Malicious software detection method and device, computer equipment and storage medium
By obtaining and comparing the API call data and preset combination data of the software to be detected, and entering the pre-trained detection model for detection, the problem of low accuracy of existing malware detection methods is solved, and more efficient malware recognition is achieved.
Patent Information
- Application Number
- CN202311751671.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-18
- Publication Date
- 2025-06-20
AI Technical Summary
The existing malware detection methods are less accurate and are easily bypassed by attackers by modifying file signatures or software code.
By obtaining the call data of the software to be detected calling the application programming interface (API), comparing it with the preset combination data, and input the comparison results into the pre-trained malware detection model for detection. The preset combination data is generated based on the function combination data when the sample software performs malicious actions.
Improves the accuracy of malware detection and avoids attackers from bypassing detection by modifying file signatures or obfuscating software code, thereby enhancing the ability to identify malware.
Smart Images

Figure CN120180430A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of data processing, and particularly to a method, device, computer device, and storage medium for malware detection. Background Art
[0002] With the progress of Internet technology, intelligent devices have become popular among users, and various intelligent devices are indispensable in users' daily life and work. The continuous development of intelligent devices has brought convenience to users' daily life and work, and this convenience comes from various types of software installed on intelligent devices.
[0003] Generally, in order to ensure the security of the installed software, it is necessary to detect the software to determine whether it is malware. Currently, the common means of malware detection include static detection technology. Static detection technology constructs a detection model based on file signatures and software code. However, this method is easily bypassed by attackers through means such as modifying file signatures or code obfuscation, resulting in the failure of the model, and thus the accuracy of malware detection is relatively low. Summary of the Invention
[0004] Based on this, in view of the above technical problems, it is necessary to provide a malware detection method, device, computer device, computer-readable storage medium, and computer program product that can improve the accuracy of malware detection.
[0005] In a first aspect, the present application provides a malware detection method. The method includes:
[0006] Obtaining call data corresponding to the application programming interface called by the software to be detected;
[0007] Comparing the call data with preset combined data to obtain a comparison result, where the preset combined data refers to at least one set of function combined data called when a sample software executes malicious actions;
[0008] Inputting the comparison result into a pre-trained malware detection model for malware detection to obtain a malware detection result corresponding to the software to be detected.
[0009] In one embodiment, the malware detection model includes multiple sub-detection models, and the multiple sub-detection models are trained according to different types of sample software;
[0010] The step of inputting the comparison result into a pre-trained malware detection model for malware detection to obtain a malware detection result corresponding to the software to be detected includes:
[0011] Input the comparison results into multiple sub-detection models respectively to obtain multiple sub-detection results;
[0012] Determine the proportion of the first results indicating that the software to be detected is malicious among the multiple sub-detection results, and determine the proportion of the second results indicating that the software to be detected is non-malicious among the multiple sub-detection results;
[0013] Obtain the malicious software detection result according to the first result proportion, the second result proportion and the preset proportion threshold.
[0014] The step of comparing the call data with the preset combined data to obtain a comparison result includes:
[0015] Detect whether each function combined data exists in the call data;
[0016] If it exists in the call data, generate a first comparison result corresponding to each function combined data;
[0017] If it does not exist in the call data, generate a second comparison result corresponding to each function combined data;
[0018] Obtain the comparison result corresponding to the software to be detected according to the first comparison result and the second comparison result.
[0019] In one embodiment, before the step of obtaining the call data corresponding to the software to be detected by calling the application programming interface, the method further includes: training the malicious software detection model, including:
[0020] Obtain the sample data of each sample software calling the application programming interface;
[0021] Based on each sample data, determine the preset combined data;
[0022] According to each sample data and the preset combined data, determine the training data set corresponding to each sample data;
[0023] Train the malicious software detection model based on the training data set.
[0024] In one embodiment, the step of determining the preset combined data based on each sample data includes:
[0025] In each sample data, screen out each target combined data, where the target combined data refers to the function combination called by the corresponding sample software of each sample data when performing malicious actions;
[0026] Obtain the occurrence probability corresponding to each of the target combination data, where the occurrence probability is used to characterize the frequency of occurrence of the target combination data;
[0027] Generate a frequent item set based on the occurrence probability and a preset support threshold;
[0028] Perform redundancy processing on the frequent item set to obtain the preset combination data.
[0029] In one embodiment, the performing redundancy processing on the frequent item set to obtain the preset combination data includes:
[0030] Obtain each frequent item in the frequent item set;
[0031] Perform redundancy detection on each of the frequent items to obtain a redundancy detection result corresponding to each of the frequent items, where the redundancy detection result is used to indicate whether the frequent item exists in other frequent items in the frequent item set;
[0032] Obtain the preset combination data based on each of the redundancy detection results.
[0033] In one embodiment, the malware detection model includes a plurality of sub-detection models, and training the malware detection model based on the training data set includes:
[0034] Cluster the training data set according to the type of the sample software to obtain a plurality of sub-training data sets corresponding to the training data set;
[0035] Train one of the sub-detection models based on each of the sub-training data sets.
[0036] In a second aspect, the present application further provides a malware detection device. The device includes:
[0037] A data acquisition module, configured to acquire call data corresponding to an application programming interface called by the software to be detected;
[0038] A comparison module, configured to compare the call data with preset combination data to obtain a comparison result, where the preset combination data refers to at least one set of function combination data called when a sample software performs a malicious action;
[0039] A model detection module, configured to input the comparison result into a pre-trained malware detection model to perform malware detection and obtain a malware detection result corresponding to the software to be detected.
