Classification device and classification method
The classification device enhances malware detection by converting obfuscated application features to non-obfuscated-like features, addressing the accuracy issues in conventional methods and improving detection of obfuscated malware.
Patent Information
- Application Number
- JP2024005180
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-17
- Publication Date
- 2025-07-30
AI Technical Summary
Conventional malware classification methods struggle with reduced accuracy for obfuscated applications, leading to insufficient detection and verification of obfuscated malware.
A classification device that extracts features from obfuscated applications, converts them into non-obfuscated-like features using a trained model, and classifies using these converted features.
Improves classification accuracy for obfuscated applications by restoring obfuscated features to a state similar to non-obfuscated ones, enhancing detection and verification.
Smart Images

Figure 2025111038000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a classification device and a classification method.
Background Art
[0002] In malware classification, classification based on signatures using specific information contained in malware, classification using machine learning, etc. are used. For example, using a score function that calculates a score from the features of data according to parameters, a score is calculated for each of one or more pieces of data that are known to be negative examples or positive examples, and based on the classification result when classification is performed based on the calculated scores, a technique for updating parameters so that the calculated index is optimized is known (see, for example, Patent Document 1).
[0003] As described above, in recent years, especially classification by machine learning has been actively researched and developed, and classification methods with high detection accuracy are known.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, in the above-described conventional technology, there is a problem in improving the classification accuracy for obfuscated applications. For example, the conventional technology shows high discrimination accuracy for non-obfuscated malware, but there are many cases where the discrimination accuracy decreases or the verification is insufficient for obfuscated malware.
Means for Solving the Problems
[0006] Therefore, in order to solve the above-described problems and achieve the object, the classification apparatus of the present invention includes: an extraction unit that extracts a first feature amount, which is a feature amount representing the features of the application, from the application; a conversion unit that inputs the first feature amount extracted by the extraction unit into a model learned to convert the obfuscation state of the input feature amount, and converts it into a second feature amount that is the same as or similar to the feature amount extracted from the non-obfuscated application; and a classification unit that classifies the application using the second feature amount converted by the conversion unit.
Effect of the Invention
[0007] According to the present invention, there is an effect that it is possible to improve the classification accuracy for obfuscated applications.
Brief Description of the Drawings
[0008]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Figure 18
[0009] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Hereinafter, embodiments of the present invention (hereinafter referred to as "embodiments") will be described with reference to the drawings. Note that the embodiments are not limited to the following description.
[0010] <Introduction> First, an introduction to this embodiment will be described. FIG. 1 is a diagram for explaining the overall image of the processing by the classification device 100 according to this embodiment. The classification device 100 shown in FIG. 1 converts obfuscated feature amounts (hereinafter, may be referred to as "obfuscated feature amounts") extracted from an application into feature amounts that are not obfuscated (hereinafter, may be referred to as "non-obfuscated feature amounts") or similar feature amounts (hereinafter, may be referred to as "non-obfuscated-like feature amounts"), and is an example of a computer that provides a technique for performing classification processing using the non-obfuscated-like feature amounts.
[0011] In recent years, active research has been conducted on malware classification techniques for malicious software, applications, etc. that aim to cause damage to computers and their users. For example, a reference technique is known in which classification is performed by machine learning or the like using application information extracted from an application to be classified as a feature amount.
[0012] Also, as an example of classification techniques, reference techniques such as signature-based classification using specific information included in malware and classification using machine learning are known. In particular, it is known that reference techniques for malware classification based on a machine learning model can detect malware with high accuracy.
[0013] The reference technique shows high discrimination accuracy for malware that has not been obfuscated, which is a technique for making it difficult to analyze by tampering with malware or the like. However, for obfuscated malware, verification of discrimination accuracy and the like is often insufficient, and in some cases, the actual discrimination accuracy may decrease, so there are problems with detection accuracy.
[0014] For example, in antivirus software and the like, it is known that the classification accuracy tends to decrease for obfuscated malware compared to non-obfuscated malware. Here, the problems of the reference technique will be described using a diagram. FIG. 2 is a diagram for explaining an example of the problems of the reference technique.
[0015] Figure 2 shows the results (detection rates) of scanning the applications before and after obfuscation using a website that performs malware inspections on files and websites. Note that the results shown in Figure 2 represent the scan results of multiple antivirus softwares for a certain application as "number of malware detections / number of antivirus softwares inspected".
[0016] For example, regarding the application before obfuscation shown in the upper figure of Figure 2, the scan result is "30 / 66" ((1-1) in Figure 2), while for the application after obfuscation, it is "11 / 64" ((1-2) in Figure 2), indicating a decrease in the detection rate. Also, regarding the application before obfuscation shown in the lower figure of Figure 2, the scan result is "9 / 67" ((2-1) in Figure 2), while for the application after obfuscation, it is "1 / 65" ((2-2) in Figure 2), showing a decrease in the detection rate. Therefore, it can be seen that obfuscating the target application affects the detection accuracy for malware detection by the prior art.
[0017] Therefore, in order to solve the above-mentioned problems, the classification device 100 according to this embodiment converts the obfuscation feature amount extracted from the obfuscated application (hereinafter may be referred to as "obfuscated application") into a non-obfuscated-like feature amount. Then, the classification device 100 performs classification processing using the non-obfuscated-like feature amount.
[0018] Here, returning to Figure 1, a series of processes of the classification device 100 will be described. The classification device 100 extracts a first feature amount as a feature amount representing the features of the application from the application. For example, as shown in (1) of Figure 1, the classification device 100 extracts an obfuscation feature amount as the first feature amount from the obfuscated application.
[0019] Note that the above-mentioned "first feature amount" includes the "obfuscation feature amount" extracted from the obfuscated application and the "non-obfuscation feature amount" extracted from the non-obfuscated application (hereinafter may be referred to as "non-obfuscated application").
[0020] The classification device 100 inputs the extracted first features into a model trained to convert the obfuscation state of the input features, and converts them into second features that are identical to or similar to features extracted from the de-obfuscated application. For example, as shown in (2) of FIG. 1, the classification device 100 inputs the obfuscated features extracted as the first features into a trained conversion model to convert them into de-obfuscated-like features.
[0021] Note that the above-mentioned "second feature" may not be the same feature as the de-reading feature extracted from the de-reading application, but may be a feature (de-reading-like feature) that has common parts with the de-reading feature, such as being similar to the de-reading feature.
[0022] The classification device 100 classifies applications using second features converted from the first features. For example, the classification device 100 classifies the applications to be classified as "benign ((3-1) in FIG. 1)" or "malignant ((3-2) in FIG. 1)" ((3) in FIG. 1).
[0023] As described above, the classification device 100 according to this embodiment enables application of a classifier for obfuscated applications by restoring features that change due to obfuscation to features that are close to the state before obfuscation before performing classification processing using existing reference techniques. In other words, the classification device 100 can be applied to existing classifiers for obfuscated applications by training a machine learning model in advance so that "features close to the features before obfuscation" are output from "obfuscated features."
[0024] Therefore, the classification device 100 has an effect of improving the classification accuracy for obfuscated applications.
