Malicious program perception and reverse behavior intervention method and system based on brain-like calculation and medium

Through the malicious program perception and reverse behavior intervention methods based on brain-like computing, the problem of insufficient real-time and adaptability of the existing technology in the face of new threats is solved, efficient malicious program detection and response is achieved, and the system's defense capabilities are significantly improved.

CN120197168APending Publication Date: 2025-06-24HUBEI CENT CHINA TECH DEV OF ELECTRIC POWER
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510222886.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

Existing malicious program detection technology is insufficient in real-time and adaptability when facing new threats, and malicious programs have self-concealment capabilities, making it difficult to identify and respond in a timely manner.

Method used

The malicious program perception and reverse behavior intervention method based on brain-like computing is adopted to conduct preliminary cognition and reasoning of malicious program behavior through brain-like neural network model, generate dynamic risk scores, infer behavior paths and intentions, and generate real-time intervention plans through reinforcement learning algorithms, and dynamically adjust model parameters in combination with feedback adaptive optimization mechanisms.

Benefits of technology

It significantly improves the detection and response capabilities of new malicious programs, improves identification accuracy and response speed, reduces false alarm rates, enhances the system's defense capabilities, and can dynamically adapt to new threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120197168A_ABST
    Figure CN120197168A_ABST
Patent Text Reader

Abstract

The invention provides a malicious program perception and reverse behavior intervention method and system based on brain-like calculation and a medium, and aims to improve the efficiency and accuracy of malicious program detection and defense. According to the method, the brain-like calculation model is constructed, preliminary cognition and dynamic perception are carried out on behaviors of malicious programs, risk scores are generated, and then behavior reverse analysis is carried out. By using the time sequence and the state transition probability, the system can speculate the behavior path and intention of the rogue program and generate a self-adaptive intervention decision based on the behavior path and intention. And model parameters are adjusted in real time by feeding back a self-adaptive optimization mechanism so as to adapt to novel threats. Experimental results show that the method is superior to the prior art in the aspects of malicious program identification, risk assessment and system security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of computer systems and network security, and specifically to a malicious program perception and reverse behavior intervention method, system, and medium based on brain-inspired computing. Background Art

[0002] With the rapid development of information technology, the threat of malicious programs (such as viruses, Trojans, worms, etc.) to computer systems and network security has become increasingly serious. These malicious programs can not only cause information leakage and data damage, but may also cause incalculable economic losses to the entire network environment. Traditional malicious program detection technologies mainly rely on signature matching and behavior analysis. Although they can effectively identify known threats in some cases, their ability to identify new malicious programs is relatively insufficient, especially in complex and changing network environments.

[0003] Existing detection methods mostly adopt a combination of static analysis and dynamic monitoring. However, due to the continuous evolution of malicious program technologies and the increasing complexity of their attack methods, traditional technologies face challenges in terms of real-time performance and adaptability. In addition, many malicious programs have the ability to self-conceal and can evade detection through metamorphosis or encryption technologies, resulting in the inability of existing systems to respond in a timely manner. Therefore, there is an urgent need for a more intelligent and flexible malicious program detection and intervention method to enhance the ability to prevent new threats. Summary of the Invention

[0004] The present invention is a malicious program perception and reverse behavior intervention method based on brain-inspired computing, which solves the deficiencies of existing malicious program detection technologies in the face of new threats.

[0005] A malicious program perception and reverse behavior intervention method based on brain-inspired computing provided by the present invention includes the following steps:

[0006] Step 1. Initialization of the brain-inspired computing model

[0007] Construct and initialize a brain-inspired neural network model to achieve preliminary cognition and reasoning of malicious program behaviors. The expression is as follows:

[0008]

[0009] Where C(x) represents the preliminary cognition result of malicious program behaviors, M is the number of layers of the network, N j is the number of neurons in the j-th layer, W ji is the weight between the j-th layer and the i-th neuron, b j is the bias term, σ is the activation function, g k is the k-th input factor, h k is the weight of the k-th factor, α kis the control factor. In this step, the brain-inspired computing model performs weighted summation and activation processing on the input feature x, and outputs C(x) as the preliminary cognitive result, providing a basic judgment on the behavior of malicious programs for the subsequent modules.

