APT organization malicious code defense method based on prior knowledge guided adversarial training
By introducing an adversarial training method based on prior knowledge in malware detection, using GAN to generate adversarial samples and using PGD optimization algorithms, the problems of data imbalance, adversarial attacks and insufficient model robustness of malware detection in APT attacks are solved, and the detection performance and robustness are significantly improved.
Patent Information
- Application Number
- CN202510008578.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-03
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-01-03
AI Technical Summary
Existing malware detection technologies show problems such as data imbalance, adversarial attacks and insufficient model robustness when facing APT attacks, resulting in poor detection results.
Adversarial training method based on prior knowledge is adopted, by introducing prior knowledge of malicious code family labels, the adversarial samples are generated using Generative Adversarial Network (GAN), and through weighted random sampling technology and projection gradient descent (PGD) optimization algorithm, the generation process of adversarial samples is targeted to improve the robustness and detection performance of the model.
It significantly improves the detection performance of the model in the scenario of handling code label imbalance, especially the recognition ability of a few types of codes, and enhances the robustness of the model and the detection ability of unknown malware.
Smart Images

Figure CN120068069A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of machine learning, and particularly relates to a method for defending against APT organization malicious code based on prior knowledge-guided adversarial training. Background Art
[0002] With the rapid development of Internet technology and the acceleration of global digital transformation, the network security situation has become increasingly severe. In particular, the emergence of Advanced Persistent Threat (APT) attacks has brought unprecedented challenges to the information security of countries, enterprises, and individuals. APT attacks are known for their high concealment, clear target orientation, and persistence. They aim to penetrate into the target network through a series of complex attack steps to steal sensitive information or damage critical facilities. Such attacks may last for months to years to achieve long-term intelligence collection or strategic destruction purposes.
[0003] Although important breakthroughs have been made in malware detection in recent years using deep learning and machine learning technologies, effective prevention against APT attacks still faces huge challenges. Existing malware detection technologies mainly rely on static analysis (based on known malware features) and dynamic analysis (based on the behavior patterns of malware). These methods show obvious limitations when facing APT attacks:
[0004] Data imbalance problem: Due to its uniqueness and customization characteristics, APT malware often appears as a minority class in the training dataset. This causes most traditional machine learning algorithms to tend to prioritize identifying the more numerous common malware classes, while ignoring the important but rare class of APT malware, thus weakening the detection effect.
[0005] Adversarial attacks: APT attackers will deliberately create adversarial samples that can bypass existing detection mechanisms. These samples can successfully evade detection in specific situations, increasing the difficulty of identification.
[0006] Insufficient model robustness: Current malware detection models show certain vulnerability when dealing with the continuous innovation and variant strategies of APT attackers. Attackers only need to make minor modifications to the malicious code to render the detection model ineffective, affecting the stability and reliability of the system.
[0007] In view of the above problems, researching and developing a more efficient, accurate, and highly adaptable APT malware detection system has become an urgent need in the field of network security. This requires not only innovation at the algorithm level but also improvements in multiple aspects such as data collection, model training, and practical applications to comprehensively enhance the overall effectiveness of the APT attack defense system. Summary of the Invention
[0008] The main purpose of the present invention is to overcome the disadvantages and deficiencies of the prior art, and provide an APT organization malicious code defense method based on prior knowledge-guided adversarial training. By introducing the prior knowledge of malicious code family tags, it can effectively cope with the challenge of unbalanced distribution of APT malicious code tags, making the malicious code detection model perform better in identifying customized and concealed malicious codes.
[0009] To achieve the above object, the present invention adopts the following technical solutions:
[0010] In the first aspect, the present invention provides an APT organization malicious code defense method based on prior knowledge-guided adversarial training, including the following steps:
[0011] Clean and preprocess the obtained malicious code samples to obtain original samples, and extract the distribution information of malicious code tags; the malicious code samples include malicious codes and benign codes.
[0012] Based on the distribution information of malicious code tags, calculate the frequency of each tag appearing in the dataset, and use the frequency as prior knowledge for subsequent adversarial training.
[0013] During the adversarial training process, select the tags that are more likely to be misclassified as target tags according to the distribution information of malicious code tags, and determine the sampling frequency of target tags according to the occurrence frequency of tags through weighted random sampling technology, so as to specifically guide the generation process of adversarial samples.
[0014] Use the generative adversarial network GAN to generate adversarial samples; the generative adversarial network GAN includes a generator G and a discriminator D. The generator G adopts a convolutional neural network CNN structure, and the discriminator D adopts a multi-layer perceptron MLP structure; generate samples with specific perturbations through adversarial training, and the samples with specific perturbations will guide the model to produce incorrect classification results.
[0015] Use the generated adversarial samples and the original samples as the training set for training to obtain a malicious code detection model. The training objective is to minimize the weighted combination of the standard loss and the adversarial loss, and realize the defense against malicious code attacks based on the malicious code detection model.
[0016] As a preferred technical solution, the obtaining of malicious code samples, cleaning and preprocessing, and extracting the distribution information of malicious code tags are specifically as follows:
[0017] Clean the data of the obtained malicious code samples to remove noise and invalid samples.