[0025] First Embodiment The first embodiment is a basic embodiment realized by the classification device 100 according to this embodiment, and is an example of performing classification processing by converting obfuscation feature amounts extracted from an obfuscation application into non-obfuscation-like feature amounts.
[0026] First, a series of classification processing by the classification device 100 according to the first embodiment will be described. FIG. 3 is a diagram for explaining an example of processing by the classification device 100 according to the first embodiment. In FIG. 3, “learning processing” and “classification processing” are shown as processing executed by the classification device 100.
[0027] First, “learning processing” will be described. As shown in (1) of FIG. 3, the classification device 100 learns a model (hereinafter, may be referred to as a “conversion model”) used when converting a first feature amount extracted from an application into a second feature amount.
[0028] Specifically, the classification device 100 converts a non-obfuscation application, which is a learning application input by a user or the like, into an “obfuscation application” based on an obfuscation tool or the like ((1-1) of FIG. 3).
[0029] Next, the classification device 100 extracts “non-obfuscation feature amounts” from the non-obfuscation application ((1-2) of FIG. 3). Further, the classification device 100 extracts “obfuscation feature amounts” from the obfuscation application obfuscated in the step of (1-1) of FIG. 3 ((1-3) of FIG. 3).
[0030] The classification device 100 associates the obfuscation feature amounts and non-obfuscation feature amounts extracted in the steps of (1-2) and (1-3) of FIG. 3 and stores them as a learning dataset ((1-4) of FIG. 3).
[0031] For example, as shown in (1-5) of FIG. 3, the classification device 100 stores a de-obfuscation feature "feature A1" extracted from application A, which is a de-obfuscated application, and an obfuscated feature "feature A1'" extracted from application A', which is obtained by obfuscating application A, in association with each other. Similarly, as shown in (1-5) of FIG. 3, the classification device 100 stores a "feature A2" and a "feature A2'" in association with each other, and a "feature A3" and a "feature A3'" in association with each other. As a result, the classification device 100 can train a conversion model to learn the relationship between pre-obfuscation and post-obfuscation for any application.
[0032] The classification device 100 uses the extracted de-read features and obfuscated features as training data sets to train a conversion model ((1-6) in FIG. 3).
[0033] Next, the "classification process" will be described. As shown in (2) of Fig. 3, the classification device 100 performs a classification process for applications using a transformation model that has been trained in the above-mentioned learning process and a classification model that performs a predetermined classification based on input feature quantities.
[0034] The classification device 100 extracts obfuscated features to be used in classification processing from an obfuscated application ((2-1) in FIG. 3). Next, the classification device 100 inputs the extracted obfuscated features to a trained conversion model in the learning process ((2-2) in FIG. 3). Then, the classification device 100 converts the obfuscated features into non-obfuscated-like features ((2-3) in FIG. 3).
[0035] For example, as shown in (2-4) of FIG. 3, the classification device 100 inputs the obfuscation feature "feature X1'" extracted from the obfuscated application X' into the trained conversion model and converts it into a de-obfuscation-like feature "feature X1''". Similarly, the classification device 100 converts the obfuscation feature "feature X2'" into a de-obfuscation-like feature "feature X2''" and the obfuscation feature "feature X3'" into a de-obfuscation-like feature "feature X3''".
[0036] The classification device 100 inputs obfuscation-like feature quantities into an existing classification model and outputs the classified classification results (Fig. 3 (2-5)). As a result, even when using an existing classification model that has difficulty accurately classifying obfuscated feature quantities, the classification device 100 can perform classification processing with high accuracy.
[0037] (Classification device 100) Next, the configuration of the classification device 100 will be described. Fig. 4 is a diagram showing an example of the configuration of the classification device 100 according to the first embodiment. As shown in Fig. 4, the classification device 100 includes a communication unit 110, a storage unit 120, and a control unit 130. Although not shown in Fig. 4, the classification device 100 can be provided with an input unit such as a keyboard or a mouse for receiving inputs such as operations by a user or the like. Further, the classification device 100 can be provided with a display unit such as a display for displaying information regarding the extracted or converted feature quantities, information regarding the results of the classification processing, etc. to the user or the like.
[0038] (Communication unit 110) The communication unit 110 performs data communication related to inputs such as information regarding the learning application and information regarding the application to be classified, and output of the results of the classification processing by the classification function unit 133 described later. The communication unit 110 is realized by a NIC (Network Interface Card) or the like and controls communication via a telecommunication line such as a LAN (Local Area Network) or the Internet. Then, the communication unit 110 is connected to the network by wire or wirelessly as necessary and can transmit and receive information bidirectionally. Note that the communication unit 110 can input or output information via a storage medium such as a USB (Universal Serial Bus).
[0039] (Storage unit 120) The storage unit 120 stores data and programs used for various processes by the control unit 130, and various data obtained when the control unit 130 operates. The storage unit 120 is realized by a semiconductor memory element such as a RAM (Random Access Memory) or a flash memory, or a storage device such as a hard disk or an optical disk. Further, as shown in FIG. 4, the storage unit 120 includes a model DB 121, an application DB 122, a feature amount DB 123, and a classification result DB 124.
[0040] (Model DB 121) The model DB 121 is a database that stores machine learning models such as a conversion model used by a conversion unit 133b, which will be described later, to perform conversion processing on feature amounts, and a classification model used by a classification unit 133c, which will be described later, to perform classification processing on the converted feature amounts.
[0041] Here, an example of the conversion model stored in the model DB 121 will be described. FIG. 5 is a diagram showing an example of a conversion model according to the first embodiment. FIG. 5 shows, as an example of the conversion model, a time-series model (FIG. 5(1)) that is a model for program code and a numerical model (FIG. 5(2)) that is a model for in-program parameters.
[0042] For example, the model for program code shown in FIG. 5(1) may be a model suitable for handling time-series data or sequence data such as an RNN (Recurrent Neural Network) used for language translation or speech recognition. Further, the model for in-program parameters shown in FIG. 5(2) may be a model capable of defining a matrix-to-matrix conversion, such as a CNN (Convolutional Neural Network) used for image recognition, in order to map parameters to a matrix.
[0043] For the other party, the classification model for classification processing may be a known model such as logistic regression, k-nearest neighbor method, decision tree, support vector machine, artificial neural network, etc. Note that the detailed description of the classification model in this item is omitted.
[0044] (Application DB 122) The Application DB 122 stores a learning application and an application to be classified as applications used for the learning process and classification process of the classification device 100 according to this embodiment.
[0045] Specifically, the Application DB 122 stores in association with information for identifying an application such as an application name, reception date and time, and reception number associated with the application body, which relates to the learning or classification target application input by a user or the like. Note that in this embodiment, the application includes malware, which is a malicious application such as a virus, and a normal application.
[0046] (Feature DB 123) The Feature DB 123 stores feature amounts that represent the features of the application extracted from the application. Specifically, the Feature DB 123 stores the feature amounts used as the learning dataset extracted by the extraction unit 132b described later. For example, the Feature DB 123 stores in association with information for identifying the associated feature amounts, a non-obfuscation feature amount extracted from a non-obfuscated application and an obfuscation feature amount extracted from an obfuscated application obtained by obfuscating the non-obfuscated application.