[0010] Step 2. Dynamic perception of malicious programs

[0011] Based on the preliminary cognitive result C(x) generated in Step 1, further perceive the behavior characteristics of malicious programs, and the expression is as follows:

[0012]

[0013] where P(x) is the risk score of the behavior of malicious programs, N is the number of features, w i is the weight of the i-th feature, f i (C(x)) is the feature mapping function based on the preliminary cognitive result, and ∈ is the noise term. The perception module uses C(x) as the input, and through weighted feature mapping and noise adjustment, generates the risk score P(x) of malicious programs, providing an accurate risk assessment for further analysis.

[0014] Step 3. Behavioral reverse analysis

[0015] Use the risk score P(x) in Step 2 to speculate on the behavior path and intention of malicious programs, and the expression is as follows:

[0016]

[0017] where A(b) is the result of reverse analysis, T is the length of the time series, γ is the discount factor, R t,j is the reward value at a certain time point, P(s u+1 s u , P(x)) is the transition probability based on the current state and risk score, and δ υ is the random noise term.

[0018] Step 4. Generation of intervention decisions

[0019] Based on the analysis result A(b) in Step 3, generate a real-time intervention plan for malicious programs, and the expression is as follows:

[0020]

[0021] where D t is the optimal intervention strategy at time t, a is the optional operation, and R t (A(b), a) is the reward value of executing the operation under the analysis result A(b). The decision-making module calculates the optimal intervention strategy D t to interrupt the key behaviors of malicious programs and ensure system security.

[0022] Step 5. Feedback Adaptive Optimization

[0023] Use the intervention effect of Step 4 to adjust the model parameters in real time to ensure that the system adapts to new threats. The expression is as follows:

[0024]

[0025] where θ t is the model parameter at the t-th iteration, η is the learning rate, is the gradient based on the intervention strategy D t of.

[0026] Furthermore, Step 1 is implemented using a brain-inspired computing module. The brain-inspired computing module adopts a multi-layer neural network structure with randomly distributed initial weights to ensure adaptive learning ability and is continuously updated in combination with a feedback adaptive optimization mechanism.

[0027] Furthermore, Step 2 is implemented using a perception module. The perception module supports multi-dimensional input features and uses the noise term ∈ to adjust the risk score to ensure the accuracy and stability of detection.

[0028] Furthermore, Step 3 is implemented using a reverse analysis module. The reverse analysis module accurately infers the behavior path and potential attack strategy of malicious programs through time series analysis and state transition probabilities.

[0029] Furthermore, Step 4 is implemented using an intervention decision module. The intervention decision module uses a reinforcement learning algorithm to generate an optimal intervention plan and preferentially intercepts high-risk operations to ensure system security.

[0030] Furthermore, Step 5 is implemented using a feedback adaptive optimization module. The feedback adaptive optimization module improves the dynamic adaptation ability of the model through parameter update based on historical data and real-time response results.

[0031] A malicious program perception and reverse behavior intervention system based on brain-inspired computing, comprising: a computer-readable storage medium and a processor;

[0032] The computer-readable storage medium is used to store executable instructions;

[0033] The processor is used to read the executable instructions stored in the computer-readable storage medium and execute the malicious program perception and reverse behavior intervention method based on brain-inspired computing.

[0034] A non-transitory computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the malicious program perception and reverse behavior intervention method based on brain-inspired computing.

[0035] The present invention has the following advantages:

[0036] 1. Brain-inspired computing: The present invention adopts a brain-inspired computing model to simulate the cognitive and decision-making processes of the human brain, enabling the system to perform deep learning and intelligent reasoning, and improving the understanding and analysis capabilities of malicious program behaviors.

[0037] 2. Dynamic risk scoring: By generating dynamic risk scores in real time, the system can timely identify the behavioral characteristics of malicious programs, thereby improving the detection accuracy and response speed, and reducing the false alarm rate.

