A Malware Detection Method of Code Texture Visualization Based on an Improved Faster RCNN Combining Transfer Learning

被引:26
|
作者
Zhao, Yuntao [1 ]
Cui, Wenjie [1 ]
Geng, Shengnan [2 ]
Bo, Bo [1 ]
Feng, Yongxin [3 ]
Zhang, Wenbo [3 ]
机构
[1] Shenyang Ligong Univ, Sch Informat Sci & Engn, Shenyang 110159, Peoples R China
[2] Beijing Inst Astronaut Syst Engn, Beijing 100000, Peoples R China
[3] Shenyang Ligong Univ, Grad Sch, Shenyang 110159, Peoples R China
来源
IEEE ACCESS | 2020年 / 8卷 / 08期
基金
中国博士后科学基金;
关键词
Malware; Feature extraction; Machine learning; Data mining; Cyberspace; Acceleration; Convergence; Cyberspace security; faster RCNN; malware detection; code classification; transfer model;
D O I
10.1109/ACCESS.2020.3022722
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Today, with the continuous promotion and development of IoT and 5G technology, Cyberspace has become an important pillar of economic and social development, and also a foundational domain of national security. Cyberspace security is attracting more and more attention. Therefore, detecting malware and its variants is of great significance to Cyberspace. However, the increasing sophistication of malicious variants, such as encryption, polymorphism and obfuscation, makes it more difficult to identified malware effectively. In this article, a malware detection method of code texture visualization based on an improved Faster RCNN (Region-Convolutional Neural Networks) combining transfer learning is proposed. We utilize visualization technology to map malicious code into corresponding images with typical texture features, and realize the classification of malware. Firstly, in order to quickly acquire and locate the representative texture of malware, we adopt CNN to extract the global and deeper features of malicious code images. Then with RPN (Region Proposal Network) we generate the target image frame, which is used to locate the core texture of malware file (.text file), to realize the accurate positioning of malicious features. Secondly, we preprocess and train Faster RCNN model with ImageNet set, and then transfer the model to the malware classification model to accelerate the convergence of the first model and promote generation performance. Thirdly, we construct an improved objective function in which a novel multi-label of classification proportion is added to solve the problem that the texture change of ".text" section and other sections in malicious code image is not obvious after transfer learning. We collect code samples of six malware families from Kaggle platform, and compared the experimental results before and after transfer. The results show that the novel method can accelerate the convergence of loss function, and obtain higher accuracy (92.8%), lower FPR (6.8%) and better P-R (precision-recall) curve.
引用
收藏
页码:166630 / 166641
页数:12
相关论文
共 50 条
  • [31] Research on Fabric Defect Detection Technology Based on EDSR and Improved Faster RCNN
    Yao, Li
    Zhang, Naigang
    Gao, Ao
    Wan, Yan
    KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, KSEM 2022, PT III, 2022, 13370 : 477 - 488
  • [32] Detection model based on improved faster-RCNN in apple orchard environment
    Kong, Xiaohong
    Li, Xinjian
    Zhu, Xinxin
    Guo, Ziman
    Zeng, Linpeng
    INTELLIGENT SYSTEMS WITH APPLICATIONS, 2024, 21
  • [33] Aeroengine Blade Surface Defect Detection System Based on Improved Faster RCNN
    Liu, Yixuan
    Wu, Dongbo
    Liang, Jiawei
    Wang, Hui
    INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2023, 2023
  • [34] Surface defect detection and realization of metal workpiece based on improved faster RCNN
    Dai, Xiao-Hong
    Chen, Hua-Jiang
    Zhu, Chao-Ping
    Surface Technology, 2020, 49 (10): : 362 - 371
  • [35] Malware Detection Based on Code Visualization and Two-Level Classification
    Moussas, Vassilios
    Andreatos, Antonios
    INFORMATION, 2021, 12 (03) : 1 - 14
  • [36] Design of apple recognition model based on improved deep learning object detection framework Faster-RCNN
    Zhao, Qinghua
    Liu, Yaqiu
    ADVANCES IN CONTINUOUS AND DISCRETE MODELS, 2024, 2024 (01):
  • [37] Malware detection method based on enhanced code images
    Sun B.
    Zhang P.
    Cheng M.
    Li X.
    Li Q.
    Qinghua Daxue Xuebao/Journal of Tsinghua University, 2020, 60 (05): : 386 - 392
  • [38] Airport Detection Based on Improved Faster RCNN in Large Scale Remote Sensing Images
    Shoulin Yin
    Hang Li
    Lin Teng
    Sensing and Imaging, 2020, 21
  • [39] An Insulator in Transmission Lines Recognition and Fault Detection Model Based on Improved Faster RCNN
    Zhao, Wenqing
    Xu, Minfu
    Cheng, Xingfu
    Zhao, Zhenbing
    IEEE TRANSACTIONS ON INSTRUMENTATION AND MEASUREMENT, 2021, 70
  • [40] AS-Faster-RCNN: An Improved Object Detection Algorithm for Airport Scene Based on Faster R-CNN
    He, Zhige
    He, Yuanqing
    IEEE ACCESS, 2025, 13 : 36050 - 36064