[0047] Note that in this embodiment, the feature amount is a value obtained by converting predetermined information such as a program, character string, and parameter extracted from an application into a specific format.
[0048] For example, the feature amount DB123 stores, as feature amounts, information obtained by extracting the program code extracted by disassembling or decompiling an application as a sentence, or extracting specific instruction words, words, etc. and mapping them to a matrix. Further, the feature amount DB123 extracts information recognizable as a character string excluding instruction sentences and the like included in the program code from the application, and stores, as feature amounts, information mapped to a matrix. Further, based on the fact that the parameter indicating the information of the application included in the platform on which the application operates is information of a fixed pattern defined by the platform, the feature amount DB123 stores, as a feature amount, information obtained by mapping the parameter to a matrix.
[0049] Here, an example of a feature amount used as a learning data set stored by the feature amount DB123 will be described. FIG. 6 is a table diagram showing an example of feature amounts for learning before and after obfuscation according to the first embodiment. As shown in FIG. 6, the feature amount DB123 stores an application before obfuscation, an application after obfuscation, a non-obfuscated feature amount, and an obfuscated feature amount in association with "No", which is information for identifying rows of table information.
[0050] The item of the "application before obfuscation" described above is information for identifying an application before obfuscation (non-obfuscated application). The item of the "application after obfuscation" is information for identifying an application (obfuscated application) obtained by obfuscating the application before obfuscation. The "non-obfuscated feature amount" is information for identifying feature amounts extracted from the application before obfuscation. The "obfuscated feature amount" is information for identifying feature amounts extracted from the application after obfuscation.
[0051] 6, the feature DB 123 stores a pre-obfuscation application "Application A" identified by No. "1," an obfuscated application "Application A'," a de-obfuscation feature "de-obfuscation feature A1," and an obfuscation feature "obfuscation feature A1'." The above information means that the "de-obfuscation feature A1" and the "obfuscation feature A1'" are features of application A before and after obfuscation.
[0052] The feature DB 123 can store multiple types of features for the above-mentioned items of "de-reading feature" and "obfuscation feature." For example, the feature DB 123 may store multiple types of features corresponding to each item, such as de-reading feature "de-reading feature A1, de-reading feature A2, de-reading feature A3..." and obfuscation feature "obfuscation feature A1', obfuscation feature A2', obfuscation feature A3'..." (not shown in FIG. 6).
[0053] On the other hand, the feature DB 123 stores a first feature extracted by an extraction unit 133a (described later) from an application to be classified input by a user or the like, and a second feature converted from the extracted first feature by a conversion unit 133b (described later), in association with each other.
[0054] Here, an example of features used in the classification process stored in the feature DB 123 will be described. Fig. 7 is a table diagram showing an example of features for classification before and after conversion process according to this embodiment. As shown in Fig. 7, the feature DB 123 stores an application to be classified, a first feature, and a second feature, in association with "No.", which is information for identifying a row of table information.
[0055] The item of the "application to be classified" described above is information for identifying an application (such as an obfuscation application) to be subjected to classification processing input by a user or the like. The item of the "first feature amount" is information for identifying a feature amount such as an obfuscation feature amount that is a feature amount representing the features of the application to be classified and extracted from the application to be classified. The "second feature amount" is information for identifying a non-obfuscated-like feature amount generated by converting the first feature amount by the conversion unit 133b described later.
[0056] For example, as shown in FIG. 7, the feature amount DB123 stores the application to be classified "Application X" identified by No. "1", the first feature amount "Obfuscation feature amount X1'", and the second feature amount "Non-obfuscated-like feature amount X1''". The above-described information means that the feature amount DB123 stores a "non-obfuscated-like feature amount X1''" that is close to the non-obfuscated feature amount X1 obtained by conversion processing using the "obfuscation feature amount X1'" extracted from the obfuscation application "Application X".
[0057] Note that the feature amount DB123 can store multiple types of feature amounts for the items of the "first feature amount" and the "second feature amount" described above. For example, the feature amount DB123 may store multiple types of feature amounts corresponding to each item, such as the first feature amount "Obfuscation feature amount X1', Obfuscation feature amount X2', Obfuscation feature amount X3'...", and the second feature amount "Non-obfuscated-like feature amount X1'', Non-obfuscated-like feature amount X2'', Non-obfuscated-like feature amount X3''..." (not shown in FIG. 7).
[0058] (Classification result DB124) The classification result DB124 is a database that stores the result of classification processing using the second feature amount (non-obfuscated-like feature amount) by the classification unit 133c described later. For example, the classification result DB124 stores, as a classification result, the result of classifying whether the application related to the second feature amount (non-obfuscated-like feature amount) is a normal application or malware such as a virus.
[0059] (Control unit 130) The control unit 130 has an internal memory for temporarily storing programs and processing data that define various processing procedures and the like of the classification device 100, and is realized by electronic circuits such as a CPU (Central Processing Unit), an MPU (Micro Processing Unit), and a GPU (Graphics Processing Unit), and integrated circuits such as an ASIC (Application Specific Integrated Circuit) and an FPGA (Field Programmable Gate Array). As shown in FIG. 4, the control unit 130 includes a reception unit 131, a learning function unit 132, a classification function unit 133, and an output unit 134.
[0060] (Reception unit 131) The reception unit 131 receives applications used for learning processing and classification processing via the communication unit 110 and the like described above. Specifically, the reception unit 131 receives a learning application used for learning processing by the learning function unit 132 described later and stores it in the application DB 122. Further, the reception unit 131 receives an application to be classified used for classification processing by the classification function unit 133 described later and stores it in the application DB 122.
[0061] (Learning function unit 132) The learning function unit 132 learns a conversion model used by the conversion unit 133b described later for feature conversion using a learning dataset, which is a group of feature amounts extracted from the learning application received by the reception unit 131. Note that the learning function unit 132 further includes an obfuscation unit 132a, an extraction unit 132b, and a learning unit 132c. Hereinafter, the functions of the learning function unit 132 will be described for each functional unit.
[0062] (Obfuscation unit 132a) The obfuscation unit 132a obfuscates a learning application input by a user, etc. Specifically, the obfuscation unit 132a performs obfuscation processing on a learning application that has not been obfuscated, such as replacing characters in strings and commands within the application, compressing and encrypting the program, and inserting meaningless program code.
[0063] If the training application has already been obfuscated, the obfuscation unit 132a may skip the obfuscation process or perform an additional obfuscation process. In addition to obfuscating the application itself, the obfuscation unit 132a can also obfuscate the application when generating it from the source code.
[0064] (Extraction part 132b) The extraction unit 132b extracts features to be used in the training process from the training application. For example, the extraction unit 132b extracts unobfuscated training features from a training application that is not obfuscated. Also, the extraction unit 132b extracts obfuscated training features from a training application that has been obfuscated by the obfuscation unit 132a.