[0038] 3. Reverse behavior analysis: By inferring the behavioral paths and attack intentions of malicious programs, the system can take targeted intervention measures before an attack occurs, significantly enhancing the system's defense capabilities.

[0039] 4. Real-time intervention mechanism: The system can generate intervention plans in real time according to the analysis results, and use reinforcement learning algorithms to calculate the optimal intervention strategies, effectively interrupting the key behaviors of malicious programs and ensuring network security.

[0040] 5. Adaptive optimization: Through a feedback adaptive optimization mechanism, the system can dynamically adjust the model parameters according to historical data and real-time response effects, improving the adaptability to new threats and maintaining a continuously effective protection level. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] Figure 1 is a flowchart of the method for malicious program perception and reverse behavior intervention based on brain-inspired computing of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0042] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0043] Figure 1 The following shows a method for malicious program perception and reverse behavior intervention based on brain-inspired computing in an embodiment of the present invention, including the following steps: construction of a brain-inspired computing model, dynamic perception of malicious programs, reverse behavior analysis, generation of intervention decisions, and feedback adaptive optimization. To verify the effectiveness of the present invention, a series of experiments were carried out, using malicious program samples and network traffic data for testing.

[0044] 1. Construction of the brain-inspired computing model

[0045] In this embodiment, a brain-inspired neural network model with a five-layer multi-layer perceptron (MLP) structure is constructed, which is mainly used to model the behavioral characteristics of malicious programs. The model structure is as follows:

[0046] Input layer: It contains 100 feature nodes, which are specifically used to extract traffic features related to malicious programs, such as packet size, transmission frequency, target port, protocol type, etc.

[0047] Hidden layers: It contains 64, 32, and 16 neurons, and the ReLU activation function is used for all of them to enhance the non-linear fitting ability of the model.

[0048] Output layer: 1 neuron, which outputs the risk score of the malicious program.

[0049] 2. Dataset

[0050] Table 1: Dataset

[0051] Traffic type Number of samples Number of features Main malware type Normal traffic 1000 15 Malicious traffic 500 15 Trojan, ransomware, virus

[0052] 3. Model training

[0053] 80% of the sample data is used for training, and 20% of the sample data is used for validation. Through the Adam optimizer, the mean squared error (MSE) is used as the loss function. During the training process, the training loss and validation loss are recorded, and the results are shown in Table 2:

[0054] Table 2: Training table

[0055] Number of training rounds Training loss Validation loss 1 0.753 0.780 2 0.496 0.512 3 0.339 0.350 4 0.237 0.245 5 0.165 0.175

[0056] 4. Generation of malicious program perception risk score

[0057] The trained model is used to predict the test set to generate the risk score of the malicious program. The experimental results are shown in Table 2, and the actual labels and predicted risk scores of the samples are shown in Table 3:

[0058] Table 3: Risk score table

[0059] Sample number Risk score Actual label 1 0.05 Normal traffic 2 0.88 Malicious traffic 3 0.72 Malicious traffic 4 0.02 Normal traffic 5 0.95 Malicious traffic

[0060] 5. Behavioral reverse analysis

[0061] The traffic samples with a risk score exceeding 0.7 are subjected to reverse analysis to infer their attack paths and intentions. The following are the analysis results shown in Table 4:

[0062] Table 4: Behavioral reverse analysis table

[0063] Attack type Number of samples Ratio Trojan 40 40% Ransomware 50 50% Virus 10 10%

[0064] 6. Intervention decision generation

[0065] Based on the results of reverse analysis, the system generates intervention decisions for malicious programs. The following intervention strategies are implemented and the success rate and false positive rate are recorded. The results are shown in Table 5:

[0066] Table 5: Intervention Decision Table

[0067] Intervention strategy Intervention success rate False positive rate Blocked traffic 90% 4% Recorded behavior 80% 6% Blocked IP 85% 5%

[0068] 7. Feedback Adaptive Optimization

[0069] Based on the intervention effect, the model is feedback optimized. The optimization results are shown in Table 6, which shows the changes in precision, recall, and F1 score before and after optimization:

[0070] Table 6: Adaptive Optimization Table

[0071] Number of optimization rounds Precision Recall F1 score 0 87% 82% 84.5% 1 91% 88% 89.5% 2 94% 92% 93%

[0072] 8. The experimental results show that the present invention has the following innovations:

[0073] (1) Brain-inspired computing model: Existing technologies usually adopt traditional rule matching and feature-based detection methods, which are often insufficient when facing complex malicious programs. The present invention introduces a brain-inspired computing model and uses a multi-layer neural network structure, which can significantly improve the recognition accuracy and reaction speed by learning and adapting to the changes of malicious programs.

