Obfuscated Malware Detection Using Deep Generative Model based on Global/Local Features. Issue 112 (January 2022)
- Record Type:
- Journal Article
- Title:
- Obfuscated Malware Detection Using Deep Generative Model based on Global/Local Features. Issue 112 (January 2022)
- Main Title:
- Obfuscated Malware Detection Using Deep Generative Model based on Global/Local Features
- Authors:
- Kim, Jin-Young
Cho, Sung-Bae - Abstract:
- Abstract: As a large amount of malicious software (malware), including DDoS or Trojan horse pervade in communication networks, several approaches based on global and local features have been attempted to cope with some modifications added in malware variants such as null value insertion, code interchange, and reordering of subroutines. Detectors that use only one type of feature have been studied a lot, but what uses both features is rarely investigated, although good performance might be expected due to their complementary characteristics. In this paper, we propose a hybrid deep generative model that exploits global and local features together to detect the malware variants effectively. While transforming malware into an image to efficiently represent global features with pre-defined latent space, it extracts local features using the binary code sequences. The two features extracted from the data with their respective characteristics are concatenated and entered into the malware detector. By using both features, the proposed model achieves an accuracy of 97.47%, resulting in the state-of-the-art performance. We analyze what parts of the malware code affect the results of detection through a class activation map (CAM) and confirm the usefulness by analyzing the CAM results of the generated malware that virtual malware generation improves detection performance.
- Is Part Of:
- Computers & security. Issue 112(2022)
- Journal:
- Computers & security
- Issue:
- Issue 112(2022)
- Issue Display:
- Volume 112, Issue 112 (2022)
- Year:
- 2022
- Volume:
- 112
- Issue:
- 112
- Issue Sort Value:
- 2022-0112-0112-0000
- Page Start:
- Page End:
- Publication Date:
- 2022-01
- Subjects:
- malicious software -- sensor networks -- global features -- local features -- deep learning -- generative model -- temporal model
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2021.102501 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 20097.xml