[0040] In a third aspect, the present application also provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0041] Obtain call data corresponding to the application programming interface called by the software to be detected;
[0042] Compare the call data with preset combined data to obtain a comparison result, where the preset combined data refers to at least one set of function combined data called when a sample software performs a malicious action;
[0043] Input the comparison result into a pre-trained malware detection model to perform malware detection and obtain a malware detection result corresponding to the software to be detected.
[0044] In a fourth aspect, the present application also provides a computer-readable storage medium. On the computer-readable storage medium, a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:
[0045] Obtain call data corresponding to the application programming interface called by the software to be detected;
[0046] Compare the call data with preset combined data to obtain a comparison result, where the preset combined data refers to at least one set of function combined data called when a sample software performs a malicious action;
[0047] Input the comparison result into a pre-trained malware detection model to perform malware detection and obtain a malware detection result corresponding to the software to be detected.
[0048] In a fifth aspect, the present application also provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the following steps are implemented:
[0049] Obtain call data corresponding to the application programming interface called by the software to be detected;
[0050] Compare the call data with preset combined data to obtain a comparison result, where the preset combined data refers to at least one set of function combined data called when a sample software performs a malicious action;
[0051] Input the comparison result into a pre-trained malware detection model to perform malware detection and obtain a malware detection result corresponding to the software to be detected.
[0052] The above-mentioned malware detection method, device, computer equipment and storage medium. First, obtain the call data of the software to be detected for calling the application programming interface (API, Application Programming Interface). This is because the behaviors of malware such as network connection, startup, and memory operation need to be completed by calling the API. That is to say, calling the API is an unavoidable behavior for malware. Compared with file signatures and software codes, using the data of API calls for malware detection is more reliable and accurate. Then, compare the call data with at least one set of function combination data, that is, the preset combination data, called by the sample software when performing malicious actions, to obtain a comparison result. Then, input the comparison result into a pre-trained malware detection model for malware detection to obtain the malware detection result corresponding to the software to be detected, so as to judge whether the software to be detected is malware based on the malware detection result. In this way, it effectively avoids attackers from avoiding malware detection by modifying file signatures or obfuscating software codes, thereby improving the accuracy of malware detection. Brief Description of the Drawings
[0053] Figure 1 It is a schematic diagram of the application scenario of the malware detection method in an embodiment;
[0054] Figure 2 It is a schematic flowchart of the malware detection method in an embodiment;
[0055] Figure 3 It is a schematic flowchart of determining the malware detection result in an embodiment;
[0056] Figure 4 It is a schematic flowchart of establishing a malware detection model in an embodiment;
[0057] Figure 5 It is a schematic flowchart of processing the target combination data in an embodiment;
[0058] Figure 6 It is a block diagram of the structure of the malware detection device in an embodiment;
[0059] Figure 7 It is an internal structure diagram of the computer equipment in an embodiment. Detailed Embodiments
[0060] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0061] With the progress of Internet technology, smart devices have become popular among users, and various smart devices are indispensable in users' daily life and work. The continuous development of smart devices has brought convenience to users' daily life and work, and this convenience comes from various types of software installed on smart devices. However, currently, there is a common phenomenon that external attackers use methods such as phishing, vulnerabilities, or software supply chain attacks to make malicious software programs run on the device to control the device.
[0062] Therefore, in order to protect the security of the device, it is necessary to detect the software installed in the device, that is, to detect whether it is malicious software. Currently, the mainstream malicious software detection methods mainly involve static detection techniques. Static detection techniques refer to building a detection model based on file signatures and software code, and then using this detection model to identify whether the installed software is malicious software. However, the drawback of this method is that attackers can easily bypass the detection of the model by modifying file signatures or obfuscating software code, resulting in the model becoming ineffective and unable to achieve accurate detection. Some researchers have also proposed dynamic detection techniques. Dynamic detection techniques refer to building a detection model using API call behaviors. However, most of these methods build models by counting the number of calls to a certain API function or the number of processes started. The meanings represented by these features are relatively single and cannot accurately describe the behaviors of malicious software, and thus cannot accurately identify malicious software either.
[0063] The malicious software detection method provided by the embodiments of the present disclosure can be applied to an application environment as Figure 1 shown. Among them, the server 102 is connected to the terminal 104. Specifically, if the server 102 receives a malicious software detection instruction for the software to be detected sent by the terminal 104, it obtains the call data corresponding to the application programming interface called by the software to be detected. Then, it compares this call data with preset combined data, and obtains a comparison result. The preset combined data refers to at least one set of function combined data called when a sample software performs malicious actions determined in advance. Finally, it inputs the comparison result into a pre-trained malicious software detection model for malicious software detection, and obtains a malicious software detection result corresponding to the software to be detected, and determines whether the software to be detected is malicious software based on this malicious software detection result.
[0064] Among them, the server 102 can be implemented by an independent server or a server cluster composed of multiple servers. The terminal 104 can be, but is not limited to, various desktop computers, laptop computers, smart phones, tablet computers, and Internet of Things devices.
[0065] In one embodiment, as Figure 2 shown, a malicious software detection method is provided. Taking the method applied to the Figure 1 server 102 as an example for description, the method includes the following steps:
[0066] Step S202: Obtain the call data corresponding to the application programming interface called by the software to be detected.
[0067] Among them, the software to be detected may refer to the software that needs to be maliciously detected. The application programming interface refers to pre-defined functions, whose main purpose is to enable application developers to call a set of routine functions without having to consider the underlying source code or understand the details of its internal working mechanism. The API itself is abstract, and it only defines an interface without involving the specific operations in the actual implementation process of the application. Malicious software must call the API during normal operation, and the process of calling the API cannot be tampered with. Therefore, obtaining the call data during the process of the software to be detected calling the API in this embodiment can truly reflect the behavior of the software to be detected and can more accurately detect whether the software to be detected is malicious software.