[0018] Input the malicious code and benign code datasets into the sandbox for preprocessing, and extract the JSON information of the apistat part regarding API call information, specifically including:
[0019] First, extract all the dynamically called APIs from the dataset and generate a set that contains M API call elements;
[0020] Then, convert the API calls into feature vectors through one-hot encoding;
[0021] Next, use the random forest algorithm to perform binary classification on the data in the training set, and select the top m features with the largest weights as the final feature set according to feature importance.
[0022] As a preferred technical solution, based on the distribution information of malicious code labels, calculate the frequency of each label appearing in the dataset, specifically:
[0023] In the data preprocessing stage, count the number of occurrences of each label in the dataset, and calculate the occurrence frequency of each label based on the total number of samples as prior knowledge for subsequent adversarial training. The specific calculation formula is:
[0024]
[0025] where count(c i ) is the number of occurrences of label c i , and n is the total number of samples.
[0026] As a preferred technical solution, in adversarial training, the sampling frequency of labels is expressed as follows:
[0027]
[0028] where P(y t = c i ) represents the probability that the target label c i is selected, and f(c i ) represents the frequency of label c i appearing in the dataset.
[0029] As a preferred technical solution, during the training process of GAN, the generator G and the discriminator D are alternately trained through multiple iterations. The goal of the generator G is to generate realistic samples to deceive the discriminator, while the goal of the discriminator D is to distinguish real samples from generated samples;
[0030] The loss L G function of the generator consists of an adversarial loss and a reconstruction loss, and is expressed as follows:
[0031] L G = Ez~p(z) [-logD(G(z))] + αE x~p(x) [||x - G(z)||]
[0032] Among them, the adversarial loss part is E z~p(z) [-logD(G(z))] makes the generator output to confuse the discriminator; the reconstruction loss part E x~p(x) [||x - G(z)||] then makes the generated samples closer to the original samples by minimizing the deviation between the input and the output in the data space. The parameter α is a hyperparameter controlling the weight, and z represents the noise vector;
[0033] The loss function L of the discriminator D is designed as follows:
[0034] L D = -E x~p(x) [logD(x)] - E z~p(z) [1 - log(1 - D(G(z)))] + β|E x~p(x) [y] - E z~p(z) [D(G(z))]|
[0035] Among them, D(x) represents the probability prediction of the discriminator D that the input sample x is a real sample, and the value range is (0, 1). The closer it is to 1, the more certain the discriminator is that the sample is a real sample; G(z) represents the sample generated after the generator G inputs the random noise z, z ∼ p(z) represents the distribution of the noise Z, and E x~p(x) [logD(x)] represents the expectation of the samples in the real sample set p(x), and the goal is to maximize this value to make the discriminator better identify real samples; E z~p(z) [1 - log(1 - D(G(z)))] represents the expectation of the generated sample set G(z), and the goal is to minimize this value to make the discriminator better distinguish between generated samples and real samples; E x~p(x) [y] represents the expected value of the label of the real sample x, which is used to measure whether the discriminator can accurately predict that the real sample is 1; E z~p(z) [D(G(z))] represents the expected value that the generated sample G(z) is predicted as a real sample by the discriminator. This term is used to evaluate the discriminator's judgment ability for generated samples; β represents the coordination weight; |E x~p(x) [y] - E z~p(z) [D(G(z))]| represents the auxiliary discriminator consistency regularization term, which is used to ensure the consistency of the discriminator output, that is, the distribution prediction values of real samples and generated samples as a whole are consistent with the expected values;
[0036] The loss function L of the discriminator DThe ability to discriminate real samples and the ability to identify generated samples are both considered, and a regularization term that aids in the consistency between the discriminator's output and its own output is added, where β is the coordination weight.
[0037] As a preferred technical solution, during the process of generating adversarial samples, the projected gradient descent (PGD) optimization algorithm is used for updating, and adversarial samples with perturbations in a specific direction are generated based on the target label, causing the model's prediction to shift towards the target label direction.
[0038] As a preferred technical solution, the standard loss L std is the cross-entropy loss, and its calculation formula is as follows:
[0039]
[0040] where y i represents the actual label of the sample x i ; f(x i ; θ) represents the predicted probability of the malicious code detection model;
[0041] The adversarial loss L adv is calculated from the adversarial samples as follows:
[0042]
[0043] where represents the generated adversarial sample, represents the target label of the adversarial sample; represents the predicted probability distribution of the malicious code detection model for the input sample x i ; it is the output result of the model;
[0044] The final training loss function is a weighted combination of the standard loss L std and the adversarial loss L adv :
[0045] L total = L std + λL adv
[0046] where λ is a hyperparameter that controls the trade-off between the standard loss and the adversarial loss.
