0038] A first extraction module is used to extract functions and function call graphs in the executable file to be detected using radare2, classify the functions into local functions and external functions, and extract basic blocks and control flow graphs from the local functions;
[0039] A second extraction module is used to pre-process the assembly instructions in the basic block and then input them into the BERT model for feature extraction to obtain a feature vector and a tag vector of the basic block;
[0040] A characterization module is used to use the feature vector and the tag vector of the basic block and the control flow graph as the features of the local function, and use the features of the local function and the function call graph as the features of the executable file to be detected, so as to detect whether there is malicious behavior using a malware detection model based on the features of the executable file to be detected.
[0041] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, an executable file characterization method for resisting malware detection model aging as described in any one of the above-mentioned methods is implemented.
[0042] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the above-described executable file characterization methods for resisting malware detection model aging.
[0043] The present invention also provides a computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the executable file characterization method for resisting malware detection model aging as described in any one of the above-mentioned methods.
[0044] The executable file characterization method and system for resisting the aging of the malware detection model provided by the present invention utilize radare2 to extract the control flow graph, function call graph and basic blocks of the executable file to be detected, and use the trained BERT model to construct a hierarchical graph to generate a multi-level feature representation, thereby improving the richness and accuracy of feature expression, enhancing the robustness of malware detection, realizing the executable file characterization that resists the rapid aging of the malware detection model, and improving the detection effect. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0046] Figure 1 It is one of the flow diagrams of the executable file characterization method for resisting malware detection model aging provided by the present invention;
[0047] Figure 2 This is the second flow chart of the executable file characterization method for resisting malware detection model aging provided by the present invention;
[0048] Figure 3 It is a schematic diagram of the overall structure of a PE feature file in the executable file characterization method for resisting malware detection model aging provided by the present invention;
[0049] Figure 4 It is a structural schematic diagram of a BERT model in an executable file characterization method for resisting malware detection model aging provided by the present invention;
[0050] Figure 5 It is a schematic diagram of the PE feature file formation process in the executable file characterization method for resisting malware detection model aging provided by the present invention;
[0051] Figure 6 It is a schematic diagram of the MLM task statement processing process in the executable file characterization method for resisting malware detection model aging provided by the present invention;
[0052] Figure 7 It is a complete flow chart of the executable file characterization method for resisting malware detection model aging provided by the present invention;
[0053] Figure 8 It is a schematic diagram of TPR comparison between the executable file characterization method for resisting malware detection model aging provided by the present invention and the baseline;
[0054] Fig. 9 It is a schematic diagram comparing the executable file characterization method for resisting malware detection model aging provided by the present invention with the baseline bACC;
[0055] Fig.10 It is a schematic diagram of the comparison of the F1 scores of the executable file characterization method for resisting malware detection model aging provided by the present invention and the baseline;
[0056] Fig.11 It is a structural schematic diagram of an executable file characterization system for resisting malware detection model aging provided by the present invention. DETAILED DESCRIPTION
[0057] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0058] Combine the following Figure 1 The present invention describes an executable file characterization method for resisting malware detection model aging, comprising:
[0059] Step 101, using radare2 to extract functions and function call graphs (FCGs) in the executable file to be detected, classifying the functions into local functions and external functions, and extracting basic blocks and control flow graphs (CFGs) from the local functions;
[0060] Step 102, pre-processing the assembly instructions in the basic block and inputting them into the BERT model for feature extraction to obtain the feature vector and label vector of the basic block;
[0061] Using radare2 disassembly tool, we extract assembly instructions based on the basic blocks of local functions in the file, and perform preprocessing on the extracted assembly instructions.
[0062] Step 103, taking the feature vector and the tag vector of the basic block and the control flow graph as the features of the local function, taking the features of the local function and the function call graph as the features of the executable file to be detected, so as to use the malware detection model to detect whether there is malicious behavior according to the features of the executable file to be detected.
[0063] Use radare2 to extract the CFG (control flow graph), FCG (function call graph) and basic blocks of the PE file to be detected, use the trained BERT model to build a hierarchical graph, and add additional information to finally represent the PE file.
[0064] like Figure 2 As shown, Radare2 is used to extract the functions and FCG (Function Call Graph) of the file, and the functions are classified based on the extracted functions into local functions and external functions. Based on the local functions, the basic blocks and CFG (Control Flow Graph) within the function are further extracted.