[0068] The call data refers to the data generated during the process of the software to be detected calling the application programming interface, including but not limited to the API function call list during the process of the software to be detected calling the application programming interface.
[0069] Specifically, the software to be detected can be submitted to a sandbox for running, and the API functions called by the software to be detected during running in the sandbox can be obtained. A sandbox is a virtual execution environment for network programming. A program or software can be placed in the sandbox for running, and all files created, modified, or deleted by it will be virtualized, that is, all operations are virtual and real files will not be modified. In this embodiment, the software to be detected is placed in the sandbox for malicious software detection to simulate the real running scenario of the software, which is convenient for monitoring and analyzing the software to be detected.
[0070] In one embodiment, the API call log of the software to be detected can be obtained, and the initial API function call list of the software to be detected can be extracted from the API call log. Then, the API function call list is merged and de-duplicated to obtain the final API function call list. This can avoid affecting the efficiency and accuracy of subsequent malicious software identification due to the existence of a large number of duplicate API functions in the list.
[0071] In one embodiment, the initial API function call list can be expressed as:
[0072]
[0073] After merging and de-duplicating the api_call_list, the final API function call list is obtained:
[0074]
[0075] Among them, api_call_num represents the length of the initial API function call list, that is, the total number of API calls, and api_num represents the number of non-repeated API functions included in api_call_list.
[0076] For example, the API call function list of the software A to be detected can be: api_call_list = {CreateDirectoryExW, CryptEncrypt, FindNextFileW, CreateDirectoryExW,..., GetSystemDirectoryW}, where CreateDirectoryExW, CryptEncrypt, FindNextFileW, CreateDirectoryExW, and GetSystemDirectoryW are all API functions called by the software A to be detected when running in the sandbox.
[0077] Step S204, compare the call data with the preset combined data to obtain a comparison result, where the preset combined data refers to at least one set of function combination data called when the sample software executes malicious actions determined in advance.
[0078] Among them, malicious software will inevitably execute malicious actions and naturally generate API call data corresponding to the malicious actions. Therefore, using the combination results of various data features generated when the malicious sample software executes malicious actions for malicious software detection can prevent attackers from avoiding detection by modifying file signatures or obfuscating code, thereby improving the effectiveness and accuracy of malicious software detection. It should be noted that the malicious actions executed by the malicious sample software are not limited to the malicious sample software starting to execute actions such as destruction, deletion, tampering, and theft, but can also include all function call behaviors involved in the entire process from the start to the end of the malicious sample software.
[0079] The malicious sample software refers to the sample software used to establish the malicious software detection model. Malicious software generally has the ability to anti-sandbox. They will first query the current running environment. If they identify that the current running environment is a sandbox environment, they will delay the execution of malicious actions to avoid being recognized. This is the anti-sandbox ability. Therefore, in one embodiment, the API call functions corresponding to querying the running environment and the API call functions corresponding to delaying malicious actions can be combined as the preset combined data, that is, by detecting whether there is a combined feature of the two behaviors of querying the running environment and delaying malicious actions in the call data of the software to be detected, it can effectively identify whether the software to be detected is malicious software.
[0080] The comparison result can be used to determine whether the function combination data in the preset combined data exists in the call data of the software to be detected, which can include a first comparison result and a second comparison result. The first comparison result can be used to indicate that the function combination data exists in the call data, and the second comparison result can be used to indicate that the function combination data does not exist in the call data.
[0081] Specifically, the call data is compared with the preset combined data, that is, it is detected whether the function combination data in the preset combined data exists in the call data, and a first comparison result and a second comparison result are obtained.
[0082] In one embodiment, it is detected whether each function combination data exists in the call data. If it exists in the call data, a first comparison result corresponding to each function combination data is generated. If it does not exist in the call data, a second comparison result corresponding to each function combination data is generated. According to the first comparison result and the second comparison result, the comparison result corresponding to the software to be detected is obtained, that is, the first comparison result and the second comparison result are integrated to obtain the comparison result of the software to be detected.
[0083] In one embodiment, the first comparison result and the second comparison result can be represented by numerical values. For example, 1 can represent the first comparison result, and 0 can represent the second comparison result.
[0084] Step S206, input the comparison result into a pre-trained malware detection model for malware detection to obtain the malware detection result corresponding to the software to be detected.
[0085] Among them, the malware detection model is a model pre-trained based on the sample data of sample software, and can be a decision tree model or a random forest model.
[0086] In one embodiment, the malware detection model includes multiple sub-detection models, and the multiple sub-detection models can be trained according to different types of sample software. The malware detection result can refer to the result used to determine whether the software to be detected is malware.
[0087] Specifically, the comparison result corresponding to the software to be detected is input into multiple pre-trained sub-detection models to obtain the sub-detection results output by each of the multiple sub-detection models. Based on each sub-detection result, the malware detection result of the software to be detected is obtained.
[0088] In this embodiment, first, call data corresponding to the application programming interface called by the software to be detected is obtained. This is because behaviors such as network connection, startup, and memory operation of malware need to be completed by calling the API. That is, calling the API is an unavoidable behavior for malware. Compared with file signatures and software code, using the data of API calls for malware detection is more reliable and accurate. Then, the call data is compared with at least one set of function combination data, that is, the preset combination data, called when the sample software performs malicious actions determined in advance, to obtain a comparison result. Then, the comparison result is input into a pre-trained malware detection model for malware detection to obtain a malware detection result corresponding to the software to be detected, so as to determine whether the software to be detected is malware based on the malware detection result. In this way, it effectively avoids attackers from avoiding malware detection by modifying file signatures or obfuscating software code, thereby improving the accuracy of malware detection.