[0047] In a second aspect, the present invention provides an APT organization malicious code defense system based on prior knowledge-guided adversarial training, which is applied to the APT organization malicious code defense method based on prior knowledge-guided adversarial training, and includes a data acquisition module, a prior knowledge acquisition module, a target label selection module, an adversarial sample generation module, and a model training module;
[0048] The data acquisition module is used to clean and preprocess the obtained malicious code samples as original samples, and extract the distribution information of malicious code tags; the malicious code samples include malicious code and benign code;
[0049] The prior knowledge acquisition module is used to calculate the frequency of each tag appearing in the dataset based on the distribution information of malicious code tags, and the frequency is used as prior knowledge for subsequent adversarial training;
[0050] The target tag selection module is used to select tags that are more likely to be misclassified as target tags according to the distribution information of malicious code tags during the adversarial training process, and determine the sampling frequency of the target tags according to the occurrence frequency of the tags through weighted random sampling technology, so as to specifically guide the generation process of adversarial samples;
[0051] The adversarial sample generation module is used to generate adversarial samples using the generative adversarial network GAN; the generative adversarial network GAN includes a generator G and a discriminator D, the generator G adopts a convolutional neural network CNN structure, and the discriminator D adopts a multi-layer perceptron MLP structure; samples with specific perturbations are generated through adversarial training, and the samples with specific perturbations will lead the model to produce incorrect classification results;
[0052] The model training module is used to train the generated adversarial samples and the original samples as a training set to obtain a malicious code detection model. The training objective is to minimize the weighted combination of the standard loss and the adversarial loss, and realize the defense against malicious code attacks based on the malicious code detection model.
[0053] In a third aspect, the present invention provides an electronic device, and the electronic device includes:
[0054] At least one processor; and,
[0055] A memory communicatively connected to the at least one processor; wherein,
[0056] The memory stores computer program instructions executable by the at least one processor, and the computer program instructions are executed by the at least one processor so that the at least one processor can execute the APT organization malicious code defense method based on prior knowledge-guided adversarial training.
[0057] In a fourth aspect, the present invention provides a computer-readable storage medium storing a program, and when the program is executed by a processor, the APT organization malicious code defense method based on prior knowledge-guided adversarial training is implemented.
[0058] Compared with the prior art, the present invention has the following advantages and beneficial effects:
[0059] 1. Improve the detection performance of minority classes: By introducing the prior knowledge of APT malicious code tags, the present invention guides the adversarial training process, thereby significantly improving the detection performance of the model in the scenario of unbalanced code tags, especially the recognition ability of minority-class codes.
[0060] 2. Make full use of prior knowledge: By extracting the label distribution information of APT malicious codes from the training data, this method can make full use of prior knowledge. This frequency-based prior knowledge can provide strong guidance for adversarial sample generation and target label selection, thereby more specifically exposing the weaknesses of the model on minority-class labels.
[0061] 3. Effectiveness of generating adversarial samples: By using the generative adversarial network (GAN) and the projected gradient descent (PGD) algorithm, this method can generate highly realistic adversarial samples. The two-way adversarial training of GAN ensures the authenticity and diversity of the generated samples, while the PGD algorithm ensures the effectiveness of the adversarial samples, making the model show stronger robustness when facing these adversarial samples.
[0062] 4. Enhance the robustness of the model: Through targeted adversarial perturbation generation, the model can effectively cope with the unbalanced distribution of APT malicious codes during training, thereby reducing the misclassification rate and enhancing the detection ability for unknown malware. Description of the Drawings
[0063] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0064] Figure 1 It is a flowchart of the APT organization malicious code defense method based on prior knowledge-guided adversarial training according to the embodiment of the present invention;
[0065] Figure 2 It is a block diagram of the APT organization malicious code defense system based on prior knowledge-guided adversarial training according to the embodiment of the present invention.
[0066] Figure 3 It is a structural diagram of the electronic device according to the embodiment of the present invention. Detailed Embodiments
[0067] To enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of this application.
[0068] In this application, the mention of "embodiment" means that the specific features, structures or characteristics described in connection with the embodiment may be included in at least one embodiment of this application. The phrase appears in various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described in this application can be combined with other embodiments.
[0069] The malicious code used by APT organizations usually has the following characteristics:
[0070] 1. Highly customized: These malicious codes are often tailored for specific targets, have the ability to survive in specific environments, and are significantly different from traditional general malicious software.
[0071] 2. Strong concealment: In order to avoid security detection, APT malicious codes usually adopt various technical means, such as encryption, obfuscation, staged loading, etc., making it difficult to be discovered by traditional protection measures.
[0072] 3. Diversified and frequent variants: APT malicious codes are often updated or have variants to avoid detection rules or signature libraries, making it difficult for traditional detection methods based on feature matching to effectively identify.
[0073] Please refer to Figure 1 , a method for defending against APT organization malicious code based on prior knowledge-guided adversarial training provided in this embodiment, includes the following steps:
[0074] S1. Data collection and cleaning, specifically:
[0075] S11. Collect a large number of malicious software samples and their corresponding code tags from multiple channels (such as static analysis, dynamic analysis, file signatures, etc.);
[0076] S12. Clean the collected data, remove noise and invalid samples, and ensure the accuracy and consistency of the data. This step can be automated through programming scripts to improve efficiency.