[0065] After preprocessing the statements of the basic block, they are input into the pre-trained BERT model. The 32-dimensional vector corresponding to the last layer of all the hidden layers in the output is extracted to obtain the feature vector of a single statement. The feature vectors of the entire basic block are integrated to obtain a matrix of 32 assembly code lines. The matrix is compressed into a 32-dimensional vector by averaging the matrix and used as the feature vector of the basic block. In addition, the [CLS] tag vector generated by the BERT model for the entire basic block is extracted, and both are used together with the CFG (control flow graph) as the features of a local function.
[0066] All local function features, together with FCG (function call graph), the number of functions in the file, function list, MD5 value of the function and other additional information are used as the features of the entire executable file to be detected. The feature structure of the executable file to be detected is as follows: Figure 3 As shown. The structure of the BERT model is as follows Figure 4 The feature formation process of the executable file to be detected is as follows Figure 5 shown.
[0067] According to the characteristics of the executable file to be detected, the malware detection model is used to detect whether there is malicious behavior. The second-order GraphSAGE can be used as the GNN model to train the malware detection model, and with the self-training BERT model, a layer of weighted aggregation and a layer of max-pooling aggregation are implemented to realize PE file feature extraction. This embodiment does not limit the type of malware detection model.
[0068] The main problem faced by existing malware detection methods is model aging. Over time, malware samples and behaviors continue to change, causing the performance of the detection model to degrade and fail to effectively identify new or variant malware. In addition, existing methods usually rely on static features or dynamic analysis, which can be easily bypassed by attackers.
[0069] This embodiment uses radare2 to extract the control flow graph, function call graph and basic blocks of the executable file to be detected, and uses the trained BERT model to construct a hierarchical graph to generate a multi-level feature representation, thereby improving the richness and accuracy of feature expression, enhancing the robustness of malware detection, and realizing executable file representation that resists the rapid aging of malware detection models, thereby improving detection effects.
[0070] Based on the above embodiment, in this embodiment, the functions are classified into local functions and external functions, including:
[0071] Using the radare2 to classify the functions in the executable file to be detected, and obtaining the prefix name of the function;
[0072] The functions with prefix names of fcn and loc are regarded as the local functions, and the functions with prefix names other than fcn or loc are regarded as the external functions.
[0073] Since malicious behaviors usually occur in local functions, feature extraction is only performed on local functions.
[0074] Based on the above embodiment, in this embodiment, the assembly instructions in the basic block are preprocessed and then input into the BERT model for feature extraction, including:
[0075] Performing vocabulary splitting on each statement of the assembly instruction;
[0076] If the address information obtained after splitting is greater than 0xfff, the address information is replaced with const;
[0077] Reorganize the split and replaced statements, and remove the preset instruction set in the assembly instructions;
[0078] The statements of two adjacent assembly instructions in the basic block are combined and input into the BERT model for feature extraction.
[0079] The single statement of the assembly instruction is split, and the address information exceeding 0xfff is replaced with "const". Some advanced instruction sets are also removed, such as AVX (Advanced Vector Extensions) instruction set, SSE (Streaming SIMD Extensions) series instruction set, MMX (Multi-Media Xtensions) instruction set, FMA (Fused Multiply-Add) instruction set, etc., to prevent the problem of too large a corpus when training the BERT model.
[0080] Adjacent sentences extracted from the basic block can be combined in the format of "sentence + TAB + sentence" and then input into the BERT model for feature extraction.
[0081] For example, to extract binary information from malware executable files using tools, you can use the third-party toolkit Radare2 to extract the opcode sequence, and use r2pipe in Python to control Radare2 to disassemble the executable file and extract the various information needed, and get the following information:
[0082]
[0083] The first column is the line number, the second column is the opcode address, the third column is the hexadecimal representation of the opcode, and the fourth column is the assembly language code, where the 1st to 2nd lines are a basic block, and the 3rd to 6th lines are considered the second basic block. The extracted assembly code is preprocessed, including splitting, replacing, and reorganizing.
[0084] First, the extracted assembly code is lexically split. For example, taking the assembly instruction "lea r8d,[rdx+2]", the irrelevant information before and after the statement is removed, and then the "," in the statement is removed. Finally, each part of the statement is identified and split. The results are "lea", "r8d", "[", "rdx", "+", "2", "]".
