Malware variant generation method based on neural network and deformation state transition diagram

Generating malware variants through neural networks and deformation state transfer diagrams solves the problem of scarcity of high-quality data, improves the robustness and generalization capabilities of the malware detection model, realizes batch generation of high-hidden variants, and expands the source of training data.

CN120337220APending Publication Date: 2025-07-18SICHUAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510516737.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-23
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The scarcity of high-quality malware data in the prior art makes it difficult for machine learning detection methods based on static features to adapt to the rapid evolution and obscurity of malware and to effectively identify unknown threats.

Method used

The malware variant generation model is constructed based on neural networks and deformation state transfer diagrams. The deformation process is guided through deformation state transfer diagrams. A variety of deformation methods and neural network models are combined to generate highly occult malware variants and expand the training data source.

Benefits of technology

It effectively expands the diversity and data sources of malware, improves the robustness and generalization capabilities of intelligent detection models, and enhances the ability to identify and protect unknown threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337220A_ABST
    Figure CN120337220A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, in particular to a malicious software variant generation method based on a neural network and a deformation state transition diagram, which comprises the following steps of: 1, defining a malicious software training sample set, a deformation method set and a detection model set; 2, constructing a deformation state transition diagram; 3, generating an initial empty sequence for each malicious software training sample at the beginning of each round; 4, predicting a next deformation method; 5, generating a next deformation sequence and malicious software training sample variants; 6, the step 4 and the step 5 are cycled until a deformation malicious software training sample set of the current round is obtained, and a detection probability matrix is calculated; 7, updating the model according to the loss function; 8, executing the steps circularly until a final model is output and obtained; and generating variants of malware in batches. According to the method, high-concealment malicious software variants can be generated in batches, and the problem of insufficient high-quality malicious software data is effectively solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly to a method for generating malware variants based on neural networks and deformed state transition graphs. Background Art

[0002] Malicious software (Malware) refers to a type of malicious program that steals, interferes with, damages, or otherwise harms computer systems, networks, and devices. Its propagation channels usually include phishing emails, system vulnerability exploitation, and other forms of social engineering attacks. Currently, there are a wide variety of malicious software, and the most common ones include Trojans, backdoors, ransomware, and spyware, etc. According to the statistical data of the world-renowned cybersecurity company Kaspersky, its detection system discovered approximately 411,000 malicious software on average per day in 2023. This figure reflects the increasingly severe and complex network security situation, where attackers continuously develop new malicious software, attack techniques, and methods to continuously break through the defense system and pose threats to the information security of organizations and individuals.

[0003] To effectively address the security threats posed by malicious software, academia and industry have proposed and developed various malicious software detection methods. According to whether it is necessary to execute the suspicious software during the detection process, malicious software detection methods can generally be divided into two categories: static detection and dynamic detection. Static detection methods extract static features (such as information entropy, import and export function names, N-gram byte sequences, etc.) from the suspicious software to determine whether it has malicious properties without actually running the software. Relatively speaking, dynamic detection methods need to execute the suspicious software in an isolated environment and judge the maliciousness of the software by analyzing the dynamic behavior characteristics generated during its operation, such as file system operations, registry modifications, network communication behaviors, etc.

[0004] Furthermore, according to different detection mechanisms, malicious software detection methods can be further divided into signature-based detection and machine learning-based detection. Signature-based detection methods extract feature signatures from known malicious software, build a malicious software signature library, and judge whether the suspicious software is malicious by comparing its signature with that in the library. However, signature-based detection cannot identify unknown malicious software. In contrast, machine learning-based detection methods build a malicious software dataset, extract its static or dynamic features, and train a detection model in combination with machine learning algorithms. This method has the ability to identify unknown malicious software.

[0005] Considering both detection efficiency and recognition performance, machine learning detection methods based on static features are expected to become the mainstream technology in the future field of malicious software detection.

[0006] Current machine learning detection methods based on static features face several limitations in practical applications and deployments. One of them is the severe scarcity of high-quality malware data. The root causes of this problem are mainly reflected in the following aspects:

[0007] Strong malware concealment ability: Modern malware usually uses technical means such as encryption, shelling, and code obfuscation to hide its static features to avoid detection by static analysis tools. At the same time, malware may also adopt anti-dynamic detection technologies such as process hiding and sandbox escape, making it difficult for researchers to obtain comprehensive and representative malware in a real environment, thus limiting the diversity of the dataset.

