Malicious process behavior identification method based on quantum computing and topological data analysis

Through the combination of dynamic binary instrumentation, topological data analysis and quantum support vector machines, high-dimensional features of malicious processes are extracted and classified and identified, which solves the problem that the existing technology is difficult to capture the dynamic features of malicious processes, and achieves higher recognition accuracy and efficiency.

CN120124052APending Publication Date: 2025-06-10BEIJING GUOTENG INNOVATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311675051.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-07
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively capture and identify the dynamic characteristics of malicious processes, resulting in a decrease in detection effect when malicious code mutations and obfuscations.

Method used

Dynamic binary instrumentation technology is used to monitor malicious processes in real time, topological data analysis is used to extract high-dimensional features, and complex network models are built, and finally high-precision classification and identification is performed through quantum support vector machine (QSVM).

Benefits of technology

This method can more effectively capture the dynamic characteristics of malicious behavior, improve the recognition rate and accuracy rate, and enhance the prevention ability of attacks on complex malicious processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
  • Figure FT_2
    Figure FT_2
  • Figure FT_3
    Figure FT_3
Patent Text Reader

Abstract

The invention relates to a malicious process identification method based on behavior analysis, and aims to solve the problems of malicious processes in a computer system. According to the method, a behavior analysis rule is automatically updated in real time by utilizing technologies such as machine learning, so that a malicious process is identified. The specific implementation process comprises the steps of obtaining behavior data of a process, extracting behavior features, constructing feature vectors, and carrying out classification and recognition by using a support vector machine (SVM) algorithm. Meanwhile, according to the method, an attack and defense mechanism against a resistant sample is provided aiming at the hiding and latent characteristics of the malicious process. Experimental verification is carried out on the method, and effectiveness and feasibility of the method in the aspect of malicious process identification are proved. The method can be applied to the fields of computer security, network security and the like, and has wide application prospect and commercial value.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This patent proposes a brand-new method for identifying malicious process behaviors based on quantum computing and topological data analysis. First, dynamic binary instrumentation technology is used to monitor malicious processes in real time. Then, topological data analysis (TDA) is utilized to extract high-dimensional features of malicious behaviors and construct a complex network model. Finally, quantum support vector machine (QSVM) is used for high-precision classification and identification. Background Art

[0002] Computer viruses and malware are an important threat in the current Internet environment. A malicious process refers to a malware program that lurks in a computer system through various means and destroys, steals, or pilfers information. The existence of malicious processes can cause great harm to computer systems and user information, such as stealing user privacy, damaging system security, and spreading network viruses. Malicious processes are an important issue in the field of computer system security and pose a serious threat to the security and stability of computer systems.

[0003] Currently, the detection and defense of malicious processes mainly adopt two methods: static and dynamic. Among them, the static method mainly detects malicious behaviors through the analysis and disassembly of program codes. However, the defect of the static method is that it is vulnerable to deception and mutation of malicious codes and cannot capture dynamic behaviors. The dynamic method mainly detects malicious behaviors by monitoring the execution behaviors of programs. This method can capture the dynamic features of malicious behaviors. However, with the continuous mutation and obfuscation of malicious codes, the effectiveness of the dynamic method is gradually decreasing. Summary of the Invention

[0004] Therefore, we propose a brand-new method for identifying malicious process behaviors based on quantum computing and topological data analysis. First, dynamic binary instrumentation technology is used to monitor malicious processes in real time. Then, topological data analysis (TDA) is utilized to extract high-dimensional features of malicious behaviors and construct a complex network model. Finally, quantum support vector machine (QSVM) is used for high-precision classification and identification. Compared with traditional static and dynamic detection methods, this new method can more effectively capture the dynamic features of malicious behaviors and greatly improve the recognition rate and accuracy through quantum computing.

[0005] In this new method, dynamic binary instrumentation technology is one of the key technologies for realizing dynamic behavior analysis. It can obtain the runtime behaviors of programs and thus provide data support for subsequent feature extraction and behavior model construction. Through topological data analysis, high-dimensional features of malicious behaviors can be extracted, and then a network model reflecting their complex behaviors can be constructed. Finally, through QSVM, high-precision classification and identification can be carried out in the quantum state space, thereby effectively identifying the types of malicious processes.