[0074] (2) Dynamic risk scoring mechanism: Traditional methods mostly rely on static features or simple scoring systems, which are difficult to reflect the real risks of malicious programs. The present invention can generate accurate risk scores in real time through a dynamic risk scoring mechanism, combined with multi-dimensional input features and noise adjustment, ensuring the timely identification of potential threats and avoiding the limitations of high false positives and missed detections in existing technologies.

[0075] (3) Behavioral reverse analysis: Current malicious program analysis methods often stay at static analysis or monitoring of single behaviors, and cannot effectively predict the future behaviors and attack intentions of malicious programs. The present invention adopts methods of time series analysis and state transition probability, which can deeply infer the behavioral paths and potential attack strategies of malicious programs, providing strong support for formulating effective countermeasures.

[0076] (4) Adaptive intervention decision generation: Traditional intervention strategies are often based on historical experience and lack flexibility, and cannot respond to new threats in real time. The present invention uses a reinforcement learning algorithm to generate adaptive intervention strategies, which can adjust decisions according to real-time data, prioritize high-risk operations, and greatly improve the security and response capabilities of the system.

[0077] (5) Feedback Adaptive Optimization Mechanism: In the face of new malicious programs, existing technologies often struggle to effectively update model parameters, leading to a decline in detection capabilities. Through the feedback adaptive optimization mechanism, the present invention realizes the dynamic adjustment and continuous improvement of the model, ensuring high detection and intervention capabilities in a rapidly changing network security environment.

[0078] (6) Comprehensive Evaluation and Experimental Data Support: Traditional methods lack sufficient experimental verification, while the present invention verifies its effectiveness and feasibility through experimental data in a real environment. Experimental results show that the present invention is superior to existing technologies in multiple key performance indicators, such as reducing the false alarm rate, increasing the detection rate, and shortening the response time, demonstrating its great potential and advantages in practical applications.

[0079] Another embodiment of the present invention provides a malicious program perception and reverse behavior intervention system based on brain-inspired computing, including: a computer-readable storage medium and a processor;

[0080] The computer-readable storage medium is used to store executable instructions;

[0081] The processor is used to read the executable instructions stored in the computer-readable storage medium and execute the malicious program perception and reverse behavior intervention method based on brain-inspired computing described in the first aspect.

[0082] Another embodiment of the present invention provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the malicious program perception and reverse behavior intervention method based on brain-inspired computing described in the first aspect.

[0083] Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.

[0084] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate for implementation in the processFigure 1 one or more processes and / or blocks Figure 1 means for the functions specified in one or more blocks

[0085] These computer program instructions can also be stored in a computer-readable memory capable of guiding a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured article including an instruction device, and the instruction device implements the processes Figure 1 one or more processes and / or blocks Figure 1 the functions specified in one or more blocks

[0086] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide for implementing the processes Figure 1 one or more processes and / or blocks Figure 1 the steps of the functions specified in one or more blocks

[0087] The present invention proposes a malicious program perception and reverse behavior intervention method based on brain-inspired computing. The method first constructs and initializes a brain-inspired neural network model, and realizes the preliminary cognition and reasoning of the behavior of the malicious program by inputting the feature data of the malicious program. Then, a dynamic risk score is generated based on the preliminary cognition result to further perceive the behavior characteristics of the malicious program. Subsequently, the risk score is used to speculate the behavior path and attack intention of the malicious program, and a real-time intervention plan is generated according to the analysis result. The reinforcement learning algorithm is used to calculate the optimal intervention strategy to effectively interrupt the key behaviors of the malicious program. Finally, the system adjusts the model parameters in real time according to the intervention effect through a feedback adaptive optimization mechanism to ensure that it can dynamically adapt to new threats. This method combines the intelligent advantages of brain-inspired computing technology and the effectiveness of existing detection means, significantly improves the detection and response capabilities for new malicious programs, and has broad application prospects.

