A Malware Detection Method of Code Texture Visualization Based on an Improved Faster RCNN Combining Transfer Learning

被引:26
|
作者
Zhao, Yuntao [1 ]
Cui, Wenjie [1 ]
Geng, Shengnan [2 ]
Bo, Bo [1 ]
Feng, Yongxin [3 ]
Zhang, Wenbo [3 ]
机构
[1] Shenyang Ligong Univ, Sch Informat Sci & Engn, Shenyang 110159, Peoples R China
[2] Beijing Inst Astronaut Syst Engn, Beijing 100000, Peoples R China
[3] Shenyang Ligong Univ, Grad Sch, Shenyang 110159, Peoples R China
来源
IEEE ACCESS | 2020年 / 8卷 / 08期
基金
中国博士后科学基金;
关键词
Malware; Feature extraction; Machine learning; Data mining; Cyberspace; Acceleration; Convergence; Cyberspace security; faster RCNN; malware detection; code classification; transfer model;
D O I
10.1109/ACCESS.2020.3022722
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Today, with the continuous promotion and development of IoT and 5G technology, Cyberspace has become an important pillar of economic and social development, and also a foundational domain of national security. Cyberspace security is attracting more and more attention. Therefore, detecting malware and its variants is of great significance to Cyberspace. However, the increasing sophistication of malicious variants, such as encryption, polymorphism and obfuscation, makes it more difficult to identified malware effectively. In this article, a malware detection method of code texture visualization based on an improved Faster RCNN (Region-Convolutional Neural Networks) combining transfer learning is proposed. We utilize visualization technology to map malicious code into corresponding images with typical texture features, and realize the classification of malware. Firstly, in order to quickly acquire and locate the representative texture of malware, we adopt CNN to extract the global and deeper features of malicious code images. Then with RPN (Region Proposal Network) we generate the target image frame, which is used to locate the core texture of malware file (.text file), to realize the accurate positioning of malicious features. Secondly, we preprocess and train Faster RCNN model with ImageNet set, and then transfer the model to the malware classification model to accelerate the convergence of the first model and promote generation performance. Thirdly, we construct an improved objective function in which a novel multi-label of classification proportion is added to solve the problem that the texture change of ".text" section and other sections in malicious code image is not obvious after transfer learning. We collect code samples of six malware families from Kaggle platform, and compared the experimental results before and after transfer. The results show that the novel method can accelerate the convergence of loss function, and obtain higher accuracy (92.8%), lower FPR (6.8%) and better P-R (precision-recall) curve.
引用
收藏
页码:166630 / 166641
页数:12
相关论文
共 50 条
  • [21] Underwater Biological Detection Algorithm Based on Improved Faster-RCNN
    Shi, Pengfei
    Xu, Xiwang
    Ni, Jianjun
    Xin, Yuanxue
    Huang, Weisheng
    Han, Song
    WATER, 2021, 13 (17)
  • [22] Detection of spinal fracture lesions based on Improved Faster-RCNN
    Sha, Gang
    Wu, Junsheng
    Yu, Bin
    PROCEEDINGS OF 2020 IEEE INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND INFORMATION SYSTEMS (ICAIIS), 2020, : 29 - 32
  • [23] Underwater fish detection in sonar image based on an improved Faster RCNN
    Zhao, Di
    Dou, Yinke
    Yang, Bo
    Guo, Xiaojia
    2022 9TH INTERNATIONAL FORUM ON ELECTRICAL ENGINEERING AND AUTOMATION, IFEEA, 2022, : 358 - 363
  • [24] Surface Defect Detection Algorithm of Aluminum Based on Improved Faster RCNN
    Li, Lu
    Jiang, Zhanjun
    Li, Yanneng
    2021 IEEE 9TH INTERNATIONAL CONFERENCE ON INFORMATION, COMMUNICATION AND NETWORKS (ICICN 2021), 2021, : 522 - 526
  • [25] Malware detection based on semi-supervised learning with malware visualization
    Gao, Tan
    Zhao, Lan
    Li, Xudong
    Chen, Wen
    MATHEMATICAL BIOSCIENCES AND ENGINEERING, 2021, 18 (05) : 5995 - 6011
  • [26] A high-precision detection method of hydroponic lettuce seedlings status based on improved Faster RCNN
    Li, Zhenbo
    Li, Ye
    Yang, Yongbo
    Guo, Ruohao
    Yang, Jinqi
    Yue, Jun
    Wang, Yizhe
    COMPUTERS AND ELECTRONICS IN AGRICULTURE, 2021, 182
  • [27] A Small Object Detection Method for Oil Leakage Defects in Substations Based on Improved Faster-RCNN
    Yang, Qiang
    Ma, Song
    Guo, Dequan
    Wang, Ping
    Lin, Meichen
    Hu, Yangheng
    SENSORS, 2023, 23 (17)
  • [28] Spark plug defects detection based on improved Faster-RCNN algorithm
    Liu, Yuhang
    Liu, Yi
    Zhang, Pengcheng
    Zhang, Quan
    Wang, Lei
    Yan, Rongbiao
    Li, Wenqiang
    Gui, Zhiguo
    JOURNAL OF X-RAY SCIENCE AND TECHNOLOGY, 2022, 30 (04) : 709 - 724
  • [29] Table Detection Method Based on Faster-RCNN and Window Attention
    Chen, Han
    Song, Shengli
    Su, Rijian
    PROCEEDINGS OF 2023 THE 12TH INTERNATIONAL CONFERENCE ON NETWORKS, COMMUNICATION AND COMPUTING, ICNCC 2023, 2023, : 267 - 273
  • [30] Object Detection in Autonomous Driving Scenarios Based on an Improved Faster-RCNN
    Zhou, Yan
    Wen, Sijie
    Wang, Dongli
    Mu, Jinzhen
    Richard, Irampaye
    APPLIED SCIENCES-BASEL, 2021, 11 (24):