[0089] In one embodiment, as Figure 3 shown, inputting the comparison result into a pre-trained malware detection model for malware detection to obtain a malware detection result corresponding to the software to be detected includes:
[0090] Step S302, input the comparison result into multiple sub-detection models respectively to obtain multiple sub-detection results.
[0091] Among them, the malware detection model may include sub-detection models corresponding to different types of malicious sample software. This is considering that there are many types of malware, such as Trojans, botnets, ransomware, worms, spyware, etc. Different types of malware may have very different specific behaviors due to different purposes. That is, the API functions called by different types of malware when performing the same malicious behavior may be different. For example, the API functions called by different types of malware to query the running environment are different, and the API functions called by different types of malware to delay malicious actions are also different. Therefore, establishing corresponding sub-detection models for different types of malicious sample software can effectively improve the accuracy of malware recognition. The sub-detection result may refer to the prediction result of the software to be detected in the sub-detection model, and this prediction result may refer to the prediction result that the software to be detected is malware.
[0092] Specifically, after obtaining the sub-detection models corresponding to different types of malicious sample software respectively, input the comparison result corresponding to the software to be detected into each sub-detection model respectively to obtain the sub-detection results output by each sub-detection model.
[0093] Step S304: Determine the proportion of the first results indicating that the software to be detected is malware among multiple sub-detection results, and determine the proportion of the second results indicating that the software to be detected is non-malware among multiple sub-detection results.
[0094] Among them, the proportion of the first results may refer to the proportion of the first results among all sub-detection results, and the first results may be the results indicating that the software to be detected is malware. The proportion of the second results may refer to the proportion of the second results among all sub-detection results, and the second results may be the results indicating that the software to be detected is non-malware.
[0095] Specifically, among multiple sub-detection results, filter out the first results indicating that the software to be detected is malware, and calculate the proportion of the number of the first results in all sub-detection results, that is, the proportion of the first results. And among multiple sub-detection results, filter out the second results indicating that the software to be detected is non-malware, and calculate the proportion of the number of the second results in all sub-detection results, that is, the proportion of the second results.
[0096] Step S306: Obtain the malware detection result according to the proportion of the first results, the proportion of the second results, and the preset proportion threshold.
[0097] Among them, the preset proportion threshold refers to the standard value of the result proportion, and may include the first proportion threshold corresponding to the proportion of the first results and the second proportion threshold corresponding to the proportion of the second results.
[0098] Specifically, if the proportion of the first results reaches the first proportion threshold, it means that more than a certain number of sub-detection models have detected that the software to be detected is malware, then it is determined that the software to be detected is malware. If the proportion of the second results reaches the second proportion threshold, it means that more than a certain number of sub-detection models have detected that the software to be detected is non-malware, then it is determined that the software to be detected is normal software.
[0099] For example, the first proportion threshold can be set to 50%. If the proportion of the first results reaches 50%, it means that half of the sub-detection models have detected that the software to be detected is malware, then it is determined that the software to be detected is malware. Similarly, the second proportion threshold can also be set to 50%. If the proportion of the second results reaches 50%, it means that half of the sub-detection models have detected that the software to be detected is non-malware, then it is determined that the software to be detected is normal software. It should be noted that the preset proportion threshold can also be set to other values, and can also be set according to the actual application situation. The specific setting value is not limited here.
[0100] In this embodiment, based on the sub-detection results output by multiple sub-detection models, the first result proportion indicating that the software to be detected is malware and the second result proportion indicating that the software to be detected is non-malware are obtained. Then, the malware detection result is obtained according to the first result proportion, the second result proportion, and a preset proportion threshold, improving the accuracy of the malware detection result.
[0101] In one embodiment, as Figure 4 shown, before the step of obtaining the call data corresponding to the application programming interface called by the software to be detected, the method further includes: training a malware detection model, including:
[0102] Step S402, obtaining the sample data of each sample software calling the application programming interface.
[0103] Among them, the sample software may include malicious sample software and normal sample software, and the sample data may include malicious sample data generated when the malicious sample software calls the API interface, and normal sample data generated when the normal sample software calls the API interface.
[0104] In one embodiment, the malicious sample data may further include the respective sample call data corresponding to different types of malicious sample software when calling the API interface, and the sample call data may include a sample call function list.
[0105] Specifically, normal sample software and different types of malicious sample software can be obtained first, these normal sample software and malicious sample software are put into a sandbox for running, and the sample call function list during the running process of these malicious sample software is collected, as well as the sample call function list during the running process of the normal sample software is collected.
[0106] Step S404, determining preset combined data based on each sample data.
[0107] Specifically, the function combinations called when the sample software performs malicious actions can be extracted from each sample data, and frequent item mining is performed on these function combinations, that is, the final preset combined data is generated according to the occurrence probability of these function combinations.
[0108] Step S406, determining the training data set corresponding to each sample data according to each sample data and the preset combined data.
[0109] Among them, the training data set may refer to the sample call function list of the normal sample software and the sample call function list of the malicious sample software.
[0110] Specifically, for each malicious sample data, the normal sample data can be divided into each malicious sample data. The normal sample software refers to the software that does not damage the normal operation of the system, and the normal sample data refers to the API function call data when the normal sample software runs in the sandbox. After the malicious sample data with the normal sample data included is used as the training set together with the preset combined data for subsequent model training.
[0111] Step S408: Train a malware detection model based on the training data set.
