A Malware Detection Method of Code Texture Visualization Based on an Improved Faster RCNN Combining Transfer Learning

被引:26
|
作者
Zhao, Yuntao [1 ]
Cui, Wenjie [1 ]
Geng, Shengnan [2 ]
Bo, Bo [1 ]
Feng, Yongxin [3 ]
Zhang, Wenbo [3 ]
机构
[1] Shenyang Ligong Univ, Sch Informat Sci & Engn, Shenyang 110159, Peoples R China
[2] Beijing Inst Astronaut Syst Engn, Beijing 100000, Peoples R China
[3] Shenyang Ligong Univ, Grad Sch, Shenyang 110159, Peoples R China
来源
IEEE ACCESS | 2020年 / 8卷 / 08期
基金
中国博士后科学基金;
关键词
Malware; Feature extraction; Machine learning; Data mining; Cyberspace; Acceleration; Convergence; Cyberspace security; faster RCNN; malware detection; code classification; transfer model;
D O I
10.1109/ACCESS.2020.3022722
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Today, with the continuous promotion and development of IoT and 5G technology, Cyberspace has become an important pillar of economic and social development, and also a foundational domain of national security. Cyberspace security is attracting more and more attention. Therefore, detecting malware and its variants is of great significance to Cyberspace. However, the increasing sophistication of malicious variants, such as encryption, polymorphism and obfuscation, makes it more difficult to identified malware effectively. In this article, a malware detection method of code texture visualization based on an improved Faster RCNN (Region-Convolutional Neural Networks) combining transfer learning is proposed. We utilize visualization technology to map malicious code into corresponding images with typical texture features, and realize the classification of malware. Firstly, in order to quickly acquire and locate the representative texture of malware, we adopt CNN to extract the global and deeper features of malicious code images. Then with RPN (Region Proposal Network) we generate the target image frame, which is used to locate the core texture of malware file (.text file), to realize the accurate positioning of malicious features. Secondly, we preprocess and train Faster RCNN model with ImageNet set, and then transfer the model to the malware classification model to accelerate the convergence of the first model and promote generation performance. Thirdly, we construct an improved objective function in which a novel multi-label of classification proportion is added to solve the problem that the texture change of ".text" section and other sections in malicious code image is not obvious after transfer learning. We collect code samples of six malware families from Kaggle platform, and compared the experimental results before and after transfer. The results show that the novel method can accelerate the convergence of loss function, and obtain higher accuracy (92.8%), lower FPR (6.8%) and better P-R (precision-recall) curve.
引用
收藏
页码:166630 / 166641
页数:12
相关论文
共 50 条
  • [41] Airport Detection Based on Improved Faster RCNN in Large Scale Remote Sensing Images
    Yin, Shoulin
    Li, Hang
    Teng, Lin
    SENSING AND IMAGING, 2020, 21 (01):
  • [42] Small Target Modified Car Parts Detection Based on Improved Faster-RCNN
    Xue, Hongcheng
    Qin, Junping
    Ren, Wei
    Quan, Chao
    Gao, Tong
    INTERNATIONAL CONFERENCE ON IMAGE PROCESSING AND INTELLIGENT CONTROL (IPIC 2021), 2021, 11928
  • [43] Machine Learning Based Improved Malware Detection Schemes
    Priyadarshan, Pradosh
    Sarangi, Prateek
    Ratht, Adyasha
    Rath, Adyasha
    Panda, Ganapati
    2021 11TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING, DATA SCIENCE & ENGINEERING (CONFLUENCE 2021), 2021, : 925 - 931
  • [44] A Malware Detection Method Based on Hybrid Learning
    Liang G.-H.
    Bai L.
    Pang J.-M.
    Shan Z.
    Yue F.
    Zhang L.
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2021, 49 (02): : 286 - 291
  • [45] MC-ISA: A Multi-Channel Code Visualization Method for Malware Detection
    Qi, Xuyan
    Liu, Wei
    Lou, Rui
    Li, Qinghao
    Jiang, Liehui
    Tang, Yonghe
    ELECTRONICS, 2023, 12 (10)
  • [46] Fabric defect detection based on transfer learning and improved Faster R-CNN
    Jia, Zhao
    Shi, Zhou
    Quan, Zheng
    Mei Shunqi
    JOURNAL OF ENGINEERED FIBERS AND FABRICS, 2022, 17
  • [47] An improved RepLKNet-based malware detection method
    Zhang, Dandan
    Wang, Yang
    Song, Yafei
    2023 11TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: IOT AND SMART CITY, ITIOTSC 2023, 2023, : 199 - 202
  • [48] Esophageal cancer detection based on classification of gastrointestinal CT images using improved Faster RCNN
    Chen, Kuan-bing
    Xuan, Ying
    Lin, Ai -jun
    Guo, Shao-hua
    COMPUTER METHODS AND PROGRAMS IN BIOMEDICINE, 2021, 207
  • [49] MalDeep: A Deep Learning Classification Framework against Malware Variants Based on Texture Visualization
    Zhao, Yuntao
    Xu, Chunyu
    Bo, Bo
    Feng, Yongxin
    SECURITY AND COMMUNICATION NETWORKS, 2019, 2019
  • [50] Improved Faster-RCNN Based Biomarkers Detection in Retinal Optical Coherence Tomography Images
    Liu, Xiaoming
    Zhou, Kejie
    Wang, Man
    Zhang, Ying
    2022 IEEE 34TH INTERNATIONAL CONFERENCE ON TOOLS WITH ARTIFICIAL INTELLIGENCE, ICTAI, 2022, : 1088 - 1092