[0085] Secondly, considering that the vocabulary size should be considered when training the BERT model, and in the assembly code, there is a large amount of address information. During the compilation process of the code, a large amount of address information is usually placed in the assembly code, and then these address information will cause huge interference to the BERT model prediction, and greatly expand the size of the vocabulary, so after the splitting process, some excessive address information needs to be replaced. In this embodiment, the address information greater than 0xfff specifies specific function address information, that is, the address greater than 0xfff is replaced with "const". For example, the "jmp0x1400207bb" instruction in the second row is split into "jmp", "0x1400207bb", and becomes "jmp" and "const" after replacement. Similarly, for the "call fcn.140014c10" instruction in the sixth row, in the process of assembly, the function name will be mapped to address information, and it will also be split and replaced, and finally become "call" and "const".
[0086] Finally, the split and replaced sentences are reorganized. For example, the sentences in the split step are reorganized, and the words are separated by spaces, and the final complete sentence is "lear8d[rdx+2]".
[0087] Treat a line of assembly code as a statement, and construct the statement and the following statement in the basic block, forming a "statement\tstatement" format. For example, for the following basic block:
[0088]
[0089] After splitting, replacing and reorganizing the assembly code in lines 1 and 2, we get "mov ezxdword[eax]\tjmpconst\n".
[0090] Based on the above embodiment, this embodiment further includes:
[0091] Use radare2 to extract the basic blocks of local functions in the executable file sample;
[0092] Preprocessing the assembly instructions of the basic blocks of the local functions in the executable file sample;
[0093] Combining two adjacent preprocessed assembly instruction statements in a basic block of a local function in the executable file sample as a single positive sample;
[0094] Keep the last statement in each training positive sample and replace it with a random statement in a random line of the next executable file sample as a single negative sample;
[0095] Deduplication processing is performed on the positive samples and negative samples as training data;
[0096] According to the longest sentence length in the training data, pad the sentences in the training data after deduplication processing to the same length to obtain final training data;
[0097] The BERT model is trained according to the final training data.
[0098] The basic blocks of local functions in the executable file samples are preprocessed using the same method as the basic block preprocessing of the executable file to be detected. All the extracted statements in the basic block can be used as a single training sample in the format of "statement+TAB+statement". All the extracted training samples are evenly stored in 32 files, and all the samples in the files are deduplicated as positive samples for the BERT training model.
[0099] Based on the positive sample, a negative sample is constructed. The specific steps are as follows: retain the first sentence of the positive sample, select a random sentence in a random line of the next file for the second sentence, form a new single training sample as a negative sample, and remove duplicates from the training samples in the file as negative samples for the BERT training model.
[0100] All positive and negative samples are integrated into a total file, and the training samples in the file are deduplicated. The training samples are marked and made into json files to form the BERT model corpus. The longest sentence length in the training samples is obtained so that all sentences can be padded to the same length when training the model to ensure the normal progress of the training.
[0101] This embodiment uses the radare2 disassembly tool to extract assembly instructions in basic blocks and preprocess them to generate a malware corpus for training the BERT model, ensuring dynamic updating and diversity of the corpus.
[0102] Based on the above embodiment, in this embodiment, the BERT model is trained according to the final training data, including:
[0103] Using the unique mapping relationship between binary and assembly instructions, a fixed-length word list is constructed, wherein the word list contains x86 opcodes, prefixes, ModRM, and all operands in the range of 0x0 to 0xfff except AVX, SSE, MMX, and FMA;
[0104] The BERT model is trained using the final training data and the vocabulary.
[0105] Based on the above embodiment, this embodiment further includes:
[0106] Use the MLM task and the CSP task to build the BERT model.
[0107] Obtain the necessary parameter information required to train the BERT model from the BERT model corpus, that is, the sentence length of a single training sample. Use the necessary parameter information obtained to train the word segmenter required by BERT for the corpus.
[0108] Using the unique mapping relationship between binary and assembly instructions, a fixed-length vocabulary is constructed externally, and then the self-training BERT model is trained using self-constructed training samples and self-constructed vocabulary. The trained BERT model directly gives the feature vector of the basic block as the feature vector obtained by averaging the 32-dimensional vector output by the BERT model for a single sentence.
[0109] When training the BERT model, the MLM (Masked Language Model) task and the CSP (Context Statement Prediction) task are used to build the model in preparation for subsequent file representation.