[0008] Fast malware evolution speed: In order to bypass continuously upgraded defense mechanisms, attackers continuously innovate technical means, making malware in a state of continuous evolution. This continuous technological game prompts malware to iterate continuously and frequently update its attack strategies and behavioral characteristics, resulting in existing detection models being difficult to adapt to new malware threats and further exacerbating the problem of rapid data obsolescence.

[0009] High degree of malware customization: Many high-value malware are customized according to specific targets (such as government agencies, critical infrastructure, etc.) and usually only execute in specific environments. This highly customized malware makes it difficult for them to be widely obtained. In particular, ordinary researchers often cannot access these highly targeted malware, further limiting the representativeness and coverage of the dataset.

[0010] Therefore, the scarcity of malware data, especially in the collection and extraction of high-quality malware, has become a major bottleneck in the development of current intelligent malware detection methods. It is urgent to change the idea of passive collection and capture, actively generate high-quality malware variants, and alleviate the problem of data scarcity. Summary of the Invention

[0011] The present invention provides a malware variant generation method based on a neural network and a deformation state transition graph, which is used to expand the data source of highly concealed malware, provide high-quality training data for malware detection methods based on machine learning, and indirectly improve the robustness and generalization ability of existing malware detection models.

[0012] The malware variant generation method based on a neural network and a deformation state transition graph of the present invention includes:

[0013] Step 1: Set the total number of training rounds T of the malware variant generation model and the number of deformation times K of each malware training sample in each round, and select the set S of malware training samples to be deformed; define the set M of malware deformation methods, and initialize the set D of malware detection models;

[0014] Step 2: Construct a deformation state transition graph of malware training samples according to the deformation method set M;

[0015] Step 3: Use the deformation state transition graph as the initialization parameter of the transfer layer of the malware variant generation model. At the beginning of each round of training, generate an initial empty sequence as the current deformation sequence for each malware training sample in the malware training sample set S;

[0016] Step 4: Predict the next deformation method with the highest probability for the malware training sample according to the input malware training sample and the current deformation sequence;

[0017] Step 5: Add the predicted next deformation method to the current deformation sequence to form the next deformation sequence, and then generate a malware training sample variant;

[0018] Step 6: Loop steps 4 and 5 until K deformations are completed to obtain the deformation sequence set of all malware training samples in the current round and the corresponding deformed malware training sample set S′, and then calculate the detection probability matrix according to the detection model set D;

[0019] Step 7: Calculate the loss function based on the deformation sequence set and the detection probability matrix, update the malware variant generation model according to the loss function, and generate an optimized malware variant generation model for the next round;

[0020] Step 8: Loop through steps 3 to 7 for T rounds, and output the final malware variant generation model; batch generate variants of malware through the completed malware variant generation model.

[0021] Constructing a deformation state transition graph of malware and training a neural network model to generate highly concealed malware variants not only effectively expands the diversity of malware and the data source, but also indirectly improves the robustness and generalization ability of existing intelligent malware detection models, thereby enhancing their ability to identify and protect against unknown threats.

[0022] Further, in step 2, the deformation methods in the deformation method set M include tail data filling of malware training samples, confusion change of important fields, program entry point change, shelling, and runtime release.

[0023] Further, in step 3, the model consists of a deformation state transition graph and any neural network-based malware training sample feature extraction model. Among them, the deformation state transition graph is used to guide and restrict the deformation process of malware training samples, and the neural network-based malware feature extraction model is used to represent malware training samples and learn the feedback of the detection model set D to guide the generation of deformation sequences.

[0024] Further, in step 5, the malware training samples generate malware training sample variants through the next deformation sequence, including the steps of:

[0025] 5.1: Reverse the deformation sequence to obtain the actual deformation sequence;

[0026] 5.2: After processing each malware training sample respectively by traversing each deformation method in the actual deformation sequence, each malware training sample variant is obtained.