[0065] In addition, when a learning application (pair) in which an obfuscated application and a de-obfuscated application are paired in advance is received, the extraction unit 132b can extract the obfuscated features and the de-obfuscated features from the learning application (pair).
[0066] (An example of the process of extracting a learning dataset) Here, the extraction of training feature quantities from a training application by the above-described obfuscation unit 132a and extraction unit 132b will be described with reference to the drawings. Fig. 8 is a diagram showing an example of the extraction process of feature quantities from a training application according to the first embodiment.
[0067] 8 shows an example in which the extraction unit 132b extracts feature amounts before and after obfuscation from a normal application and malware, respectively, and stores the feature amounts before and after obfuscation in association with each other in the feature amount DB 123. Note that malware is an application that includes a malicious program such as a virus. On the other hand, a normal application is an application that is not malware.
[0068] First, the obfuscation unit 132a obfuscates the unobfuscated application shown in (1) of Fig. 8 into the obfuscated application shown in (2) of Fig. 8 using a known obfuscation tool or the like. For example, the obfuscation unit 132a obfuscates an unobfuscated normal application into an obfuscated normal application ((1-1) of Fig. 8). Also, the obfuscation unit 132a obfuscates unobfuscated malware into obfuscated malware ((1-2) of Fig. 8).
[0069] Next, the extraction unit 132b extracts features from the de-interrogated application and the obfuscated application. Then, the extraction unit 132b associates the de-interrogated features extracted from the de-interrogated application with the obfuscated features extracted from the obfuscated application, and stores them in the feature DB 123.
[0070] For example, the extraction unit 132b extracts de-obfuscation features related to a normal application from a normal application that is not obfuscated ((3-1) in FIG. 8). Also, the extraction unit 132b extracts obfuscation features related to a normal application from an obfuscated normal application ((3-2) in FIG. 8). Then, the extraction unit 132b stores the extracted de-obfuscation features ((3-1) in FIG. 8) and the extracted obfuscation features ((3-2) in FIG. 8) in association with each other ((3-3) in FIG. 8).
[0071] On the other hand, the extraction unit 132b extracts non-obfuscation feature amounts related to the malware from non-obfuscated malware (FIG. 8(3-4)). Further, the extraction unit 132b extracts obfuscation feature amounts related to the malware from obfuscated malware (FIG. 8(3-5)). Then, the extraction unit 132b stores the extracted non-obfuscation feature amounts (FIG. 8(3-4)) and the extracted obfuscation feature amounts (FIG. 8(3-5)) in association with each other (FIG. 8(3-6)).
[0072] As a result of the processing by the obfuscation unit 132a and the extraction unit 132b described above, the classification device 100 can generate a dataset for learning feature amounts in which the feature amounts before obfuscation and the feature amounts after non-obfuscation are associated with each other.
[0073] (Learning unit 132c) When an obfuscation feature amount is input as a first feature amount, the learning unit 132c learns a conversion model so as to output a second feature amount, which is a non-obfuscation-like feature amount. When performing the learning process described above, the learning unit 132c can use a predetermined learning dataset in which the learning non-obfuscation feature amounts extracted from the non-obfuscation application and the learning obfuscation feature amounts extracted from the obfuscated application obtained by obfuscating the non-obfuscation application are associated with each other.
[0074] Here, the learning process performed by the learning unit 132c will be described with reference to the drawings. FIG. 9 is a diagram showing an example of the learning process of the conversion model according to the first embodiment. FIG. 9 shows a conversion model that converts the obfuscation feature amounts extracted for each obfuscated application into non-obfuscation-like feature amounts. For example, the conversion model shown in FIG. 9 is a model that converts the obfuscation feature amount A1' (FIG. 9(1-1)) into a non-obfuscation-like feature amount A1'' (FIG. 9(1-2)) when the obfuscation feature amount A1' is input.
[0075] The learning unit 132c learns a conversion model using a learning dataset in which obfuscation feature amounts and non-obfuscation feature amounts are associated with each other as the feature amounts extracted from the applications before and after obfuscation (FIG. 9(2)).
[0076] In other words, the learning unit 132c learns a machine learning model (conversion model) selected according to the target feature amount among machine learning models (conversion models) having a structure that generates "feature amounts of the same format" from the "target feature amounts". Further, when the classification model used by the classification function unit 133 described later targets a plurality of feature amounts, the learning unit 132c individually learns models selected according to the respective feature amounts.
[0077] (Classification function unit 133) The classification function unit 133 performs classification processing of a second feature amount, which is a non-obfuscated-like feature amount converted using a learned conversion model, and classification processing of an application related to the second feature amount. Note that the classification function unit 133 further includes an extraction unit 133a, a conversion unit 133b, and a classification unit 133c. From here, the functions of the classification function unit 133 will be described for each functional unit.
[0078] (Extraction unit 133a) The extraction unit 133a extracts a first feature amount, which is a feature amount in which the features of the application to be classified are expressed, from the application to be classified. For example, the extraction unit 133a extracts, as the first feature amount, an obfuscation feature amount for use in classification processing from the obfuscated application to be classified input by a user or the like.
[0079] (Conversion unit 133b) The conversion unit 133b inputs the first feature amount (obfuscation feature amount) extracted by the extraction unit 133a into the conversion model learned by the above-described learning function unit 132 so as to convert the obfuscation state of the input feature amount, and converts it into a second feature amount, which is a non-obfuscated-like feature amount.
[0080] Here, an example of the conversion process by the conversion unit 133b will be described with reference to the drawings. FIG. 10 is a diagram showing an example of the conversion process based on the conversion model according to the first embodiment. In FIG. 10, using the learned conversion model learned by the learning function unit 132, the obfuscated feature amount (first feature amount) extracted from the obfuscated application to be classified is converted into a non-obfuscated-like feature amount (second feature amount) that is close to the feature of the non-obfuscated feature amount. An example is shown.
[0081] For example, the conversion unit 133b converts the obfuscated feature amount (program) extracted as a feature amount related to the program from the obfuscated application shown in (1) of FIG. 10 into a non-obfuscated-like feature amount (program). As an example, the conversion unit 133b inputs the obfuscated feature amount (program) ( (2-1) in FIG. 10) extracted from the obfuscated application into an RNN ( (2-2) in FIG. 10) or the like that has been learned as a conversion model for programs, and generates a non-obfuscated-like feature amount (program) ( (2-3) in FIG. 10). Note that the conversion unit 133b may use a model other than the above-described RNN to perform the conversion of the feature amount related to the program.
[0082] For example, the conversion unit 133b converts the obfuscated feature amount (string) extracted as a feature amount related to the string from the obfuscated application shown in (1) of FIG. 10 into a non-obfuscated-like feature amount (string). As an example, the conversion unit 133b inputs the obfuscated feature amount (string) ( (3-1) in FIG. 10) extracted from the obfuscated application into a CNN ( (3-2) in FIG. 10) or the like that has been learned as a conversion model for strings, and generates a non-obfuscated-like feature amount (string) ( (3-3) in FIG. 10). Note that the conversion unit 133b may use a model other than the above-described CNN to perform the conversion of the feature amount related to the string.