[0110] Without using the general BERT pre-trained model, it is impossible to directly extract features from the instructions. First, the MLM task needs to be completed to allow the model to learn the connection between the semantics of words and context, help the model generate rich word representations, and capture the complex relationship between words and sentence structures.
[0111] Assume that the instruction consists of n tokens, that is, I = [i1,i2,i3...i n ], each token in the instruction will have a 15% probability of being replaced. If you choose i k There is an 80% chance that it will be replaced with [MASK], a 10% chance that it will be replaced with another token in the vocabulary, and a 10% chance that the original token will remain unchanged. The processing is as follows: Figure 6 As shown. Finally, the Softmax function is used to predict i k Predicted value of:
[0112]
[0113] in, For i k The predicted value, N is the size of the vocabulary, w m is the weight value of tokenm, is the parameter of the prediction model, indicating the vector dimension of the mapping, which is 32 in this model. is the corresponding vector of the last hidden layer of the model. The cross entropy loss function is:
[0114]
[0115] The CSP task of the BERT model uses the training data in the corpus to train the model to understand the relationship between sentence contexts, help the model understand the coherence and logical relationship between sentences, and improve its performance in cross-sentence tasks.
[0116] The input in the corpus is formatted, and the [CLS] tag is added to the front of the sentence pair. The "\t" in the middle of the sentence pair is replaced with the tag [SEP], and the tag [SEP] is added to the end of the sentence pair. After the data in the corpus is formatted, the entire sentence is converted into the input of the model through vocabulary embedding, position embedding, and paragraph embedding. After encoding the sentence, it is sent to the BERT model, and the vectors corresponding to all the words and tags in the last hidden layer are output. The vector corresponding to the tag [CLS] in the output is extracted and sent to the fully connected layer for a binary classification task to determine the connection between contexts and optimize the model based on the tags.
[0117] The [CLS] vector value of the sentence output is used to predict the relationship between contexts. The formula for predicting the context-related probability is:
[0118]
[0119] in, Is the predicted value of whether it is the context. Its cross loss function is:
[0120]
[0121] The BERT model generated after the MLM task and CSP task are completed will generate corresponding vectors based on the input sentence and its context.
[0122] This embodiment trains the BERT model through MLM and CSP tasks, which can capture the deep semantic relationship in the malware instruction sequence and enhance the model's ability to identify new and variant malware.
[0123] On the basis of the above embodiments, the characteristics of the executable file to be detected in this embodiment further include the name, hash value and number of functions in the executable file to be detected.
[0124] On the basis of the above embodiments, after taking the features of the local function and the function call graph as the features of the executable file to be detected, this embodiment further includes:
[0125] Calculating the similarity between the feature vector and the label vector of the basic block, and using the similarity as the weight of the basic block;
[0126] Taking the basic block as a node of the control flow graph, constructing a first graph neural network based on the control flow graph according to the edge information between the nodes of the control flow graph, adding the weight of the basic block to the node aggregation operation of the first graph neural network, and obtaining the characteristics of each node of the first graph neural network;
[0127] Taking the nodes of the first graph neural network as nodes, constructing a second graph neural network based on the function call graph according to the edge information corresponding to the nodes in the function call graph, and obtaining the feature representation of the executable file to be detected using the second graph neural network according to the features of the nodes;
[0128] A multi-layer perceptron is used to perform binary classification based on the feature representation of the executable file to be detected to detect whether there is malicious behavior.
[0129] The basic block is regarded as the node of CFG, and the cosine similarity is calculated between the vector of the basic block and the [CLS] label vector. The obtained value is added to the node aggregation operation of GNN as the weight value of the basic block. Then, based on the edge information in CFG, GraphSAGE is selected as the GNN model to construct the first graph neural network based on CFG.
[0130] The nodes in the first graph neural network are used as nodes, and the edge information in FCG is used to build a second graph neural network based on FCG. The function name, hash value, and number of functions are added to the feature file for malware detection. The complete flowchart is as follows: Figure 7 shown.
[0131] For the feature calculation of CFG (control flow graph), the direction and strength of information flow transmission are dynamically adjusted through the similarity between the feature vector of the basic block and the [CLS] tag vector. The similarity calculation formula between [CLS] and the basic block feature is:
[0132]
[0133] The final similarity calculation value range is [-1,1]. If the similarity is closer to 1, it means that the basic block is more similar to the self-trained BERT model corpus, and the weight is higher; if the similarity is closer to 0, it means that the basic block is less similar to the self-trained BERT model corpus, and the weight is lower; if the similarity is closer to -1, it means that the semantics of the basic block and the self-trained BERT model corpus are completely opposite, indicating that the basic block may be tampered with and needs special attention.
