MINES: Multi-perspective API Call Sequence Behavior Fusion Malware Classification

被引:1
|
作者
Gao, Mohan [1 ]
Wu, Peng [1 ,2 ]
Pan, Li [1 ,2 ]
机构
[1] Shanghai Jiao Tong Univ, Sch Elect Informat & Elect Engn, Shanghai, Peoples R China
[2] Shanghai Jiao Tong Univ, Shanghai Key Lab Integrated Adm Technol Informat, Shanghai, Peoples R China
基金
中国国家自然科学基金;
关键词
Malware Detection; Contrastive Learning; Graph Neural Network;
D O I
10.1007/978-981-97-5562-2_13
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The growing variety of malicious software, i.e., malware, has caused great damage and economic loss to computer systems. The API call sequence of malware reflects its dynamic behavior during execution, which is difficult to disguise. Therefore, API call sequence can serve as a robust feature for the detection and classification of malware. There are two distinct characteristics within the API call sequences of malware: 1) the API existence feature caused by frequent calls to the APIs with some special functions, and 2) the API transition feature caused by frequent calls to some special API subsequence patterns. Based on these two characteristics, this paper proposes the Multi-perspective apI call sequeNce bEhavior fuSion malware classification Method, called MINES. It adopts the graph contrastive learning framework to extract the API existence feature from two graphs that model relationships between APIs from different perspectives. Similarly, a CNN-based contrastive learning framework is adopted to extract the API transition feature from two sets of multi-hop transition matrices. Finally, the extracted two features are fused to classify malware. Experiments on five datasets demonstrate the superiority of MINES over various state-of-the-arts by a large margin.
引用
收藏
页码:210 / 220
页数:11
相关论文
共 50 条
  • [21] Multi-Perspective Hierarchical Deep-Fusion Learning Framework for Lung Nodule Classification
    Sekeroglu, Kazim
    Soysal, Omer Muhammet
    SENSORS, 2022, 22 (22)
  • [22] A Comparison Between API Call Sequences and Opcode Sequences as Reflectors of Malware Behavior
    Alqurashi, Saja
    Batarfi, Omar
    2017 12TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2017, : 105 - 110
  • [23] Text to Image Synthesis based on Multi-Perspective Fusion
    Zhang, Zhiqiang
    Fu, Chen
    Zhou, Jinjia
    Yu, Wenxin
    Jiang, Ning
    2021 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2021,
  • [24] Using API Call Sequences for IoT Malware Classification Based on Convolutional Neural Networks
    Lin, Qianguang
    Li, Ni
    Qi, Qi
    Hu, Jiabin
    INTERNATIONAL JOURNAL OF SOFTWARE ENGINEERING AND KNOWLEDGE ENGINEERING, 2021, 31 (04) : 587 - 612
  • [25] Evolutionary Binary Classification using Cuckoo Search for Malware Perception in API Call Sequences
    Krishna, G. Bala
    Radha, V.
    Rao, K. Venu Gopala
    2017 IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND COMPUTING RESEARCH (ICCIC), 2017, : 474 - 481
  • [26] Multi-perspective gait recognition based on classifier fusion
    Wang, Xiuhui
    Feng, Shiling
    IET IMAGE PROCESSING, 2019, 13 (11) : 1885 - 1891
  • [27] A multi-perspective taxonomy for systematic classification of grid faults
    Hofer, Juergen
    Fahringer, Thomas
    PROCEEDINGS OF THE 16TH EUROMICRO CONFERENCE ON PARALLEL, DISTRIBUTED AND NETWORK-BASED PROCESSING, 2008, : 126 - 130
  • [28] Aspect dependent drivers for multi-perspective target classification
    Vespe, Michele
    Baker, Chris J.
    Griffiths, Hugh D.
    2006 IEEE RADAR CONFERENCE, VOLS 1 AND 2, 2006, : 256 - +
  • [29] BINet: Multi-perspective business process anomaly classification
    Nolle, Timo
    Luettgen, Stefan
    Seeliger, Alexander
    Muehlhaeuser, Max
    INFORMATION SYSTEMS, 2022, 103
  • [30] Stance Classification of Multi-Perspective Consumer Health Information
    Sen, Anirban
    Sinha, Manjira
    Mannarswamy, Sandya
    Roy, Shourya
    PROCEEDINGS OF THE ACM INDIA JOINT INTERNATIONAL CONFERENCE ON DATA SCIENCE AND MANAGEMENT OF DATA (CODS-COMAD'18), 2018, : 273 - 282