[0083] For example, the conversion unit 133b converts obfuscation features (parameters) extracted from the obfuscated application as features related to parameters, as shown in (1) of Fig. 10, into de-obfuscation-like features (parameters). As an example, the conversion unit 133b inputs the obfuscation features (parameters) extracted from the obfuscated application ((4-1) of Fig. 10) into a trained CNN ((4-2) of Fig. 10) or the like as a conversion model for parameters, thereby generating de-obfuscation-like features (parameters) ((4-3) of Fig. 10). Note that the conversion unit 133b may use a model other than the above-mentioned CNN to convert the features related to parameters.
[0084] (Classification section 133c) The classification unit 133c classifies the application using the second feature, which is the de-analysis-like feature converted by the conversion unit 133b. Specifically, the classification unit 133c inputs the converted de-analysis-like feature into a predetermined classification model and, based on the obtained result, identifies which of the preset classifications the de-analysis-like feature corresponds to. Then, the classification unit 133c determines the classification of the application from which the feature corresponding to the classified de-analysis-like feature was extracted. For example, if the de-analysis-like feature extracted and converted from the application to be classified is classified as "malware," the classification unit 133c classifies the application to be classified related to the de-analysis-like feature as "malware."
[0085] Here, an example of the classification process by the classification unit 133c will be described with reference to the drawings. Fig. 11 is a diagram showing an example of the classification process according to the first embodiment. Fig. 11 shows a case where the classification process is performed by inputting the de-reading-like feature, which is the converted second feature, into an existing classification model (upper diagram of Fig. 11), and a case where the classification process is performed by generating a file that is identical to or similar to the de-reading application from the de-reading-like feature, which is the converted second feature (lower diagram of Fig. 11).
[0086] For example, as shown in the upper diagram of FIG. 11, the classification unit 133c inputs the extracted obfuscation-like feature amounts (FIG. 11(1)) into the classification model (FIG. 11(2)), and generates a classification result for the application to be classified by performing classification processing. That is, the classification unit 133c can perform classification processing by directly using the conventional classification model by using obfuscation-like feature amounts that are the same as or similar to the obfuscation feature amounts.
[0087] Also, for example, as shown in the lower diagram of FIG. 11, the classification unit 133c reconstructs the application again using the extracted obfuscation-like feature amounts (FIG. 11(1)), and generates a classification result for the application to be classified by performing classification processing using a classifier such as antivirus software. That is, the classification unit 133c converts only the feature amounts that are easily affected by obfuscation, other than other application components (FIG. 11(3-1)) such as image files included in the obfuscated application that are not easily affected by obfuscation, into obfuscation-like feature amounts and replaces them, thereby reconstructing a file similar to the obfuscated application (FIG. 11(3-2)) and performing classification processing. As a result, the classification device 100 can take in the application itself and directly use the conventional classifier to perform classification processing.
[0088] (Output unit 134) The output unit 134 outputs the classification result of the application to be classified generated by the classification unit 133c. For example, the output unit 134 can output the classification result to an external information processing device or the like via the communication unit 110 described above. Also, for example, the output unit 134 can output (display, print out, etc.) the classification result to the user via a display unit or the like provided in the classification device 100.
[0089] (Procedure of processing by classification device 100) From here, the processing procedures realized by the classification device 100 according to the first embodiment will be explained separately as a "learning process" and a "classification process." First, the "learning process" will be explained. Fig. 12 is a flowchart showing an example of the procedure of the learning process according to the first embodiment.
[0090] The obfuscation unit 132a obfuscates an unobfuscated application into an obfuscated application (S101).
[0091] The extraction unit 132b extracts de-obfuscation features for learning from the de-obfuscated application (S102). The extraction unit 132b also extracts obfuscation features for learning from the obfuscated application (S103).
[0092] The extraction unit 132b stores the extracted non-decipherable feature and obfuscated feature in association with each other (S104).
[0093] The learning unit 132c uses the stored non-decoded features and obfuscated features to learn a conversion model (S105).
[0094] Here, if the predetermined learning termination condition is not satisfied (No in S106), the classification device 100 returns to the previous step and continues the processing. Note that while FIG. 12 shows an example of returning to the step before S101, for example, if no additional feature extraction is performed, the step may be returned to the step before S105. Furthermore, the learning termination condition referred to here may be any condition that is determined arbitrarily, such as the number of times learning is performed, or whether an index indicating the accuracy of the model exceeds a predetermined threshold, or the like.
[0095] On the other hand, if the predetermined learning termination condition is met (Yes in S106), classification device 100 terminates the process.
[0096] Next, the "classification process" will be described. Fig. 13 is a flowchart showing an example of the procedure of the classification process according to the first embodiment.
[0097] The receiving unit 131 receives an application to be classified (S201).
[0098] The extraction unit 133a extracts a first feature amount from the application to be classified (S202). Next, the conversion unit 133b inputs the first feature amount into a conversion model and converts it into a second feature amount (S203).
[0099] The classification unit 133c inputs the second feature amount into a classification model and performs classification processing (S204). Furthermore, the classification unit 133c classifies the applications to be classified based on the classification results of the second feature amount (S205).
[0100] The output unit 134 outputs the classification result (S206), and the classification device 100 ends the process.
[0101] (effect) Next, the effects of the classification device 100 according to the first embodiment will be described. The extraction unit 133a of the classification device 100 according to the first embodiment extracts, from an application, obfuscated features that represent the characteristics of the application as first features. The conversion unit 133b of the classification device 100 inputs the first features extracted by the extraction unit 133a into a trained conversion model and converts them into second features that are deobfuscated-like features. Then, the classification unit 133c of the classification device 100 classifies the application using the second features converted by the conversion unit 133b. Therefore, the classification device 100 according to the first embodiment has the effect of improving the classification accuracy of obfuscated applications.
[0102] Specifically, the learning unit 132c uses a predetermined learning dataset that associates learning de-obfuscation features extracted from a de-obfuscated application with learning obfuscation features extracted from an obfuscated application that obfuscates the de-obfuscated application, and trains the model so that when an obfuscated feature is input, the model outputs a second feature.
[0103] In this way, the classification device 100 learns the conversion model by using the feature amounts before and after obfuscation extracted from each application after obfuscating the pre-prepared de-obfuscation application. Therefore, the classification device 100 can create a conversion model that can convert the obfuscation feature amounts extracted from the obfuscation application into de-obfuscation-like feature amounts that are the same as or similar to the feature amounts extracted from the de-obfuscation application.
[0104] As described above, the classification device 100 according to the first embodiment converts the obfuscation feature amounts extracted from the obfuscation application into de-obfuscation-like feature amounts close to the feature amounts of the de-obfuscation application and uses them. Here, although it is not practical in terms of computational complexity or the like to convert the obfuscation application into an application that has not been obfuscated and operates without problems, the classification device 100 does not reproduce the de-obfuscation application itself, but only converts it into a form that can be used by existing classifiers or antivirus software.