[0134] For a target node v in CFG (control flow graph), its neighbor node set is N(v). For each neighbor node u of v, the weight is calculated by the similarity formula, and the weight is sent to the softmax function for normalization and converted to w(u). Then, the original average neighbor aggregation of GraphSAGE is abandoned and replaced with weighted neighbor aggregation. The calculation formula for calculating the feature representation of node v at the kth layer is:
[0135]
[0136] in, is the feature representation of the target node v at the k-1 layer, is the feature representation of neighbor node u at the k-1 layer, W k is the linear transformation matrix of the kth layer, and σ is the ReLU activation function.
[0137] Among them, the conversion formula of w(u) is:
[0138]
[0139] Finally, the top-level vector is output and input into the FCG (Function Call Graph) as function-level features.
[0140] For the feature calculation of FCG (function call graph), the feature input has been generated for each node of FCG. In order to emphasize the most important neighbor nodes, GraphSAGE with max-pooling is used for calculation. The calculation formula is:
[0141]
[0142] Finally, the top-level vector is output as the feature representation of the entire PE file level.
[0143] Finally, MLPs (Multi-layer Perceptrons) are used to perform binary classification on the feature representation of PE files, and finally the probability of detecting malware is given.
[0144] By calculating the similarity between the basic block features and the [CLS] label, the importance of the basic block is automatically determined. The closer the weight is to 1, the greater the weight is, the closer it is to 0, the smaller the weight is, and the closer it is to -1, the more likely the basic block is to be tampered with, thus achieving automated weighted aggregation and risk judgment.
[0145] The PE file representation method proposed in this embodiment utilizes the characteristics of GNN itself to filter out certain malware that adds random character disturbances during the feature extraction stage. At the same time, when selecting the GNN model, it fully considers the problem of reduced detector detection rate caused by adversarial attacks and selects a GNN type that can aggregate nearby nodes, thereby preventing criminals from confusing the detector by tampering with the CFG of the PE file.
[0146] After the successful application of the present invention, the service life of the GNN-based detector can be greatly enhanced, thereby reducing the computing power spent by users on repeated training, and can fill the domestic technical gap in extending the use of malware detectors on the Windows platform.
[0147] In summary, the present invention uses self-training BERT to characterize the feature values within the basic block based on the representation of the file in a hierarchical graph, which can fully exploit the detection performance of the model to the maximum extent, thereby achieving the effect of resisting model aging.
[0148] The specific application fields of the present invention can cover the following aspects:
[0149] 1. Cybersecurity
[0150] Enterprise network security: Deploy malware detection systems in enterprise networks to protect internal networks and data security and prevent data leakage and business interruption caused by malware attacks.
[0151] Government and public institutions: Deploy malware detection systems in government networks and public service systems to ensure the security of government data and public service systems.
[0152] 2. Anti-Virus Software
[0153] Personal Computers and Mobile Devices: Develop advanced anti-virus software based on GNN and BERT for malware detection and protection on personal computers and mobile devices.
[0154] Enterprise-level security solution: Provides enterprise-level anti-virus solutions to protect all terminal devices in the enterprise network from malware attacks.
[0155] 3. Intrusion Detection System (IDS)
[0156] Network traffic analysis: Integrate malware detection capabilities into the network traffic monitoring system to detect and prevent malware propagation in real time by analyzing incoming and outgoing network packets.
[0157] Advanced Threat Protection (ATP): Combined with advanced threat protection system, it provides more granular malware detection and response capabilities.
[0158] 4. Cloud Security
[0159] Cloud Service Providers: Provide malware detection services to cloud service providers to protect virtual machines and containers in cloud environments from malware attacks.
[0160] Cloud Security Gateway: Integrate malware detection capabilities into the cloud security gateway to protect the security of cloud applications and data.
[0161] 5. Internet of Things (IoT) Security
[0162] Smart devices and sensors: Integrate malware detection capabilities in smart devices and IoT sensors to prevent malware attacks from causing device failures and data leaks.
[0163] Industrial Control Systems (ICS): Protect critical equipment and networks in industrial control systems to prevent production disruptions and security incidents caused by malware attacks.