[0027] Further, in step 7, based on the deformation sequence set Seq and the detection probability matrix R, the model G is updated t to generate the optimized model G for the next round t+1 , where t represents the training round, and the training round t ≤ the total number of training rounds T, including the steps of:

[0028] 7.1: Calculate the mean value of the detection probability matrix R to obtain

[0029] 7.2: Set the threshold T hs to obtain the reward value

[0030] 7.3: Calculate the loss function Loss = -∑ i G t (seq i [1:], s i )[seq i [1]]·R e [i], where s i represents the original malware training sample corresponding to the i-th deformation sequence seq i in the deformation sequence set Seq, seq i [1:] is the deformation sequence for the previous round of this malware training sample s i , seq i [1] is the deformation sequence for the current round of this malware training sample s i ;

[0031] 7.4: Update the model G according to the loss function Loss t to obtain the model G for the (t + 1)-th round t+1 .

[0032] Further, the detection models in the detection model set D include detection models based on random forest, based on XGBoost, based on LightGBM, based on GBDT, or based on neural network.

[0033] The beneficial effects of the present invention include:

[0034] 1. It can transform malware of different platforms and formats, actively generate malware variants with high concealment, and expand the data source for intelligent detection model training.

[0035] 2. By constructing a deformation state transition graph of malware to constrain the deformation process of malware, combining multiple malware deformation methods and neural network models, intelligently deform existing malware, and finally realize the batch generation of highly concealed malware samples.

[0036] 3. It effectively alleviates the problem of insufficient high-quality malware data, promotes the development of network security defense technology by greatly expanding the training data source required by the intelligent detection model. Description of the Drawings

[0037] Figure 1 It is a flowchart of the malware variant generation method based on neural network and deformation state transition graph of the present invention.

[0038] Figure 2 It is a schematic structural diagram of the model in the present invention.

[0039] Figure 3 It is a schematic diagram of deforming malware training samples through a deformation sequence in the present invention.

[0040] Figure 4 It is a schematic diagram of training the model through the discrimination result of the model in the present invention. Detailed Embodiments

[0041] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Usually, the components of the embodiments of the present application described and illustrated herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the present application claimed, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative efforts shall fall within the protection scope of the present application.

[0042] As Figure 1 shown, the malware variant generation method based on neural network and deformation state transition graph of the present invention includes:

[0043] Step 1: Set the total number of training rounds T of the malware variant generation model and the number of deformations K of each malware training sample per round, and select the set of malware training samples to be deformed

[0044] S = {s1, s2, s3,..., s n}. The malware samples in the malware training sample set S can be obtained by downloading from public data sources such as VirusShare. Malware samples of the same family can also be collected according to the need to generate deformed samples, such as Trojans, backdoors, ransomware, etc.

[0045] Set the malware deformation method set M = {m1, m2, m3,..., m n}, and initialize the malware detection model set D = {d1, d2, d3,..., d n}. Among them, the deformation methods of each malware in the deformation method set M can be provided by existing tools, such as VMProtect, UPX shelling tools, etc., or some lightweight deformation methods, such as software tail data filling, important field confusion change, program entry point change, etc. The detection models in the detection model set D are trained based on existing open-source machine learning and deep learning algorithms using public malware data, such as detection models based on random forest, XGBoost, LightGBM, GBDT, or neural network.

[0046] Step 2: Construct a deformation state transition graph of malware training samples according to the deformation method set M Where means that after using the deformation method m i the deformation method m j cannot be used, means that after using the deformation method m i the deformation method m j can be used. In the deformation method set M, the deformation methods include deformation methods such as tail data filling, important field confusion change, program entry point change, shelling, and runtime release of malware training samples.

[0047] Step 3: Initialize the parameters of the model G d of the malware training sample according to the deformation state transition graph Trans 0 , where the superscript 0 represents the training round. During the initialization process, set the state transition layer parameters of the model G 0 to the deformation state transition graph Trans d , and the parameters of other layers of the model G 0 are all random values. Therefore, the model G 0 is composed of the deformation state transition graph Trans dIt is composed of any neural network-based malware feature extraction model, such as models based on recurrent neural generation, long short-term memory neural network, convolutional neural network, etc. Among them, the metamorphic state transition graph Trans d is used to guide and restrict the metamorphic process of malware training samples. The neural network-based malware feature extraction model is used to represent malware training samples and learn the feedback of the detection model set D to guide the generation of metamorphic sequences.