[0112] Specifically, after obtaining the training data set, model training can be further performed based on the training data set until the model training accuracy or the model iteration times are reached, and a malware detection model is obtained. It should be noted that both the model training accuracy and the model iteration times can be preset.
[0113] In one embodiment, training a malware detection model based on the training data set includes: clustering the training data set according to the types of sample software to obtain multiple sub-training data sets corresponding to the training data set; training a sub-detection model based on each sub-training data set.
[0114] Specifically, after obtaining the training data set, the training data set can be divided by using a clustering algorithm to obtain multiple sub-training data sets. The clustering algorithm can be K-means (k-means clustering algorithm) or DBSCAN (Density-Based Spatial Clustering of Applications with Noise), and thus a sub-detection model is trained based on each sub-training data set.
[0115] In this embodiment, by obtaining the malicious sample data of different types of malicious sample software calling the application programming interface and the normal sample data of the normal sample software calling the application programming interface, the malicious sample data, the normal sample data, and the preset combined data are used as the training data set together. Then, the training data set is clustered to obtain multiple sub-training data sets, and a sub-detection model is trained based on each sub-training data set. This improves the accuracy of the detection model, and thus improves the accuracy of subsequent malware detection using the sub-detection model.
[0116] In one embodiment, as Figure 5 shown, determining the preset combined data based on each sample data includes:
[0117] Step S502: From each sample data, filter out each target combination data, where the target combination data refers to the function combination called by the corresponding sample software when performing malicious actions.
[0118] Among them, the target combination data may refer to the API functions called by the malicious sample software when performing malicious actions, including but not limited to the API functions called by the malicious sample software when querying the running environment, the API functions called by the malicious sample software when delaying malicious actions, the API functions called by the malicious sample software when tampering with files, all the API call functions during the whole process from the start to the end of the malicious sample software, etc.
[0119] Step S504: Obtain the occurrence probability corresponding to each target combination data, where the occurrence probability is used to characterize the frequency of occurrence of the target combination data.
[0120] Among them, the occurrence probability corresponding to each target combination data can be obtained through frequent item mining. Frequent item mining can be implemented based on the Apriori algorithm. The Apriori algorithm is a commonly used data association rule mining method, which can be used to find the data sets that frequently appear in the data set. The occurrence probability can refer to the frequency of occurrence of each target combination data.
[0121] Specifically, from each sample data, filter out each target combination data, and then use the Apriori algorithm to calculate the occurrence probability of each target combination data.
[0122] Step S506: Generate a frequent item set based on the occurrence probability and a preset support threshold.
[0123] Among them, the frequent item set refers to the data set whose occurrence probability reaches the preset support threshold. The support threshold refers to the standard proportion of the records containing this item set in the data set.
[0124] Specifically, if it is detected that the occurrence probability of each target combination data reaches the preset support threshold, then the target combination data corresponding to this occurrence probability is used as the frequent item set.
[0125] In one embodiment, the support threshold can be set to 5% multiplied by the number of target combination data.
[0126] In one embodiment, the expression of the frequent item set can be:
[0127]
[0128] Among them, api_freq_item represents the target combination data, and api_freq_num represents the number of target combination data.
[0129] For example, api_freq_items can be {GetInterfaceInfo, NtOpenProcess}, where GetInterfaceInfo refers to the API call function when extracting network interface information, and NtOpenProcess refers to the API call function for actually performing the operation of opening a process. api_freq_items can also be {NtQuerySystemInformation, FindNextChangeNotification, NtDelayExecution}, where both NtQuerySystemInformation and FindNextChangeNotification refer to the API call functions for querying the system running environment information, and NtDelayExecution refers to the API call function for delaying the execution of malicious actions.
[0130] In one embodiment, the preset combined data can be a combination between two target combined data, or a combination between three or more target combined data. The target combined data can be arranged according to the occurrence time, or randomly arranged. Specifically, it can be adjusted according to the actual situation.
[0131] Step S508: Perform redundancy processing on the frequent item sets to obtain the preset combined data.
[0132] Among them, in order to ensure the accuracy of the obtained preset combined data, redundancy processing can be performed on each frequent item set, that is, the duplicate sets in the frequent item set are removed to obtain the candidate item set corresponding to each frequent item set. In this way, it can prevent the model from performing multiple comparisons due to a large number of duplicate features in the preset combined data, thereby reducing the model detection efficiency and further reducing the malicious software detection efficiency. Therefore, this embodiment can effectively improve the malicious software detection efficiency.
[0133] In one embodiment, each frequent item in the frequent item set is obtained; redundancy detection is performed on each frequent item to obtain the redundancy detection result corresponding to each frequent item, where the redundancy detection result is used to indicate whether the frequent item exists in other frequent items in the frequent item set; based on each redundancy detection result, the preset combined data is obtained.
[0134] Specifically, for each frequent item in the frequent item set, redundancy detection is performed on each frequent item, that is, it is detected whether there are other frequent items in the frequent item set such that the current frequent item exists in other frequent items, and a redundancy detection result is obtained. If the redundancy detection result is that the frequent item exists in other frequent items, it means that the frequent item is repeated, and then the frequent item is deleted from the frequent item set. If the redundancy detection result is that the frequent item does not exist in other frequent items, it means that the frequent item is not repeated, and then the frequent item is retained.
[0135] For example, for any one api_freq_item in api_freq_items i , if there is another api_freq_item in api_freq_items j that satisfies api_freq_item i ⊆ api_freq_item j , then api_freq_item i is deleted from api_freq_items.
[0136] Specifically, for api_freq_item i = {GetInterfaceInfo, NtOpenProcess}, api_freq_item j= {GetInterfaceInfo, NtOpenProcess, NtQueryValueKey}, since api_freq_item j already contains the information in api_freq_item i , only api_freq_item j needs to be retained.