[0164] Through the description of the above specific application fields and related products, the practical application value and broad application prospects of the invention can be more clearly demonstrated.
[0165] The present invention has achieved some positive effects during the research and development or use process, and has great advantages over the prior art. The following content is described in conjunction with data, charts, etc. of the experimental process.
[0166] All experimental data samples of the present invention are shown in Table 1. All malicious software is downloaded from VirusShare by year, and all benign software is downloaded from software download sites and identified by VirusTotal, and classified according to the year when the software was first identified.
[0167] Table 1 Dataset introduction
[0168]
[0169] MalConv-1 is a deep learning-based malware detection model developed by the Endgame research team that is designed to detect malware by analyzing the binary content of files, rather than relying on traditional feature engineering or signature matching methods.
[0170] MalConv-2 is an improved version of MalConv-1, which aims to further improve the performance and accuracy of malware detection. Compared with the original MalConv-1 model, MalConv-2 is optimized in terms of model architecture, feature extraction, and processing capabilities.
[0171] MalGraph is a malware detection method based on graph neural networks. It uses graph structures to represent and analyze the behaviors and relationships of malware, thereby achieving more accurate and efficient detection.
[0172] The experiment uses four indicators to judge the model, namely TPR (True Positive Rate, recall rate), bACC (Balanced Accuracy, balanced accuracy), F1 score (F1 Score) and AUT metric (verification of the aging degree of the model). The formulas of the four indicators are:
[0173]
[0174] Among them, f in AUT is the performance indicator. In this experiment, the F1 score is used as the benchmark performance indicator.
[0175] After each model is trained using the training set, the trained model is directly validated on the validation set from 2020 to 2023 to calculate all its performance indicators.
[0176] The performance indicators of several models are shown in Table 2, Table 3, and Figures 8 to 10 As shown in the experiment, it can be found that compared with the baseline model, the aging speed of the model of the present invention is significantly reduced, and the durability of the model is improved.
[0177] Table 2 Experimental indicators recall rate, balanced accuracy and F1 score
[0178]
[0179] Table 3 Experimental indicators F1 score and AUT
[0180] 2020 2021 2022 2023 AUT The present invention 0.9660 0.8775 0.8496 0.8081 0.8714 Malconv-1 0.9552 0.8216 0.7399 0.6636 0.7903 Malconv-1 0.9624 0.8101 0.7890 0.7702 0.8218 MalGraph 0.9398 0.8262 0.8010 0.7225 0.8194
[0181] The following is a description of the executable file characterization system for resisting malware detection model aging provided by the present invention. The executable file characterization system for resisting malware detection model aging described below and the executable file characterization method for resisting malware detection model aging described above can be referenced to each other.
[0182] like Fig.11 As shown, the system includes a first extraction module 1101, a second extraction module 1102 and a characterization module 1103, wherein:
[0183] The first extraction module 1101 is used to use radare2 to extract functions and function call graphs in the executable file to be detected, classify the functions into local functions and external functions, and extract basic blocks and control flow graphs from the local functions;
[0184] The second extraction module 1102 is used to pre-process the assembly instructions in the basic block and then input them into the BERT model for feature extraction to obtain the feature vector and label vector of the basic block;
[0185] The characterization module 1103 is used to use the feature vector and label vector of the basic block and the control flow graph as the features of the local function, and use the features of the local function and the function call graph as the features of the executable file to be detected, so as to use the malware detection model to detect whether there is malicious behavior based on the features of the executable file to be detected.
[0186] This embodiment uses radare2 to extract the control flow graph, function call graph and basic blocks of the executable file to be detected, and uses the trained BERT model to construct a hierarchical graph to generate a multi-level feature representation, thereby improving the richness and accuracy of feature expression, enhancing the robustness of malware detection, and realizing executable file representation that resists the rapid aging of malware detection models, thereby improving detection effects.
[0187] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for representing executable files to resist aging of malware detection models, characterized in that: include: Use radare2 to extract functions and function call graphs in the executable file to be detected, classify the functions into local functions and external functions, and extract basic blocks and control flow graphs from the local functions; After preprocessing the assembly instructions in the basic block, input them into the BERT model for feature extraction to obtain a feature vector and a tag vector of the basic block; The feature vector and the tag vector of the basic block and the control flow graph are used as the features of the local function, and the features of the local function and the function call graph are used as the features of the executable file to be detected, so as to use a malware detection model to detect whether there is malicious behavior based on the features of the executable file to be detected.