[0077] S13. Data preprocessing: Input the malware and benign software datasets into Cuckoo Sandbox, and extract the JSON information of the apistat part regarding API call information. To construct a feature space with a fixed dimension m:
[0078] First, extract all dynamic call APIs from the dataset and generate a set containing M API call elements;
[0079] Then, convert these API calls into feature vectors through One-hot encoding.
[0080] Finally, use the random forest algorithm to perform binary classification on the data in the training set, and select the top m features with the largest weights according to feature importance as the final feature set. The final feature set is the core data basis for subsequent steps, including guiding the generation of adversarial samples, where the generator and discriminator generate and distinguish samples based on the final feature set; providing the training input for the malware detection model; supporting the selection of target labels, and based on the final feature set, statistically analyzing the label distribution frequency for guiding the selection of target labels for weighted random sampling.
[0081] It can be understood that the above-cleaned and preprocessed data, as the original samples, including the cleaned malware samples and benign software samples, after feature extraction and feature screening, are used as the basic samples for model training, for subsequent adversarial sample generation and model training.
[0082] S2. Obtain prior knowledge;
[0083] Specifically, extract the label distribution information of malware from the training dataset of the malware detection task. Through statistical analysis, calculate the frequency of each code label appearing in the training dataset, and use it as prior knowledge. These label frequencies can reflect the distribution of each malware in the dataset, providing data support for subsequent target label selection and adversarial perturbation generation.
[0084] The prior knowledge introduced in the present invention directly reflects the imbalance of label distribution in the training dataset, guiding the adversarial sample generation process to be more optimized for minority class labels. By using the label frequency as the sampling basis for target labels, the generation of adversarial samples better meets the need to expose the weaknesses of the real data distribution, thus significantly enhancing the adaptability of the model to minority class labels.
[0085] The adversarial training strategy guided by prior knowledge is the main difference from conventional adversarial sample generation methods. Traditional adversarial training usually randomly generates adversarial samples without considering label distribution, while the present invention generates adversarial samples directionally through prior knowledge, improving the pertinence and sample efficiency of the training process.
[0086] S3. Target label selection;
[0087] In each adversarial training, first, a target label is sampled from the malicious code label set. The target label is different from the actual label of the current sample, and its sampling probability is based on its frequency of occurrence in the training dataset. The sampling process can be achieved through weighted random sampling techniques, where the weight of each label is proportional to its frequency of occurrence. This process aims to utilize the label distribution information of malicious code, select target labels that are more likely to be misclassified, and thus guide the generation of adversarial perturbations, making the model pay more attention to these error-prone minority class labels during training.
[0088] Furthermore, in adversarial training, the sampling frequency of the label is expressed as follows:
[0089]
[0090] where P(y t =c i ) represents the probability that the target label c i is selected, and f(c i ) represents the frequency of occurrence of the label c i in the dataset.
[0091] S4. Generation of adversarial samples;
[0092] Use a generative adversarial network (GAN) to construct adversarial samples. The generative adversarial network consists of two parts: a generator (G) and a discriminator (D). The generator (G) model adopts a convolutional neural network (CNN) structure, and the discriminator (D) model adopts a multi-layer perceptron (MLP) structure.
[0093] During the training process of the GAN, the generator G and the discriminator D are alternately trained through multiple iterations. The goal of the generator is to generate realistic samples to deceive the discriminator, while the goal of the discriminator is to distinguish real samples from generated samples.
[0094] Furthermore, the loss function of the generator consists of an adversarial loss and a reconstruction loss:
[0095] L G =E z~p(z) [-logD(G(z))]+αE x~p(x) [||x - G(z)||]
[0096] where the adversarial loss part E z~p(z) [-logD(G(z))] makes the generator output deceive the discriminator; the reconstruction loss part E x~p(x) [||x - G(z)||] makes the generated samples closer to the original samples by minimizing the deviation between the input and the output in the data space. The parameter α is a hyperparameter that controls the weight, and z represents the noise vector.
[0097] Furthermore, the loss function of the discriminator is designed as follows:
[0098] L D = -E x~ p (x) [log D(x)] - E z~p(z) [1 - log(1 - D(G(z)))] + β|E x~p(x) [y] - E z~p(z) [D(G(z))]|
[0099] where D(x) represents the probability prediction of the discriminator D that the input sample x is a real sample, and its value range is (0, 1). The closer it is to 1, the more certain the discriminator is that the sample is a real sample; G(z) represents the sample generated after the generator G inputs the random noise z, and z ∼ p(z) represents the distribution of the noise Z. E x~p(x) [log D(x)] represents the expectation of the samples in the real sample set p(x), and the goal is to maximize this value to make the discriminator better identify real samples; E z~p(z) [1 - log(1 - D(G(z)))] represents the expectation of the generated sample set G(z), and the goal is to minimize this value to make the discriminator better distinguish between generated samples and real samples; E x~p(x) [y] represents the expected value of the label of the real sample x, which is used to measure whether the discriminator can accurately predict that the real sample is 1; E z~p(z) [D(G(z))] represents the expected value that the generated sample G(z) is predicted as a real sample by the discriminator. This term is used to evaluate the discriminator's judgment ability for generated samples; β represents the coordination weight; |E x~p(x) [y] - E z~p(z) [D(G(z))]| represents the auxiliary discriminator consistency regularization term, which is used to ensure the consistency of the discriminator output, that is, the distribution prediction values of real samples and generated samples as a whole are consistent with the expected values.