[0048] In the training round t, for each malware training sample s in the malware training sample set S i generate an initial empty sequence where the training round t ≤ the total number of training rounds T.

[0049] Step 4: In the k-th step generation of the training round t, the model G t According to the input malware training sample s i and the current metamorphic sequence predict the next metamorphic method of the malware training sample s i (When this step is first executed in the training round t, the current metamorphic sequence at this time is the initial empty sequence generated in Step 5 ), and the next metamorphic method is the metamorphic method with the highest probability predicted by the model G in the k-th step of the training round t for the malware training sample s t i .

[0050] As Figure 2 shown, the structural diagram of the model used in the present invention. The model reads in the malware training sample s to be metamorphosed i and the current metamorphic sequence extracts the malware training sample features through the feature extraction layer, generates the metamorphic sequence embedding representation through the embedding layer, merges them in the fusion layer, and after processing by the dense layer, the state transition layer and the normalization layer, predicts the next metamorphic method.

[0051] Step 5: The current metamorphic sequence and the next metamorphic method predicted in Step 4 form the next metamorphic sequence For the malware training sample s i obtain the malware training sample variant s' through the next metamorphic sequence i,k .

[0052] Figure 3 ​Shows a schematic diagram of the present invention for transforming malware training samples through a transformation sequence. According to the transformation methods in the transformation sequence continuously transform the malware training sample s i to obtain a variant s' of the malware training sample i,k , and the specific steps include:

[0053] Step 5.1: Reverse the transformation sequence to obtain the actual transformation sequence

[0054] Step 5.2: Traverse each transformation method in the actual transformation sequence to process the malware training sample s and obtain a variant s' of the malware training sample i , where n ∈ [0, k]. i,k

[0055] Step 6: Loop steps 4 and 5 until the number of transformations K is reached, to obtain the transformation sequence set Seq = {seq1, seq2, seq3,..., seq n} and the set S' of transformed malware training samples.

[0056] Use each detection model d in the detection model set D i to detect each variant s i ' in the set S' of transformed malware training samples, to obtain a detection probability matrix The closer r is to 1, the greater the likelihood of belonging to malware.

[0057] Step 7: Based on the transformation sequence set Seq and the detection probability matrix R, calculate the model G for the t-th round t For all transformed malware training samples s in the set S' of transformed malware training samples i calculate the loss function Loss, and update the model G according to the loss function Loss through an optimization algorithm t to obtain the model G for the t + 1-th round t+1 . Among them, the optimization algorithm can be arbitrarily selected, such as the gradient descent algorithm, the stochastic gradient descent algorithm, etc.

[0058] Figure 4 Shows a schematic diagram of the present invention for training the model through the discrimination results of the model. First, calculate the reward value R according to the detection probability matrix R e , and then calculate the loss function Loss to update the model G t . The specific steps include:

[0059] ​Step 7.1: Calculate the mean of the detection probability matrix R to obtain

[0060] Step 7.2: Set the threshold T hs , and obtain the reward value

[0061] Step 7.3: Calculate the loss function Loss = -∑ i G t (seq i [1:], s i )[seq i [1]]·R e [i], where s i represents the original malware training sample corresponding to the deformation sequence seq i , seq i [1:] is the deformation sequence of the previous round for the malware training sample s i , and seq i [1] is the deformation sequence of the current round for the malware training sample s i ;

[0062] Step 7.4: Update the model G according to the loss function Loss t to obtain the model G at the (t + 1)-th round t+1 .

[0063] Step 8: Loop through Steps 3 to 7 until reaching the round of the total number of training rounds T, and output the final model G final .

[0064] Through the trained model G final , select the real malware to be deformed, set the corresponding detection model, and input the malware to be deformed into the model G one by one final . The model G final outputs the corresponding deformation sequence for each malware, and deforms each malware according to the deformation sequence to batch generate variants of the malware.