2. The executable file characterization method for resisting malware detection model aging according to claim 1, characterized in that: The functions are classified into local functions and external functions, including: Using the radare2 to classify the functions in the executable file to be detected, and obtaining the prefix name of the function; The functions with prefix names of fcn and loc are regarded as the local functions, and the functions with prefix names other than fcn or loc are regarded as the external functions.
3. The executable file characterization method for resisting malware detection model aging according to claim 1, characterized in that: The assembly instructions in the basic block are preprocessed and then input into the BERT model for feature extraction, including: Performing vocabulary splitting on each statement of the assembly instruction; If the address information obtained after splitting is greater than 0xfff, the address information is replaced with const; Reorganize the split and replaced statements, and remove the preset instruction set in the assembly instructions; The statements of two adjacent assembly instructions in the basic block are combined and input into the BERT model for feature extraction.
4. The executable file characterization method for resisting malware detection model aging according to claim 3, characterized in that: After preprocessing the assembly instructions in the basic block, before inputting them into the BERT model for feature extraction, it also includes: Use radare2 to extract the basic blocks of local functions in the executable file sample; Preprocessing the assembly instructions of the basic blocks of the local functions in the executable file sample; Combining two adjacent preprocessed assembly instruction statements in a basic block of a local function in the executable file sample as a single positive sample; Keep the last statement in each training positive sample and replace it with a random statement in a random line of the next executable file sample as a single negative sample; Deduplication processing is performed on the positive samples and negative samples as training data; According to the longest sentence length in the training data, pad the sentences in the training data after deduplication processing to the same length to obtain final training data; The BERT model is trained according to the final training data.
5. The executable file characterization method for resisting malware detection model aging according to claim 4, characterized in that: Training the BERT model according to the final training data includes: Using the unique mapping relationship between binary and assembly instructions, a fixed-length word list is constructed, wherein the word list contains x86 opcodes, prefixes, ModRM, and all operands in the range of 0x0 to 0xfff except AVX, SSE, MMX, and FMA; The BERT model is trained using the final training data and the vocabulary.
6. The method for characterizing executable files against malware detection model aging according to any one of claims 1 to 5, characterized in that: After preprocessing the assembly instructions in the basic block, before inputting them into the BERT model for feature extraction, it also includes: Use the MLM task and the CSP task to build the BERT model.
7. The method for characterizing executable files to resist malware detection model aging according to any one of claims 1 to 5, characterized in that: The characteristics of the executable file to be detected also include the name, hash value and number of functions in the executable file to be detected.
8. The method for characterizing executable files to resist malware detection model aging according to any one of claims 1 to 5, characterized in that: After taking the features of the local function and the function call graph as the features of the executable file to be detected, the method further includes: Calculating the similarity between the feature vector and the label vector of the basic block, and using the similarity as the weight of the basic block; Taking the basic block as a node of the control flow graph, constructing a first graph neural network based on the control flow graph according to the edge information between the nodes of the control flow graph, adding the weight of the basic block to the node aggregation operation of the first graph neural network, and obtaining the characteristics of each node of the first graph neural network; Taking the nodes of the first graph neural network as nodes, constructing a second graph neural network based on the function call graph according to the edge information corresponding to the nodes in the function call graph, and using the second graph neural network to obtain a feature representation of the executable file to be detected according to the features of the nodes; A multi-layer perceptron is used to perform binary classification based on the feature representation of the executable file to be detected to detect whether there is malicious behavior.
9. An executable file characterization system for resisting malware detection model aging, characterized in that: include: A first extraction module is used to extract functions and function call graphs in the executable file to be detected using radare2, classify the functions into local functions and external functions, and extract basic blocks and control flow graphs from the local functions; A second extraction module is used to pre-process the assembly instructions in the basic block and then input them into the BERT model for feature extraction to obtain a feature vector and a tag vector of the basic block; A characterization module is used to use the feature vector and the tag vector of the basic block and the control flow graph as the features of the local function, and use the features of the local function and the function call graph as the features of the executable file to be detected, so as to detect whether there is malicious behavior using a malware detection model based on the features of the executable file to be detected.
10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the executable file characterization method for resisting malware detection model aging as described in any one of claims 1 to 8 is implemented.