[0100] The loss function of the discriminator takes into account both the ability to discriminate real samples and the ability to identify generated samples, and adds a regularization term for the consistency between the auxiliary discriminator output and its own output, where β is the coordination weight.
[0101] Furthermore, in the process of generating adversarial samples, the projected gradient descent (PGD) optimization algorithm is used for updating. Based on the target label, adversarial samples with specific directional perturbations are generated, making the prediction of the model shift towards the target label direction. Finally, these adversarial samples can effectively expose the weaknesses of the model on minority class labels and help improve the model performance.
[0102] Furthermore, assume that the input sample is x and its target label is y t , and the loss function of the model is L(x, yt ; θ), where θ are the parameters of the model. The PGD optimization process is as follows:
[0103] S41. Initialization. Set the initial value of the adversarial sample as the original sample:
[0104] x (0) = x;
[0105] PGD gradually optimizes the adversarial sample through multiple rounds of iteration. In the t-th iteration:
[0106] S42. Calculate the gradient. Calculate the gradient of the loss function with respect to the input sample:
[0107]
[0108] where L(x (t) , y t ; θ) is the classification loss of the model for the input sample x (t) and the target label y t . This gradient indicates the direction that needs to be adjusted to make the sample x (t) more inclined to the target label y t .
[0109] S43. Update the adversarial sample. Update the sample according to the gradient information:
[0110] x (t+1) = x (t) + η·sign(g)
[0111] where η is the step size, controlling the amplitude of each update; sign(g) is the sign function of the gradient, indicating the direction of the perturbation;
[0112] S44. Projection operation. Project the updated sample x (t+1) back to the feasible perturbation range P to ensure that the perturbation does not exceed the specified size limit:
[0113] x (t+1) = Proj p (x (t+1) )
[0114] The projection function Proj p serves to ensure that the generated adversarial sample x (t+1) satisfies the perturbation limit. For the L ∞ norm limit ∈, the projection is defined as:
[0115] x (t+1) = min(max(x (t+1) , x - ∈), x + ∈)
[0116] S45. Repeated iteration, repeat steps S42 to S44 until the preset maximum number of iterations T is reached, or the generated adversarial sample x (T) successfully biases the prediction of the model towards the target label y t .
[0117] It can be understood that the malware adversarial perturbation method based on the pseudo API call sequence conducts experimental operations in the feature space and actually never creates malicious binary files nor maps to the problem space. To solve the problem of inverse mapping, the IAT patch tool is used to achieve inverse mapping. Its principle is to utilize hook API injection and patch the ImportAddressTable of the PE executable file, and then input it into the sandbox Cuckoo again to verify whether the adversarial sample created by the inverse mapping method is still executable and retains the malicious functions of the original software.
[0118] S5. Model training;
[0119] In the model training stage, the generated adversarial samples and the original samples are jointly input into the malware detection model for training. The training objective is to minimize the weighted combination of the standard loss and the adversarial loss.
[0120] Furthermore, the standard loss is usually the cross-entropy loss, and its calculation formula is as follows:
[0121]
[0122] where y i represents the actual label of the sample x i , and f(x i ; θ) represents the prediction probability of the model.
[0123] Furthermore, the adversarial loss is calculated from the adversarial samples:
[0124]
[0125] where represents the generated adversarial sample, and
[0126] represents the target label of the adversarial sample.
[0127] L total = L std + λL adv
[0128] where λ is a hyperparameter that controls the trade-off between the standard loss and the adversarial loss.
[0129] In this embodiment, through adversarial training, the model can not only perform well on standard samples, but also remain robust on adversarial samples. Especially in the case of unbalanced distribution of malicious code labels, it can effectively improve the detection ability of minority-class codes. Finally, the detection performance of each model is evaluated on a separately prepared test set, such as using metrics under curves like Roc-Auc and AvgPrecision.
[0130] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present invention is not limited by the described action sequence, because according to the present invention, certain steps can be performed in other sequences or simultaneously.
[0131] Based on the same idea as the APT organization malicious code defense method based on prior knowledge-guided adversarial training in the above embodiment, the present invention also provides an APT organization malicious code defense system based on prior knowledge-guided adversarial training. This system can be used to execute the above APT organization malicious code defense method based on prior knowledge-guided adversarial training. For the sake of convenience of description, in the structural schematic diagram of the embodiment of the APT organization malicious code defense system based on prior knowledge-guided adversarial training, only the part related to the embodiment of the present invention is shown. Those skilled in the art can understand that the illustrated structure does not constitute a limitation on the device, and it may include more or fewer components than those illustrated, or combine some components, or arrange different components.