[0065] Starting from the perspective of the attacker, the present invention actively generates variants of malware training samples, greatly expanding the data source for the training of intelligent detection models. And by constructing a deformation state transition graph of malware training samples to constrain the deformation process of malware training samples, and combining multiple malware deformation methods, training a neural network model to intelligently deform existing malware, finally realizing the batch generation of highly concealed malware samples. The present invention can effectively solve the problem of insufficient data of high-quality malware training samples, expand the training data source required by intelligent detection models, and promote the development of network security defense technologies.

[0066] The embodiments described above only represent the specific implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the protection scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the technical solution of the present application, relevant deformations and improvements can also be made, and these all belong to the protection scope of the present application.

Claims

1. A method for generating malware variants based on a neural network and a deformation state transition graph, characterized in that Including: Step 1: Set the total number of training rounds T of the malware variant generation model and the number of deformations K for each malware training sample in each round, and select the set S of malware training samples to be deformed; Define the set M of malware deformation methods, and initialize the set D of malware detection models; Step 2: Construct a deformation state transition graph of the malware training samples according to the set M of deformation methods; Step 3: Use the deformation state transition graph as the initialization parameter of the transition layer of the malware variant generation model. At the beginning of each round of training, generate an initial empty sequence as the current deformation sequence for each malware training sample in the set S of malware training samples; Step 4: Predict the next deformation method with the highest probability of the malware training sample according to the input malware training sample and the current deformation sequence; Step 5: Add the predicted next deformation method to the current deformation sequence to form the next deformation sequence, and then generate a malware training sample variant; Step 6: Loop through Step 4 and Step 5 until K deformations are completed, obtaining the deformation sequence set of all malware training samples in the current round and the corresponding set S of deformed malware training samples ′ , and then calculating the detection probability matrix according to the detection model set D; Step 7: Calculate the loss function based on the set of deformation sequences and the detection probability matrix, and update the malware variant generation model according to the loss function to generate an optimized malware variant generation model for the next round; Step 8: Loop through steps 3 to 7 for T rounds, and output the final malware variant generation model; Through the completed malware variant generation model, batch generate variants of malware.

2. The malware variant generation method based on neural network and deformation state transition graph according to claim 1, characterized in that: In step 2, the deformation methods in the set M of deformation methods include tail data filling of malware training samples, confusion change of important fields, change of program entry point, shelling, and release at runtime.

3. The malware variant generation method based on neural network and deformation state transition graph according to claim 1, characterized in that: In step 3, the malware variant generation model consists of a deformation state transition graph and any neural network-based malware training sample feature extraction model. Among them, the deformation state transition graph is used to guide and restrict the deformation process of malware training samples, and the neural network-based malware feature extraction model is used to represent malware training samples and learn the feedback of the detection model set D to guide the generation of deformation sequences.

4. The malware variant generation method based on neural network and deformation state transition graph according to claim 1, characterized in that: In step 5, the malware training sample generates a malware training sample variant through the next deformation sequence, including the steps: 5.1: Reverse the deformation sequence to obtain the actual deformation sequence; 5.2: After traversing each deformation method in the actual deformation sequence and processing each malware training sample respectively, obtain each malware training sample variant.

5. The malware variant generation method based on neural network and deformation state transition graph according to claim 1, characterized in that: In step 7, based on the deformation sequence set Seq and the detection probability matrix R, update the model G t to generate the optimized model G for the next round t+1 , where t represents the training round, and the training round t ≤ the total number of training rounds T, including the steps: 7.1: Calculate the mean of the detection probability matrix R to obtain 7.2: Set the threshold T hs , and obtain the reward value 7.3: Calculate the loss function Loss = -∑ i G t (seq i [1:], s i )[seq i [1]]·R e [i], where s i represents the original malware training sample corresponding to the i-th deformed sequence seq i in the set of deformed sequences Seq, seq i [1:] is the deformed sequence for the malware training sample s i in the previous round, and seq i [1] is the deformed sequence for the malware training sample s i in the current round; 7.4: Update the model G according to the loss function Loss t Obtain the model G at the (t + 1)-th round t+1 .

6. The malware variant generation method based on neural network and deformation state transition graph according to any one of claims 1 to 5, characterized in that: The detection models in the detection model set D include detection models based on random forest, based on XGBoost, based on LightGBM, based on GBDT, or based on neural network.