[0137] In this embodiment, by performing frequent item mining on each malicious sample data, the frequent item set corresponding to each malicious sample data is obtained, and then redundancy processing is performed on each frequent item set to obtain the preset combined data. In this way, it is ensured that each set of features in the preset combined data will frequently appear, improving the reliability and accuracy of the preset combined data, and thus improving the reliability and accuracy of subsequent malicious software detection based on the preset combined data.
[0138] In one embodiment, the malware may be ransomware, and the detection method for ransomware may include: obtaining the call data corresponding to the application programming interface called by the software to be detected. Comparing the call data with preset combined data to obtain a comparison result, where the preset combined data refers to at least one set of function combined data called when a sample software performs a ransom action. Inputting the comparison result into a pre-trained malware detection model to perform malware detection and obtaining a malware detection result corresponding to the software to be detected.
[0139] In this embodiment, by directly comparing the call data of the software to be detected with the preset combined data, and the preset combined data is at least one set of function combined data called when the sample software performs a ransom action. If it is detected that the preset combined data exists in the call data, it is determined that the software to be detected is ransomware. In this way, it effectively avoids attackers from avoiding the detection of ransomware by modifying the file signature or obfuscating the software code, thereby improving the accuracy of ransomware detection.
[0140] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are displayed in sequence according to the arrows, these steps do not necessarily need to be executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily need to be executed at the same time, but can be executed at different times. The execution order of these steps or stages does not necessarily need to be sequential, but can be executed alternately or alternately with at least a part of other steps or steps in other steps.
[0141] Based on the same inventive concept, an embodiment of the present application further provides a malware detection device for implementing the above-mentioned malware detection method. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the malware detection device provided below can refer to the limitations on the malware detection method in the above text, and will not be repeated here.
[0142] In one embodiment, as Figure 6 shown, a malware detection device is provided, including: a data acquisition module 602, a comparison module 604, and a model detection module 606, where:
[0143] The data acquisition module 602 is used to obtain the call data corresponding to the application programming interface called by the software to be detected;
[0144] A comparison module 604, configured to compare the call data with preset combined data to obtain a comparison result, where the preset combined data refers to at least one set of function combined data called when a sample software executes malicious actions and is determined in advance;
[0145] A model detection module 606, configured to input the comparison result into a pre-trained malware detection model for malware detection to obtain a malware detection result corresponding to the software to be detected.
[0146] In one embodiment, the model detection module 606 further includes:
[0147] A sub-detection unit, configured to input the comparison result into a plurality of the sub-detection models respectively to obtain a plurality of sub-detection results;
[0148] A determination ratio unit, configured to determine a ratio of a first result indicating that the software to be detected is malware among the plurality of sub-detection results, and determine a ratio of a second result indicating that the software to be detected is non-malware among the plurality of sub-detection results;
[0149] A determination result unit, configured to obtain the malware detection result according to the first result ratio, the second result ratio, and a preset ratio threshold.
[0150] In one embodiment, the comparison module 604 is further configured to:
[0151] Detect whether each of the function combined data exists in the call data;
[0152] If it exists in the call data, generate a first comparison result corresponding to each of the function combined data;
[0153] If it does not exist in the call data, generate a second comparison result corresponding to each of the function combined data;
[0154] According to the first comparison result and the second comparison result, obtain a comparison result corresponding to the software to be detected.
[0155] In one embodiment, the malware detection device further includes:
[0156] A sample acquisition module, configured to acquire sample data of each sample software calling the application programming interface;
[0157] A preset combined data determination module, configured to determine the preset combined data based on each of the sample data;
[0158] A training set determination module, configured to determine a training data set corresponding to each of the sample data according to each of the sample data and the preset combined data;
[0159] A model training module, configured to train the malware detection model based on the training data set.
[0160] In one embodiment, the preset combined data determination module further includes:
[0161] A screening unit, configured to screen out each target combined data from each of the sample data, where the target combined data refers to a function combination called by the sample software corresponding to each of the sample data when performing malicious actions;
[0162] An occurrence probability calculation unit, configured to obtain the occurrence probability corresponding to each of the target combined data, where the occurrence probability is used to characterize the frequency of occurrence of the target combined data;
[0163] A frequent item set generation unit, configured to generate a frequent item set based on the occurrence probability and a preset support threshold;
[0164] A redundancy processing unit, configured to perform redundancy processing on the frequent item set to obtain the preset combined data.
[0165] In one embodiment, the redundancy processing unit is further configured to:
[0166] Obtain each frequent item in the frequent item set;
[0167] Perform redundancy detection on each of the frequent items to obtain a redundancy detection result corresponding to each of the frequent items, where the redundancy detection result is used to indicate whether the frequent item exists in other frequent items in the frequent item set;
[0168] Obtain the preset combined data based on each of the redundancy detection results.
[0169] In one embodiment, the model training module is further configured to:
[0170] Cluster the training data set according to the type of the sample software to obtain a plurality of sub-training data sets corresponding to the training data set;
[0171] Train one sub-detection model based on each of the sub-training data sets.
[0172] Each module in the above malware detection device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above respective modules.
[0173] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structural diagram may be as shown in Figure 7 . The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store item recommendation data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a malware detection method.
[0174] Those skilled in the art can understand that Figure 7 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0175] In one embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented:
[0176] Obtain the call data corresponding to the application programming interface called by the software to be detected;
[0177] Compare the call data with preset combined data to obtain a comparison result. Among them, the preset combined data refers to at least one set of function combined data called when a sample software performs malicious actions;
[0178] Input the comparison result into a pre-trained malware detection model for malware detection to obtain the malware detection result corresponding to the software to be detected.