[0132] Please refer to Figure 2 , in another embodiment of the present application, an APT organization malicious code defense system 100 based on prior knowledge-guided adversarial training is provided. This system includes a data acquisition module 101, a prior knowledge acquisition module 102, a target label selection module 103, an adversarial sample generation module 104, and a model training module 105;
[0133] The data acquisition module 101 is used to clean and preprocess the obtained malicious code samples as original samples, and extract the distribution information of malicious code labels; the malicious code samples include malicious codes and benign codes;
[0134] The prior knowledge acquisition module 102 is used to calculate the frequency of each label appearing in the dataset based on the distribution information of malicious code labels, and this frequency is used as prior knowledge for subsequent adversarial training;
[0135] The target label selection module 103 is configured to select a more easily misclassified label as the target label according to the distribution information of malicious code labels during the adversarial training process, and determine the sampling frequency of the target label according to the occurrence frequency of the label through the weighted random sampling technique, so as to specifically guide the generation process of adversarial samples;
[0136] The adversarial sample generation module 104 is configured to use a generative adversarial network (GAN) to generate adversarial samples; the generative adversarial network (GAN) includes a generator G and a discriminator D, the generator G adopts a convolutional neural network (CNN) structure, and the discriminator D adopts a multi-layer perceptron (MLP) structure; adversarial training is performed to generate samples with specific perturbations, and the samples with specific perturbations will guide the model to produce incorrect classification results;
[0137] The model training module 105 is configured to use the generated adversarial samples and the original samples as a training set for training to obtain a malicious code detection model. The training objective is to minimize the weighted combination of the standard loss and the adversarial loss, and the defense against malicious code attacks is realized based on the malicious code detection model.
[0138] It should be noted that the APT organization malicious code defense system based on prior knowledge-guided adversarial training of the present invention corresponds one-to-one with the APT organization malicious code defense method based on prior knowledge-guided adversarial training of the present invention. The technical features and beneficial effects described in the embodiments of the above APT organization malicious code defense method based on prior knowledge-guided adversarial training are applicable to the embodiments of the APT organization malicious code defense based on prior knowledge-guided adversarial training. For specific content, reference can be made to the description in the method embodiments of the present invention, which will not be repeated here. This is hereby declared.
[0139] In addition, in the implementation manner of the APT organization malicious code defense system based on prior knowledge-guided adversarial training in the above embodiments, the logical division of each program module is only an example. In practical applications, according to needs, for example, considering the configuration requirements of the corresponding hardware or the convenience of software implementation, the above functions can be assigned to different program modules to complete, that is, the internal structure of the APT organization malicious code defense system based on prior knowledge-guided adversarial training is divided into different program modules to complete all or part of the functions described above.
[0140] Please refer to Figure 3, in one embodiment, an electronic device for implementing an APT organization malicious code defense method based on prior knowledge-guided adversarial training is provided. The electronic device 200 may include a first processor 201, a first memory 202, and a bus. It may also include a computer program stored in the first memory 202 and executable on the first processor 201, such as an APT organization malicious code defense program 203 based on prior knowledge-guided adversarial training.
[0141] Among them, the first memory 202 includes at least one type of readable storage medium, and the readable storage medium includes flash memory, mobile hard disk, multimedia card, card-type memory (such as SD or DX memory, etc.), magnetic memory, magnetic disk, optical disc, etc. In some embodiments, the first memory 202 may be an internal storage unit of the electronic device 200, such as the mobile hard disk of the electronic device 200. In some other embodiments, the first memory 202 may also be an external storage device of the electronic device 200, such as a plug-in mobile hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. equipped on the electronic device 200. Further, the first memory 202 may also include both the internal storage unit and the external storage device of the electronic device 200. The first memory 202 can be used not only to store application software installed on the electronic device 200 and various types of data, such as the code of the APT organization malicious code defense program 203 based on prior knowledge-guided adversarial training, but also to temporarily store data that has been output or will be output.
[0142] In some embodiments, the first processor 201 may be composed of integrated circuits. For example, it may be composed of a single packaged integrated circuit, or may be composed of multiple integrated circuits with the same or different functions, including a combination of one or more Central Processing Units (CPUs), microprocessors, digital processing chips, graphics processors, and various control chips. The first processor 201 is the control core (Control Unit) of the electronic device, connecting various components of the entire electronic device through various interfaces and lines, and executing various functions of the electronic device 200 and processing data by running or executing programs or modules stored in the first memory 202 and calling data stored in the first memory 202.
[0143] Figure 3 Only the electronic device with components is shown. Those skilled in the art can understand that Figure 3The structures shown do not constitute a limitation on the electronic device 200, and may include fewer or more components than those shown, or combine certain components, or have different component arrangements.