[0006] The process of the malicious process behavior recognition method based on quantum computing and topological data analysis described in this patent is as follows Figure 1 as shown below and is described in detail as follows:

[0007] Step1: Quantum dynamic binary instrumentation. This step will utilize the basic principles of quantum computing to map traditional binary code onto quantum states. Each binary code segment can be regarded as the state of a qubit. By performing interference and entanglement on these qubits, more behavioral information can be collected in a higher-dimensional space. Specifically, using the quantum circuit design tool Qiskit, the binary code is converted into a corresponding quantum circuit, and instrumentation is performed by inserting a specific quantum operation, the CNOT gate, which can achieve control inversion between two qubits. This method can collect and record the quantum behavioral information of the target program in real time, providing data support for subsequent analysis.

[0008] Step2: Construction of a complex network behavior model. This patent constructs a directed graph complex network model based on system calls to deeply study and characterize the behavior patterns of malicious processes. The nodes in this network represent system calls, and the edges depict the relationships between system calls. First, record the system call sequence of the target program. Then, each independent system call is regarded as a node, and each pair of sequentially occurring system calls is regarded as a directed edge. In this framework, the nodes represent unique system calls, and their labels can be the names or IDs of the system calls. When system call A occurs immediately after system call B, a directed edge from node A to node B will appear in the network, and the weight of the edge may be the occurrence frequency of the pair of system calls A and B. The network model constructed in this way not only captures the independent events of system calls but also reveals the complex relationships between system calls. The topological structure of this network can provide in-depth information about system call patterns. For example, if a malicious program often executes a specific system call sequence, then this pattern will be manifested in the network in a specific structural pattern.

[0009] Step 3: Quantum behavior matching. In this step, this patent uses quantum algorithms to perform behavior matching. For the process to be analyzed, first its behavior model is mapped to a quantum state, and then it is processed using a quantum computer. Quantum algorithms can perform calculations in a high-dimensional space, thus avoiding the "curse of dimensionality" problem that traditional algorithms encounter with high-dimensional data. Specifically, first the behavior models of the process to be analyzed and known malicious behavior models are both mapped to a high-dimensional quantum state space. Then, the QSVM algorithm is executed using a quantum computer to find a hyperplane that maximizes the margin between the behavior model of the process to be analyzed and the known malicious behavior models in the quantum state space. Finally, based on which side of the hyperplane the behavior model of the process to be analyzed lies, it is determined whether it is a malicious behavior, thus achieving behavior matching.

[0010] Step 4: High-dimensional geometric feature extraction. Use tools of high-dimensional geometry, such as topological data analysis (TDA), to extract more complex features. Specifically, a tool of TDA called persistent homology can be used to extract high-dimensional features of program behavior. Persistent homology is a method that can capture and measure the complexity of the shape and structure of data. For example, calculate the Betti numbers of the system call network, which is a measure reflecting the complexity of the network topology. Briefly, the zero-th Betti number represents the number of connected components in the network, the first-order Betti number represents the number of "holes" in the network, the second-order Betti number represents the number of enclosed spaces in the network, and so on. These Betti numbers can provide rich information about the network topology and help extract complex features. In addition, persistent homology can not only extract the Betti numbers of each dimension, but also provide the trend of these Betti numbers as the parameters (such as the density or threshold of the network) change, which is called the persistence diagram or persistence barcode. These diagrams can provide an in-depth understanding of how the network structure changes with the parameters, further enhancing the feature extraction ability.

[0011] Step 5: Quantum Support Vector Machine Classification and Recognition. In this step, a Quantum Support Vector Machine (QSVM) is used for classification and recognition. QSVM is the quantum version of the Support Vector Machine (SVM), which can perform calculations in the quantum state space to improve the accuracy of classification. First, the extracted feature vectors are converted into quantum states, and then these quantum states are used as input data to train the QSVM model. During the training process, the decision boundary of QSVM is optimized to maximize the margin between different types of malicious processes in the quantum state space. This can ensure that the QSVM model has good classification performance for new malicious processes. After training, a QSVM classifier is obtained. For each malicious process to be recognized, its feature vector is first extracted, then converted into a quantum state, and this quantum state is input into the QSVM classifier. The classifier will output a classification result indicating which category the malicious process belongs to. Since the QSVM model performs classification in the quantum state space, it can achieve higher classification accuracy than the traditional SVM.