[0105] Therefore, the classification device 100 enables accurate classification of obfuscation applications even by existing classifiers. And the classification device 100 can reduce the accuracy degradation when classifying obfuscation applications using existing classifiers. As a result, the classification device 100 has the effect of enabling accurate classification processing for obfuscation applications without modifying or changing existing high-precision classifiers, antivirus software, etc.
[0106] Furthermore, the classification device 100 according to the first embodiment does not make the second feature amounts generated by the conversion process exactly the same as the feature amounts extracted from the de-obfuscation application, but only converts them into the same or similar feature amounts, thereby reducing the processing by the computer.
[0107] <Second Embodiment> Next, a second embodiment, which is another form of the first embodiment, will be described. The second embodiment is an example of generating a non-obfuscated-like feature amount (second feature amount) and performing classification processing for an application whose obfuscation status is unknown, regardless of whether it is obfuscated or not.
[0108] In an actual usage scenario, it may be unknown whether the application to be classified is obfuscated. In that case, the classification device 100 according to the second embodiment can handle both cases of "obfuscated application" and "non-obfuscated application" by converting the feature amount extracted from the input application into a "non-obfuscated-like feature amount" regardless of whether the input application is obfuscated or not.
[0109] First, a series of classification processes by the classification device 100 according to the second embodiment will be described. FIG. 14 is a diagram showing an example of classification processing for an application in which obfuscated and non-obfuscated states coexist according to the second embodiment. FIG. 14 shows a case where conversion from a "non-obfuscated feature amount" to a "non-obfuscated-like feature amount" is performed.
[0110] As shown in FIG. 14, the classification device 100 converts the first feature amount extracted from the application to be classified, whose obfuscation state is unknown, into a second feature amount.
[0111] Specifically, when the input application to be classified is obfuscated, the classification device 100 extracts the first feature amount that is obfuscated from the obfuscated application. Then, the classification device 100 converts the extracted obfuscated first feature amount into a second feature amount that is a non-obfuscated-like feature amount ((1) in FIG. 14).
[0112] On the other hand, when the input application to be classified is not obfuscated, the classification device 100 extracts a first feature amount that is not obfuscated from the non-obfuscated application. Then, the classification device 100 converts the extracted first feature amount that is not obfuscated into a second feature amount that is a non-obfuscated-like feature amount ((2) in FIG. 14).
[0113] Then, the classification device 100 performs classification processing in the same manner as in the first embodiment using the second feature amount extracted as described above.
[0114] (Classification device 100) Next, the configuration of the classification device 100 according to the second embodiment will be described. Since the classification device 100 according to the second embodiment has the same device configuration as the classification device 100 according to the first embodiment, this item will be described again using FIG. 4. As shown in FIG. 4, the classification device 100 according to the second embodiment includes a communication unit 110, a storage unit 120, and a control unit 130. As described above, since the classification device 100 according to the second embodiment has the same functions as the classification device 100 according to the first embodiment, the description of the overlapping parts of the functions will be omitted.
[0115] (Learning unit 132c) When a non-obfuscated feature amount or an obfuscated feature amount is input as the first feature amount, the learning unit 132c learns a conversion model so as to output a second feature amount that is a non-obfuscated-like feature amount. Specifically, the learning unit 132c uses a learning dataset in which an obfuscated feature amount and a non-obfuscated feature amount are associated, and learns a conversion model so as to "convert an obfuscated feature amount into a non-obfuscated-like feature amount" and "convert a non-obfuscated feature amount into a non-obfuscated-like feature amount". Note that the "non-obfuscated-like feature amount" in the above-mentioned "converting a non-obfuscated feature amount into a non-obfuscated-like feature amount" may be the same feature amount as the non-obfuscated feature amount input to the conversion model (that is, a feature amount that outputs the same thing as it is).
[0116] (Conversion unit 133b) The conversion unit 133b converts, without distinction, the feature amounts (first feature amounts) extracted from applications whose obfuscation state is unknown into obfuscation-like feature amounts (second feature amounts). For example, the conversion unit 133b inputs a first feature amount, which is an obfuscation-free feature amount extracted from an obfuscation-free application, into a conversion model, and generates a second feature amount, which is an obfuscation-like feature amount. On the other hand, the conversion unit 133b inputs a first feature amount, which is an obfuscated feature amount extracted from an obfuscated application, into a conversion model, and generates a second feature amount, which is an obfuscation-like feature amount.
[0117] (Procedure of processing by the classification device 100) Regarding the procedure of the processing realized by the classification device 100 according to the second embodiment, since the processing steps are common to those of the first embodiment, detailed description thereof is omitted in this section.
[0118] (Effect) Hereinafter, the effects exhibited by the classification device 100 according to the second embodiment will be described. The classification device 100 according to the second embodiment converts the extracted feature amounts into "obfuscation-like feature amounts" regardless of whether the input application is obfuscated or not.
[0119] In this way, the classification device 100 realizes the classification process of the application to be classified as a series of processes even when it is unknown whether the input application to be classified is obfuscated. Therefore, the classification device 100 has the effect of being able to accurately classify even when it is not known that the application to be classified is obfuscated.
[0120] <Third Embodiment> Hereinafter, a third embodiment, which is another form of the first embodiment, will be described. The third embodiment is an example in which, for an application whose obfuscation state is unknown, the obfuscation state of the application is determined in advance and then the classification process is performed.
[0121] As described in the second embodiment, in an actual usage scenario, when it is unknown whether the application to be classified is obfuscated, the classification device 100 according to the third embodiment can determine in advance whether the application to be classified is obfuscated, so as to be able to handle both cases of "obfuscated application" and "non-obfuscated application".
[0122] First, a series of classification processes by the classification device 100 according to the third embodiment will be described. FIG. 15 is a diagram showing an example of the classification process for an application in which an obfuscated state and a non-obfuscated state coexist according to the third embodiment. FIG. 15 shows a case where "preliminary determination of obfuscation" is performed.
[0123] For example, as shown in FIG. 15, the classification device 100 determines whether the application to be classified is obfuscated based on a determination model learned to determine the obfuscated state of the application ((1) in FIG. 15). Specifically, the classification device 100 uses the result regarding the obfuscated state of the application obtained by inputting various feature amounts extracted from the application to be classified into the determination model to determine whether the application to be classified is an obfuscated application.
[0124] If it is determined that the application is an obfuscated application, the classification device 100 performs classification processing after converting the first obfuscated feature amount extracted from the application to be classified into a second feature amount as described in the first embodiment ((2) and (4) in FIG. 15). On the other hand, if it is determined that the application is a non-obfuscated application, the classification device 100 performs classification processing using the first non-obfuscated feature amount extracted from the application to be classified as it is ((3) and (4) in FIG. 15).
[0125] (Classification device 100) Next, the configuration of the classification device 100 according to the third embodiment will be described. FIG. 16 is a diagram showing an example of the configuration of the classification device 100 according to the third embodiment. As shown in FIG. 16, the classification device 100 includes a communication unit 110, a storage unit 120, and a control unit 130. Since the classification device 100 according to the third embodiment has the same functions as the classification device 100 according to the first embodiment, the description of the overlapping parts will be omitted.