[0144] The APT organization malicious code defense program 203 based on prior knowledge-guided adversarial training stored in the first memory 202 in the electronic device 200 is a combination of multiple instructions, and when running in the first processor 201, can implement:
[0145] Clean and preprocess the obtained malicious code samples as original samples, and extract the distribution information of malicious code labels; the malicious code samples include malicious code and benign code;
[0146] Based on the distribution information of malicious code labels, calculate the frequency of each label appearing in the dataset, and use the frequency as prior knowledge for subsequent adversarial training;
[0147] During the adversarial training process, select the labels that are more likely to be misclassified as target labels according to the distribution information of malicious code labels, and determine the sampling frequency of the target labels according to the occurrence frequency of the labels through the weighted random sampling technique, so as to specifically guide the generation process of adversarial samples;
[0148] Use the generative adversarial network GAN to generate adversarial samples; the generative adversarial network GAN includes a generator G and a discriminator D, the generator G adopts a convolutional neural network CNN structure, and the discriminator D adopts a multi-layer perceptron MLP structure; generate samples with specific perturbations through adversarial training, and the samples with specific perturbations will guide the model to produce incorrect classification results;
[0149] Use the generated adversarial samples and the original samples as a training set for training to obtain a malicious code detection model. The training objective is to minimize the weighted combination of the standard loss and the adversarial loss, and realize the defense against malicious code attacks based on the malicious code detection model.
[0150] Furthermore, if the modules / units integrated in the electronic device 200 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM, Read-Only Memory).
[0151] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a non-volatile computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0152] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0153] The above embodiments are preferred embodiments of the present invention, but the embodiments of the present invention are not limited to the above embodiments. Any other changes, modifications, substitutions, combinations, and simplifications made without departing from the spirit and principle of the present invention shall be equivalent replacement methods and are all included in the protection scope of the present invention.
Claims
1. A method for defending against malicious code of APT organizations based on prior knowledge-guided adversarial training, characterized in that: The steps include: The acquired malicious code samples are cleaned and preprocessed as original samples, and distribution information of malicious code labels is extracted; the malicious code samples include malicious code and benign code; Based on the distribution information of malicious code labels, the frequency of each label in the data set is calculated, and the frequency is used as prior knowledge for subsequent adversarial training; During adversarial training, labels that are more easily misclassified are selected as target labels based on the distribution information of malicious code labels. The sampling frequency of target labels is determined according to the frequency of occurrence of labels through weighted random sampling technology, thereby guiding the generation process of adversarial samples in a targeted manner. Generate adversarial samples using a generative adversarial network (GAN); the generative adversarial network (GAN) includes a generator G and a discriminator D, the generator G adopts a convolutional neural network (CNN) structure, and the discriminator D adopts a multi-layer perceptron (MLP) structure; generate samples with specific perturbations through adversarial training, and the samples with specific perturbations will guide the model to produce incorrect classification results; The generated adversarial samples and the original samples are used as training sets to obtain a malicious code detection model. The training goal is to minimize the weighted combination of standard loss and adversarial loss, and to achieve defense against malicious code attacks based on the malicious code detection model.
2. The method for defending against malicious code of APT organizations based on prior knowledge-guided adversarial training according to claim 1 is characterized in that: The malicious code samples are obtained and cleaned and preprocessed to extract the distribution information of the malicious code labels, specifically: Clean the acquired malicious code sample data to remove noise and invalid samples; The malicious code and benign code datasets are input into the sandbox for preprocessing, and the JSON information of the apistat part about the API call information is extracted, including: First, extract all dynamically called APIs from the dataset and generate a set containing M API call elements; Then, the API calls are converted into feature vectors through One-hot encoding; Next, the random forest algorithm is used to classify the data in the training set into two categories, and the first m features with the largest weights are selected as the final feature set based on feature importance.
3. According to claim 1, the method for defending against malicious code of APT organizations based on prior knowledge-guided adversarial training is characterized in that: The distribution information of malicious code labels is based on calculating the frequency of each label in the data set, specifically: In the data preprocessing stage, the number of occurrences of each label in the statistical data set is counted, and the frequency of occurrence of each label is calculated based on the total number of samples as prior knowledge for subsequent adversarial training. The specific calculation formula is: where count(c i ) is the label c i The number of occurrences of , n is the total number of samples.
4. According to claim 1, the method for defending against malicious code of APT organizations based on prior knowledge-guided adversarial training is characterized in that: In adversarial training, the sampling frequency of the label is expressed as follows: Among them, P(y t =c i ) represents the target label c i The probability of being selected, f(c i ) indicates label c i The frequency with which a variable appears in a dataset.