[0088] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: the specific implementation manners of the present invention can still be modified or equivalently replaced, and any modification or equivalent replacement without departing from the spirit and scope of the present invention should be covered by the protection scope of the claims of the present invention.

Claims

1. A method for malicious program perception and reverse behavior intervention based on brain-like computing, characterized in that: The following steps are involved: Step 1. Initialize the brain-like computing model Construct and initialize a brain-like neural network model to achieve preliminary cognition and reasoning of malicious program behavior. The expression is as follows: Where C(x) represents the initial cognitive result of the malicious program behavior, M is the number of layers in the network, and N j is the number of neurons in the jth layer, W ji is the weight between the jth layer and the i-th neuron, b j is the bias term, σ is the activation function, g k is the kth input factor, h k is the weight of the kth factor, α k is the control factor; Step 2. Dynamic detection of malicious programs According to the preliminary cognitive result C(x) generated in step 1, the behavioral characteristics of the malicious program are further perceived, and the expression is as follows: Where P(x) is the risk score of the malicious program behavior, N is the number of features, and w i is the weight of the i-th feature, f i (C(x)) is the feature mapping function based on the preliminary cognitive results, ∈ is the noise term; Step 3. Behavior Reverse Engineering Use the risk score P(x) in step 2 to infer the behavior path and intention of the malicious program. The expression is as follows: Where A(b) is the result of the reverse analysis, T is the length of the time series, γ is the discount factor, and R t,j is the reward value at a certain time point, P(s u+1 |s u , P(x)) is the transition probability based on the current state and risk score, δ v is the random noise term; Step 4. Intervention decision making Based on the reverse analysis result A(b) in step 3, a real-time intervention plan for the malicious program is generated, which is expressed as follows: Where D t is the optimal intervention strategy at time t, a is an optional operation, R t (A(b), a) is the reward value for performing the operation under the analysis result A(b); Step 5. Feedback Adaptive Optimization Optimal intervention strategy D using step 4 t , adjust the model parameters in real time to ensure that the system adapts to new threats. The expression is as follows: where θ t is the model parameter at the tth iteration, η is the learning rate, Based on intervention strategy D t gradient.

2. The method according to claim 1, characterized in that Step 1 is implemented using a brain-like computing module, which adopts a multi-layer neural network structure with random initial weights to ensure adaptive learning capabilities, and is continuously updated in combination with a feedback adaptive optimization mechanism.

3. The method according to claim 1, characterized in that Step 2 is implemented using the perception module, which supports multi-dimensional input features and uses the noise term ∈ to adjust the risk score to ensure the accuracy and stability of detection.

4. The method according to claim 1, characterized in that: Step 3 is implemented using a reverse analysis module, which accurately infers the behavior path and potential attack strategies of malicious programs through time series analysis and state transition probability.

5. The method according to claim 1, characterized in that: Step 4 is implemented using the intervention decision module, which uses a reinforcement learning algorithm to generate the optimal intervention plan and prioritizes high-risk operations to ensure system safety.

6. The method according to claim 1, characterized in that Step 5 is implemented using a feedback adaptive optimization module, which improves the dynamic adaptability of the model by updating parameters based on historical data and real-time response results.

7. A malicious program perception and reverse behavior intervention system based on brain-like computing, comprising: A computer readable storage medium and a processor; The computer-readable storage medium is used to store executable instructions; The processor is used to read the executable instructions stored in the computer-readable storage medium and execute the malicious program perception and reverse behavior intervention method based on brain-like computing as described in any one of claims 1-6.

8. A non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the malicious program perception and reverse behavior intervention method based on brain-like computing as described in any one of claims 1-6.