[0179] In one embodiment, when the processor executes the computer program, the following steps are further implemented:
[0180] Input the comparison result into multiple sub-detection models respectively to obtain multiple sub-detection results;
[0181] Determine the proportion of the first results indicating that the software to be detected is malware among the multiple sub-detection results, and determine the proportion of the second results indicating that the software to be detected is non-malware among the multiple sub-detection results;
[0182] Obtain the malware detection result based on the first result ratio, the second result ratio, and a preset ratio threshold.
[0183] In one embodiment, when the processor executes the computer program, the following steps are further implemented:
[0184] Detect whether each piece of function combination data exists in the call data;
[0185] If it exists in the call data, generate a first comparison result corresponding to each piece of function combination data;
[0186] If it does not exist in the call data, generate a second comparison result corresponding to each piece of function combination data;
[0187] Obtain the comparison result corresponding to the software to be detected according to the first comparison result and the second comparison result.
[0188] In one embodiment, when the processor executes the computer program, the following steps are further implemented:
[0189] Obtain the sample data of each sample software calling the application programming interface;
[0190] Based on each piece of sample data, determine the preset combined data;
[0191] According to each piece of sample data and the preset combined data, determine the training data set corresponding to each piece of sample data;
[0192] Train the malware detection model based on the training data set.
[0193] In one embodiment, when the processor executes the computer program, the following steps are further implemented:
[0194] In each piece of sample data, screen out each piece of target combined data, where the target combined data refers to the function combination called by the sample software corresponding to each piece of sample data when performing malicious actions;
[0195] Obtain the occurrence probability corresponding to each piece of target combined data, where the occurrence probability is used to characterize the frequency of occurrence of the target combined data;
[0196] Generate a frequent item set based on the occurrence probability and a preset support threshold;
[0197] Perform redundancy processing on the frequent item set to obtain the preset combined data.
[0198] In one embodiment, when the processor executes the computer program, the following steps are further implemented:
[0199] Obtain each frequent item in the frequent item set;
[0200] Perform redundancy detection on each of the frequent items to obtain a redundancy detection result corresponding to each of the frequent items, where the redundancy detection result is used to indicate whether the frequent item exists in other frequent items in the frequent item set;
[0201] Based on each of the redundancy detection results, obtain the preset combined data.
[0202] In one embodiment, when the processor executes the computer program, the following steps are further implemented:
[0203] Cluster the training data set according to the type of the sample software to obtain a plurality of sub-training data sets corresponding to the training data set;
[0204] Train one sub-detection model based on each of the sub-training data sets.
[0205] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0206] Obtain the call data corresponding to the application programming interface called by the software to be detected;
[0207] Compare the call data with the preset combined data to obtain a comparison result, where the preset combined data refers to at least one set of function combination data called when the sample software executes malicious actions;
[0208] Input the comparison result into a pre-trained malware detection model for malware detection to obtain a malware detection result corresponding to the software to be detected.
[0209] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:
[0210] Input the comparison result into a plurality of the sub-detection models respectively to obtain a plurality of sub-detection results;
[0211] Determine the proportion of the first results indicating that the software to be detected is malware among the plurality of sub-detection results, and determine the proportion of the second results indicating that the software to be detected is non-malware among the plurality of sub-detection results;
[0212] Obtain the malware detection result according to the first result proportion, the second result proportion, and a preset proportion threshold.
[0213] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:
[0214] Check whether each of the function combination data exists in the call data;
[0215] If it exists in the call data, generate a first comparison result corresponding to each of the function combination data;
[0216] If it does not exist in the call data, generate a second comparison result corresponding to each of the function combination data;
[0217] According to the first comparison result and the second comparison result, obtain the comparison result corresponding to the software to be detected.
[0218] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0219] Obtain sample data of each sample software calling the application programming interface;
[0220] Based on each of the sample data, determine the preset combination data;
[0221] According to each of the sample data and the preset combination data, determine a training data set corresponding to each of the sample data;
[0222] Train the malware detection model based on the training data set.
[0223] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0224] In each of the sample data, screen out each target combination data, where the target combination data refers to the function combination called by the sample software corresponding to each of the sample data when performing malicious actions;
[0225] Obtain the occurrence probability corresponding to each of the target combination data, where the occurrence probability is used to characterize the frequency of occurrence of the target combination data;
[0226] Generate a frequent item set based on the occurrence probability and a preset support threshold;
[0227] Perform redundancy processing on the frequent item set to obtain the preset combination data.
[0228] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0229] Obtain each frequent item in the frequent item set;
[0230] Perform redundancy detection on each of the frequent items to obtain a redundancy detection result corresponding to each of the frequent items, where the redundancy detection result is used to indicate whether the frequent item exists in other frequent items in the frequent item set;
[0231] Based on each of the redundancy detection results, obtain the preset combined data.
[0232] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0233] Cluster the training data set according to the type of the sample software to obtain a plurality of sub-training data sets corresponding to the training data set;
[0234] Train one of the sub-detection models based on each of the sub-training data sets.
[0235] In one embodiment, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the following steps are implemented:
[0236] Obtain the call data corresponding to the application programming interface called by the software to be detected;
[0237] Compare the call data with the preset combined data to obtain a comparison result, where the preset combined data refers to at least one set of function combined data called when the sample software performs malicious actions;
[0238] Input the comparison result into a pre-trained malware detection model to perform malware detection, and obtain the malware detection result corresponding to the software to be detected.