5. According to claim 1, the method for defending against malicious code of APT organizations based on prior knowledge-guided adversarial training is characterized in that: In the training process of GAN, the generator G and the discriminator D are trained alternately through multiple iterations. The goal of the generator G is to generate realistic samples to deceive the discriminator, while the goal of the discriminator D is to distinguish between real samples and generated samples. The loss of the generator is L G The function consists of adversarial loss and reconstruction loss, expressed as follows: L G =E z~p(z) [-logD(G(z))]+αE x~p(x) [||x-G(z)||] Among them, the anti-loss part E z~p(z) [-logD(G(z))] makes the generator output confuse the discriminator; reconstruction loss part E x~p(x) [||xG(z)||] makes the generated sample closer to the original sample by minimizing the deviation between the input and output in the data space. The parameter α is a hyperparameter that controls the weight, and z represents the noise vector. The loss function L of the discriminator D The design is as follows: L D =-E x~p(x) [logD(x)]-E z~p(z) [1-log(1-D(G(z)))]+β|E x~p(x) [y]-E z~p(z) [D(G(z))]|Wherein, D(x) represents the probability prediction of the discriminator D that the input sample x is a real sample, and the value range is (0,1). The closer it is to 1, the more confident the discriminator is that the sample is a real sample; G(z) represents the sample generated by the generator G after inputting random noise z, z~p(z) represents the distribution of noise Z, and B x~p(x) [logD(x)] represents the expectation of samples in the real sample set p(x). The goal is to maximize this value so that the discriminator can better identify real samples; E z~p(z) [1-log(1-D(G(z)))] represents the expectation of the generated sample set G(z). The goal is to minimize this value so that the discriminator can better distinguish between generated samples and real samples; E x~p(x) [y] represents the expected value of the label of the real sample x, which is used to measure whether the discriminator can accurately predict that the real sample is 1; E z~p(z) [D(G(z))] represents the expected value of the generated sample G(z) predicted by the discriminator as a real sample. This item is used to evaluate the discriminator's ability to judge the generated samples; β represents the coordination weight; |E x~p(x) [y]-E z~p(z) [D(G(z))]| represents the auxiliary discriminator consistency regularization term, which is used to ensure the consistency of the discriminator output, that is, the overall distribution prediction value of the real sample and the generated sample is consistent with the expected value; The loss function L of the discriminator D At the same time, the ability to discriminate real samples and the ability to identify generated samples are considered, and a regular term is added to ensure the consistency between the output of the auxiliary discriminator and its own output. β is the coordination weight.
6. According to claim 5, the method for defending against malicious code of APT organizations based on prior knowledge-guided adversarial training is characterized in that: In the process of generating adversarial samples, the projected gradient descent PGD optimization algorithm is used for updating, and adversarial samples with specific direction perturbations are generated based on the target label, so that the model's prediction shifts toward the target label direction.
7. According to claim 1, the method for defending against malicious code of APT organizations based on prior knowledge-guided adversarial training is characterized in that: Standard loss L std is the cross entropy loss, and the calculation formula is as follows: Among them, y i Represents sample x i The actual label, f(x i ; θ) represents the predicted probability of the malicious code detection model; Adversarial loss L adv It is calculated through adversarial samples: in, represents the generated adversarial sample, Represents the target label of the adversarial sample; Represents the malicious code detection model for the input sample x i The predicted probability distribution of is the output of the model; The final training loss function is the standard loss L std and adversarial loss L adv A weighted combination of: THE total =L std +λL adv Among them, λ is a hyperparameter that controls the trade-off between standard loss and adversarial loss.
8. APT organization malicious code defense system based on prior knowledge guided adversarial training, characterized by: A method for defending against malicious code of an APT organization based on adversarial training guided by prior knowledge, applied to any one of claims 1-7, comprising a data acquisition module, a priori knowledge acquisition module, a target label selection module, an adversarial sample generation module and a model training module; The data acquisition module is used to clean and pre-process the acquired malicious code samples as original samples, and extract the distribution information of malicious code labels; the malicious code samples include malicious code and benign code; The prior knowledge acquisition module is used to calculate the frequency of each label in the data set based on the distribution information of the malicious code labels, and the frequency is used as prior knowledge for subsequent adversarial training; The target label selection module is used to select labels that are more easily misclassified as target labels according to the distribution information of malicious code labels during adversarial training, and determine the sampling frequency of target labels according to the frequency of occurrence of labels through weighted random sampling technology, so as to guide the generation process of adversarial samples in a targeted manner; The adversarial sample generation module is used to generate adversarial samples using a generative adversarial network (GAN); the generative adversarial network (GAN) includes a generator G and a discriminator D, the generator G adopts a convolutional neural network (CNN) structure, and the discriminator D adopts a multi-layer perceptron (MLP) structure; samples with specific perturbations are generated through adversarial training, and the samples with specific perturbations will guide the model to produce erroneous classification results; The model training module is used to train the generated adversarial samples and the original samples as training sets to obtain a malicious code detection model. The training goal is to minimize the weighted combination of standard loss and adversarial loss, and to achieve defense against malicious code attacks based on the malicious code detection model.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores computer program instructions that can be executed by the at least one processor, and the computer program instructions are executed by the at least one processor so that the at least one processor can execute the APT organization malicious code defense method based on prior knowledge guided adversarial training as described in any one of claims 1-7.
10. A computer-readable storage medium storing a program, characterized in that: When the program is executed by the processor, the APT organization malicious code defense method based on prior knowledge guided adversarial training as described in any one of claims 1-7 is implemented.
Citation Information
Patent Citations
Adversarial attack defense method based on adversarial sample training
CN110334808A
Method and system for detecting malicious software based on adversarial training
CN118747364A
Synthetic biological characteristic generator based on real biological data signatures
US20220310196A1