[0126] (Classification function unit 133) In addition to the processes described in the first embodiment, the classification function unit 133 according to the third embodiment performs a pre-determination process on the application to be classified that is input. The classification function unit 133 further includes an extraction unit 133a, a conversion unit 133b, a classification unit 133c, and a determination unit 133d. As described above, since the content of the extraction unit 133a overlaps with that of the first embodiment, the description thereof will be omitted.
[0127] (Conversion unit 133b) When the determination unit 133d described later determines that the application to be classified is obfuscated, the conversion unit 133b converts the first feature amount that is obfuscated into a second feature amount that is a non-obfuscated-like feature amount. For example, when it is determined that the application is an obfuscated application, the conversion unit 133b inputs the obfuscation feature amount (the first feature amount) extracted from the application into a conversion model and generates a non-obfuscated-like feature amount (the second feature amount).
[0128] (Classification unit 133c) The classification unit 133c performs classification processing on the feature amount based on the application and the application related to the feature amount according to the obfuscation state of the application.
[0129] Specifically, when the determination unit 133d described later determines that the application to be classified is not obfuscated, the classification unit 133c performs classification processing using the first feature amount that is not obfuscated. Specifically, the classification unit 133c identifies which of the classifications preset for the first feature amount that is not obfuscated based on the result obtained by inputting the first feature amount that is not obfuscated into a predetermined classification model. Then, the classification unit 133c determines the classification of the application that is the extraction source of the feature amount corresponding to the classified first feature amount that is not obfuscated.
[0130] On the other hand, when it is determined that the application is an obfuscated application, the classification unit 133c performs classification processing in the same manner as in the first embodiment using the second feature amount, which is a non-obfuscated-like feature amount generated from the first feature amount that is obfuscated and extracted from the application.
[0131] (Determination unit 133d) The determination unit 133d determines whether or not the input application to be classified is obfuscated. For example, the determination unit 133d inputs the feature amount extracted from the application to be classified into a determination model. Next, the determination unit 133d determines whether or not the input feature amount is obfuscated based on the result output from the determination model.
[0132] Then, for the application corresponding to the feature amount determined to be obfuscated, the determination unit 133d determines that it is an obfuscated application. On the other hand, for the application corresponding to the feature amount determined not to be obfuscated, the determination unit 13'3d determines that it is a non-obfuscated application.
[0133] Note that the determination unit 133d can use, without limitation, the feature amounts that represent the features of the application, including the first feature amount in the present embodiment, as the above-described feature amounts.
[0134] (Procedure of processing by classification device 100) Hereinafter, the procedure of the process realized by the classification device 100 according to the third embodiment will be described. Regarding the "learning process", since the processing steps are common between the first embodiment and the third embodiment, only the "classification process including pre-determination of obfuscation" will be described in this section. FIG. 17 is a flowchart showing an example of the procedure of the classification process according to the third embodiment.
[0135] The reception unit 131 receives the application to be classified (S301). Next, the extraction unit 133a extracts the first feature amount from the application to be classified (S302).
[0136] The determination unit 133d determines whether it is an obfuscated application (S303). Here, if it is determined that it is an obfuscated application (Yes in S304), the conversion unit 133b inputs the obfuscated first feature amount into the conversion model and converts it into the second feature amount (S305). Then, the classification unit 133c inputs the second feature amount into the classification model and performs the classification process (S306).
[0137] On the other hand, if it is determined that it is not an obfuscated application (No in S304), the classification unit 133c inputs the non-obfuscated first feature amount into the classification model and performs the classification process (S307).
[0138] The classification unit 133c classifies the application to be classified based on the classification result of the above-described feature amount (the result of the process in S306 or S307) (S308).
[0139] The output unit 134 outputs the classification result (S309). Then, the classification device 100 ends the process.
[0140] (Effect) Hereinafter, the effects exhibited by the classification device 100 according to the third embodiment will be described. The classification device 100 according to the third embodiment performs, in addition to the processing of the first embodiment, the pre-determination process of the input application to be classified.
[0141] Specifically, the determination unit 133d of the classification device 100 determines whether the input application is obfuscated. If the determination unit 133d determines that the application is obfuscated, the conversion unit 133b of the classification device 100 converts the extracted obfuscated first feature into a second feature. The classification unit 133c of the classification device 100 performs classification processing using the second feature converted by the conversion unit 133b. On the other hand, if the determination unit 133d determines that the application is not obfuscated, the classification unit 133c of the classification device 100 performs classification processing using the extracted unobfuscated first feature.
[0142] In this way, even when it is unknown whether an input application to be classified is obfuscated, the classification device 100 performs a determination process in advance, thereby realizing the classification process of the application to be classified as a series of processes. Therefore, the classification device 100 has an effect of enabling accurate classification even when it is unknown whether the application to be classified is obfuscated.
[0143] Furthermore, the classification device 100 according to the third embodiment can reduce the amount of processing by a computer by selecting applications that perform feature conversion processing through the above-described prior determination processing.
[0144] <Modification> The following describes modified examples realized by the classification device 100 according to this embodiment.
[0145] (Data, etc.) The conversion model, classification model, judgment model, feature, obfuscation, de-obfuscation, de-obfuscation style, first feature, second feature, application, malware, names of functional parts of the classification device 100, steps, processes, names of steps or processes, etc. used in the description of the above embodiments are merely examples and can be changed as desired.
[0146] For example, but not limited to, the feature DB 123 stores a pre-obfuscation application, an obfuscated application, a non-obfuscated feature, and an obfuscated feature in association with "No," which is information for identifying a row of table information. Also, the feature DB 123 stores an application to be classified, a first feature, and a second feature in association with "No," which is information for identifying a row of table information.
[0147] (Obfuscation) In this embodiment, several known techniques have been exemplified as methods for obfuscating a training application by the obfuscation unit 132a, but the obfuscation unit 132a is not limited to the above-mentioned methods. For example, the obfuscation unit 132a can use any method for obfuscation processing as long as it falls within the category of reversible modification of an application to make an application such as malware difficult to detect by antivirus software or the like.
[0148] (Conversion model) In the present embodiment, it has been described that the conversion process is performed using a trained conversion model trained by the learning function unit 132. However, in practice, this is not limited thereto, and for example, the classification device 100 may use a trained conversion model trained by an external learning device or the like.
[0149] (Classification model) In this embodiment, a number of known techniques have been exemplified as classification models used in the classification process by the classification unit 133c, but the methods are not limited to those described above. For example, the classification unit 133c can use, without limitation, any method as a classification model as long as it falls within the category of processing for classifying input data such as applications by assigning a predetermined label to the data.
[0150] (Decision making process, etc.) In the third embodiment, it has been described that the determination unit 133d determines in advance whether an input application to be classified is an obfuscated application. Here, the determination unit 133d is not particularly limited in the method of determination processing, and can determine, for example, whether an application is obfuscated based on an obfuscation determination technique (for example, related document: JP 2020-060958 A) that compares the appearance frequency indicated by the appearance frequency information with a preset threshold value to determine a branch in a decision tree.