[0239] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0240] Input the comparison result into a plurality of the sub-detection models respectively to obtain a plurality of sub-detection results;
[0241] Determine the proportion of the first results indicating that the software to be detected is malware among the plurality of sub-detection results, and determine the proportion of the second results indicating that the software to be detected is non-malware among the plurality of sub-detection results;
[0242] Obtain the malware detection result according to the proportion of the first results, the proportion of the second results, and a preset proportion threshold.
[0243] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0244] Detect whether each of the function combined data exists in the call data;
[0245] If it exists in the call data, generate a first comparison result corresponding to each of the function combined data;
[0246] If it does not exist in the call data, generate a second comparison result corresponding to each function combination data;
[0247] According to the first comparison result and the second comparison result, obtain the comparison result corresponding to the software to be detected.
[0248] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0249] Obtain sample data of each sample software calling the application programming interface;
[0250] Based on each sample data, determine the preset combination data;
[0251] According to each sample data and the preset combination data, determine a training data set corresponding to each sample data;
[0252] Train the malware detection model based on the training data set.
[0253] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0254] In each sample data, screen out each target combination data, where the target combination data refers to the function combination called by the sample software corresponding to each sample data when performing malicious actions;
[0255] Obtain the occurrence probability corresponding to each target combination data, where the occurrence probability is used to characterize the frequency of occurrence of the target combination data;
[0256] Generate a frequent item set based on the occurrence probability and a preset support threshold;
[0257] Perform redundancy processing on the frequent item set to obtain the preset combination data.
[0258] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0259] Obtain each frequent item in the frequent item set;
[0260] Perform redundancy detection on each frequent item to obtain a redundancy detection result corresponding to each frequent item, where the redundancy detection result is used to indicate whether the frequent item exists in other frequent items in the frequent item set;
[0261] Based on each redundancy detection result, obtain the preset combination data.
[0262] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:
[0263] Cluster the training data set according to the type of the sample software to obtain a plurality of sub-training data sets corresponding to the training data set;
[0264] Train one sub-detection model based on each of the sub-training data sets.
[0265] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0266] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., and are not limited thereto. The processors involved in the embodiments provided in this application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., and are not limited thereto.
[0267] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0268] The above-described embodiments merely represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. A malware detection method, characterized in that, The method includes: Obtaining call data corresponding to the application programming interface called by the software to be detected; Comparing the call data with preset combined data to obtain a comparison result, where the preset combined data refers to at least one set of function combined data called when a sample software executes malicious actions; Inputting the comparison result into a pre-trained malware detection model for malware detection to obtain a malware detection result corresponding to the software to be detected.
2. The method according to claim 1, characterized in that, The malware detection model includes multiple sub-detection models, and the multiple sub-detection models are trained according to different types of sample software; The step of inputting the comparison result into a pre-trained malware detection model for malware detection to obtain a malware detection result corresponding to the software to be detected includes: Inputting the comparison result into multiple sub-detection models respectively to obtain multiple sub-detection results; Determining the proportion of the first results indicating that the software to be detected is malware among the multiple sub-detection results, and determining the proportion of the second results indicating that the software to be detected is non-malware among the multiple sub-detection results; Obtaining the malware detection result according to the first result proportion, the second result proportion, and a preset proportion threshold.
3. The method according to claim 1, characterized in that, The step of comparing the call data with preset combined data to obtain a comparison result includes: Detecting whether each function combined data exists in the call data; If it exists in the call data, generating a first comparison result corresponding to each function combined data; If it does not exist in the call data, generating a second comparison result corresponding to each function combined data; Obtaining a comparison result corresponding to the software to be detected according to the first comparison result and the second comparison result.
4. The method according to claim 1, characterized in that, Before the step of obtaining call data corresponding to the application programming interface called by the software to be detected, the method further includes: training the malware detection model, including: Obtaining sample data of each sample software calling the application programming interface; Based on each sample data, determining the preset combined data; According to each sample data and the preset combined data, determining a training data set corresponding to each sample data; Training the malware detection model based on the training data set.
5. The method according to claim 4, characterized in that, The step of determining the preset combined data based on each sample data includes: Screening out each target combined data from each sample data, where the target combined data refers to the function combination called by the sample software corresponding to each sample data when executing malicious actions; Obtaining the occurrence probability corresponding to each target combined data, where the occurrence probability is used to characterize the frequency of occurrence of the target combined data; Generating a frequent item set based on the occurrence probability and a preset support threshold; Performing redundancy processing on the frequent item set to obtain the preset combined data.
6. The method according to claim 5, characterized in that, The step of performing redundancy processing on the frequent item set to obtain the preset combined data includes: Obtaining each frequent item in the frequent item set; Redundancy detection is performed on each of the frequent items to obtain a redundancy detection result corresponding to each of the frequent items, where the redundancy detection result is used to indicate whether the frequent item exists in other frequent items in the frequent item set; Based on each of the redundancy detection results, the preset combined data is obtained.
7. The method according to claim 4, characterized in that, The malware detection model includes a plurality of sub-detection models, and training the malware detection model based on the training data set includes: Clustering the training data set according to the type of the sample software to obtain a plurality of sub-training data sets corresponding to the training data set; Training one of the sub-detection models based on each of the sub-training data sets.
8. A malware detection device, characterized in that, The device includes: A data acquisition module, configured to acquire call data corresponding to an application programming interface called by the software to be detected; A comparison module, configured to compare the call data with preset combined data to obtain a comparison result, where the preset combined data refers to at least one set of function combined data called when a sample software performs a malicious action; A model detection module, configured to input the comparison result into a pre-trained malware detection model to perform malware detection and obtain a malware detection result corresponding to the software to be detected.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium, having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 7 are implemented.