[0012] The advantages of this patent are that it combines quantum instrumentation technology and deep learning algorithms to achieve precise behavior analysis and classification recognition for malicious processes. At the same time, this patent realizes efficient, real-time, and in-depth recognition of malicious processes by combining quantum computing and complex network analysis, greatly enhancing the ability to prevent complex malicious process attacks. Different from traditional malicious process detection methods that rely on shallow features, the method of this patent is more accurate and robust, and can capture and identify more types of malicious processes. Brief Description of the Drawings

[0013] To more clearly illustrate the content of the present patent invention and the technical solutions in the embodiments, the accompanying drawings used will be briefly introduced below. The accompanying drawings in the following description are only some overall architectures and embodiments of this patent. For those of ordinary skill in the art, other accompanying drawings can be obtained based on these drawings without creative efforts.

[0014] Figure 1 It is the overall flowchart of the malicious process behavior recognition method based on quantum computing and topological data analysis provided by this patent;

[0015] Figure 2 It is the directed graph complex network model based on system calls in step two of the malicious process behavior recognition method based on quantum computing and topological data analysis. "System call A", "System call B", "System call C", "System call D", and "System call E" represent different system calls. The arrows represent the relationships between system calls, that is, another system call that occurs after one system call.

[0016] Figure 3This is the specific process of quantum support vector machine classification and recognition in the malicious process behavior recognition method based on quantum computing and topological data analysis;

[0017] Specific implementation method

[0018] To better illustrate the application of this embodiment, the following is an example.

[0019] Example 1: Identifying malware

[0020] Suppose we are conducting behavioral analysis and classification recognition for malware. We select a malware called "BlackGauss", which is a malware that attacks financial institutions.

[0021] First, we need to perform dynamic binary instrumentation on the BlackGauss malware. Specifically, we can insert some special quantum operations, such as CNOT gates, at key positions during the software execution. The purpose of these operations is to monitor and record its behavior in real time during the malware execution, such as system calls and network communication behaviors.

[0022] Next, we can use these monitoring data to construct a complex network behavior model. This model is a directed graph, where the nodes represent system calls and the edges represent the relationships between system calls. For example, if system call A occurs immediately followed by system call B, then there will be a directed edge in the network from node A to node B. This model can capture the complex relationships between system calls, rather than just independent system call events.

[0023] After obtaining the complex network behavior model, we need to perform behavior matching. We use the support vector machine (QSVM) algorithm to compare the behavior model of the BlackGauss malware to be analyzed with the known malicious behavior models and match similar behavior sequences. The advantage of the quantum algorithm is that it can perform calculations in high-dimensional spaces, avoiding the "curse of dimensionality" problem that traditional algorithms often encounter when dealing with high-dimensional data.

[0024] To extract more useful information from the complex network behavior model, high-dimensional geometric feature extraction is required. This patent uses tools of topological data analysis (TDA), such as persistent homology, to extract these features. For example, calculating the Betti numbers of the network, which is a parameter reflecting the complexity of the network topology.

[0025] Finally, a Quantum Support Vector Machine (QSVM) is used for classification and recognition. The QSVM is trained using the existing feature vector library to obtain a classifier. Then, the feature vectors of the BlackGauss malware extracted are input into the classifier to obtain a classification result. This result can identify the specific type and possible behaviors of the BlackGauss malware.

[0026] In this process, this patent successfully uses dynamic binary instrumentation and quantum machine learning methods to effectively analyze the behaviors and classify and recognize the BlackGauss malware. This process is not only accurate and reliable but also highly real-time and scalable, capable of dealing with various complex malware attacks.

[0027] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this patent and are not intended to limit them; although this patent has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of this patent.

Claims

1. A method for identifying malicious process behaviors based on quantum computing and topological data analysis, characterized in that, the method comprises the following steps: using dynamic binary instrumentation technology to monitor malicious processes to obtain dynamic behavior information of the malicious processes; using topological data analysis technology to extract behavior characteristics of the malicious processes and construct a complex network model; using the quantum support vector machine of quantum computing to classify the complex network model to identify malicious processes.

2. The method according to claim 1, characterized in that, the dynamic binary instrumentation technology is used to monitor the execution process of malicious processes in real time and collect their behavior information during runtime.

3. The method according to claim 1 or 2, characterized in that, the topological data analysis technology is used to extract meaningful characteristics from high-dimensional behavior data and construct a network model reflecting the complex behaviors of malicious processes.

4. The method according to any one of claims 1-3, characterized in that, the quantum support vector machine uses the quantum state space for classification calculation to achieve high-precision identification of malicious processes.

5. The method according to claim 1, characterized in that, the method further comprises a step of performing quantum feature mapping on the extracted features before the classification and identification by the quantum support vector machine.