[0151] Furthermore, in the present embodiment, it has been described that the classification device 100 performs the determination process, but the determination process may be performed by an information processing device or the like different from the classification device 100. In this case, the classification device 100 can receive applications associated with flag information such as "obfuscated" or "deobfuscated" and perform the above-described classification process.
[0152] (Flowcharts, etc.) The steps in the flowcharts may be interchanged as long as there is no contradiction, and some steps may not be performed. In addition, conjunctions such as "next," "continue," "further," "at this time," and "on this occasion" used in the explanation of the flowcharts do not limit the order or timing of the execution of the processes in the flowcharts.
[0153] (system) The information including the processing procedures, control procedures, specific names, various data and parameters shown in the above documents and drawings can be changed arbitrarily unless otherwise specified.
[0154] Furthermore, the components of each device shown in the figure are functional concepts and do not necessarily have to be physically configured as shown. In other words, the specific form of distribution and integration of each device is not limited to that shown. In other words, all or part of them can be functionally or physically distributed and integrated in any unit depending on various loads, usage conditions, etc. For example, the learning process and the classification process can be realized by different devices, and the two can be connected via a communication unit.
[0155] Furthermore, the classification device 100 according to this embodiment may be implemented by being incorporated into an existing malware classification system.
[0156] <Hardware configuration> The components of each device shown in the figure are conceptual functional units and do not necessarily have to be physically configured as shown. In other words, the specific form of distribution and integration of each device is not limited to that shown, and all or part of each device can be functionally or physically distributed and integrated in any unit depending on various loads, usage conditions, etc. Furthermore, all or any part of the processing functions performed by each device can be realized by a CPU and a program analyzed and executed by the CPU, or can be realized as hardware using wired logic.
[0157] Furthermore, among the processes described in this embodiment, all or part of the processes described as being performed automatically can also be performed manually using known methods. In addition, the information including the processing procedures, control procedures, specific names, various data, and parameters shown in the drawings can be changed as desired unless otherwise specified.
[0158] <Program> In one embodiment, the various devices constituting the classification device 100 can be implemented by installing a classification program as package software or online software on a desired computer. For example, by executing the classification program on an information processing device, the various devices constituting the classification device 100 can function. The information processing device referred to here includes desktop and notebook personal computers. In addition, the information processing device also includes mobile communication terminals such as smartphones and mobile phones, and slate terminals such as PDAs (Personal Digital Assistants).
[0159] FIG. 18 is a diagram showing an example of a computer that realizes the classification device 100 according to the present embodiment. The computer 1000 has, for example, a memory 1010 and a CPU 1020. The computer 1000 also has a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.
[0160] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM 1012. The ROM 1011 stores a boot program such as a BIOS (Basic Input Output System), for example. The hard disk drive interface 1030 is connected to a hard disk drive 1090. The disk drive interface 1040 is connected to a disk drive 1100. A removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1100, for example. The serial port interface 1050 is connected to, for example, a mouse 1110 and a keyboard 1120. The video adapter 1060 is connected to, for example, a display 1130.
[0161] The hard disk drive 1090 stores, for example, an OS (Operating System) 1091, an application program 1092, a program module 1093, and program data 1094. That is, the programs that define the respective processes of the various devices that make up the classification device 100 are implemented as a program module 1093 in which executable code by a computer is described. The program module 1093 is stored in the hard disk drive 1090, for example. For example, a program module 1093 for executing the same processes as the functional configurations in the various devices that make up the classification device 100 is stored in the hard disk drive 1090. Note that the hard disk drive 1090 may be replaced by an SSD (Solid State Drive).
[0162] Furthermore, setting data used in the processing of the above-described embodiment is stored as program data 1094, for example, in the memory 1010 or the hard disk drive 1090. Then, the CPU 1020 reads the program module 1093 or the program data 1094 stored in the memory 1010 or the hard disk drive 1090 into the RAM 1012 as necessary, and executes the processing of the above-described embodiment.
[0163] The program module 1093 and program data 1094 are not limited to being stored in the hard disk drive 1090, but may also be stored in, for example, a removable storage medium and read by the CPU 1020 via the disk drive 1100 or the like. Alternatively, the program module 1093 and program data 1094 may be stored in another computer connected via a network (such as a LAN or a WAN (Wide Area Network)). The program module 1093 and program data 1094 may then be read by the CPU 1020 from the other computer via the network interface 1070.
[0164] <Other> Although the present embodiment has been described above, the present embodiment is not limited by the descriptions and drawings that form part of the disclosure. In other words, other embodiments, examples, operational techniques, etc. that are made by those skilled in the art based on the present embodiment are all included in the scope of the present embodiment. [Explanation of symbols]
[0165] 100 Classifier 110 Communications Department 120 Storage section 121 Model DB 122 Application DB 123 Feature DB 124 Classification result DB 130 control section 131 Reception 132 Learning Functions 132a Obfuscation section 132b Extraction part 132c Learning Department 133 Classification function section 133a Extraction part 133b Conversion section 133c Classification Department 133d Judgment section 134 Output section
Claims
1. An extraction unit that extracts a first feature quantity that is a feature quantity representing the features of the application from the application; The first feature quantity extracted by the extraction unit is input into a model learned to convert the obfuscation state of the input feature quantity, and is converted into a second feature quantity that is the same as or similar to the feature quantity extracted from an application that has not been obfuscated. A conversion unit; A classification unit that classifies the application using the second feature quantity converted by the conversion unit; A classification device, characterized by comprising the above.
2. Using a predetermined learning dataset in which a non-obfuscated feature quantity for learning extracted from a non-obfuscated application that has not been obfuscated is associated with an obfuscated feature quantity for learning extracted from an obfuscated application obtained by obfuscating the non-obfuscated application, The classification device according to claim 1, further comprising a learning unit that learns the model so as to output the second feature quantity when at least one of a non-obfuscated feature quantity and an obfuscated feature quantity is input as the first feature quantity.
3. The classification device according to claim 1, further comprising a determination unit that determines whether or not the input application has been obfuscated, The conversion unit, When it is determined by the determination unit that the application has been obfuscated, converts the obfuscated first feature quantity into the second feature quantity, The classification unit, When it is determined by the determination unit that the application has been obfuscated, performs classification processing using the second feature quantity converted by the conversion unit using the obfuscated first feature quantity, When it is determined by the determination unit that the application has not been obfuscated, performs classification processing using the non-obfuscated first feature quantity.
4. A classification method for causing a classification device to execute, An extraction step of extracting a first feature quantity that is a feature quantity representing the features of the application from the application; A conversion step of inputting the first feature quantity extracted in the extraction step into a model learned to convert the obfuscation state of the input feature quantity, and converting it into a second feature quantity that is the same as or similar to the feature quantity extracted from an application that has not been obfuscated; A classification step of classifying the application using the second feature quantity converted in the conversion step; A classification method, characterized by including the above.
Citation Information
Patent Citations
Learning device, classification device, learning method, and learning program
JP7276483B2