Bài viết
Nâng cao hiệu quả phát hiện mã độc của mô hình deeplearning với phương pháp biểu diễn ảnh mới
- Võ Khương Lĩnh (VN)
- Nguyễn Việt Hùng (VN)
- Trần Ngọc Anh (VN)
- Dương Đỗ Nhuận (VN)
- Đinh Công Hiển (VN)
Tóm tắt
Trong những năm gần đây, phần mềm độc hại (malware) do tin tặc tạo ra có sự bùng nổ về số lượng trên phạm vi toàn cầu. Sự xuất hiện của lượng lớn các biến thể phần mềm độc hại đã gây ra những khó khăn nhất định cho các phương pháp phát hiện phần mềm độc hại truyền thống. Một trong những hướng nghiên cứu được quan tâm gần đây là ứng dụng trí tuệ nhân tạo để giải quyết vấn đề. Bài báo này đề xuất phương pháp mới biểu diễn mã độc dưới dạng ảnh bằng cách sắp xếp các byte có độ tương quan cao về các pixel gần nhau trên ảnh. Các mô hình học sâu được huấn luyện trên tập dữ liệu thực tế tự xây dựng và so sánh hiệu suất của các phương pháp biểu diễn hình ảnh khác nhau. Kết quả thử nghiệm cho thấy phương pháp đề xuất với cách sắp xếp pixel theo “hình rắn” (serpentine) mang lại kết quả tốt hơn các phương pháp khác.
Lượt tải theo tháng
Di chuột vào cột để xem số lượt tải.
Cách trích dẫn
Võ Khương Lĩnh, Nguyễn Việt Hùng, Trần Ngọc Anh, Dương Đỗ Nhuận, Đinh Công Hiển (2024). Nâng cao hiệu quả phát hiện mã độc của mô hình deeplearning với phương pháp biểu diễn ảnh mới. Tạp chí Khoa học và Công nghệ trong lĩnh vực An toàn thông tin, 1(21), 31-39. https://doi.org/10.54654/isj.v1i21.1000
Tài liệu tham khảo
- 1.Anh Tran Ngoc, Linh Vo Khuong, (2021), “Malware detection based on Machine Learning and PE header information”, Information Security Journal, Vietnam.
- 2.Alex Krizhevsky, Ilya Sutskever, Geoffrey E. Hinton, (2012), “ImageNet Classification with Deep Convolutional Neural Networks”, International Conference on Neural Information Processing Systems (NIPS).
- 3.Edward Raff, Jared Sylvester, Charles Nicholas, (2017), “Learning the PE Header, Malware Detection with Minimal Domain Knowledge”, ACM Workshop on Artificial Intelligence and Security.
- 4.Gibert, D, (2016), “Convolutional neural networks for malware classification”, University Rovira i Virgili, Tarragona, Spain.
- 5.Hironobu Fujiyoshi, Tsubasa Hirakawa, Takayoshi Yamashita, (2019), “Deep learning-based image recognition for autonomous driving”, IATSS Research, vol 43, issue 4, pages 244-252.
- 6.Hung Nguyen Viet, Ngoc Quach Danh, Dung Pham Ngoc, (2019), “Research on techniques of representing malware files and deep learning models in malware detection”, XXII National Conference: Some selected issues of Information and Communication Technology, Thai Binh, Vietnam.
- 7.Huu Danh Pham, Tuan Dinh Le, Thanh Nguyen Vu, (2018), “Static PE Malware Detection Using Gradient Boosting Decision Trees Algorithm”, International Conference on Future Data and Security Engineering, pp 228-236.
- 8.Kephart J.O. Tesauro, G.J., Gregory B Sorkin, (1996), “Neural networks for computer virus recognition”, IEEE International Conference on Intelligence and Security Informatics.
- 9.L. Nataraj, S. Karthikeyan, G. Jacob, and B. S. Manjunath, (2011), “Malware images: Visualization and automatic classification”, Proceedings of the 8th International Symposium on Visualization for Cyber Security.
- 10.Li Deng, George E. Dahl, Jack W. Stokes and Dong Yu (2013), “Large-scale malware classification using random projections and neural network”, ICASSP.
- 11.Moreira, C. C., Moreira, D. C., & de Sales Jr, C. D. S. (2023), “Improving ransomware detection based on portable executable header using xception convolutional neural network”, Computers & Security, 130, 103265.
- 12.Nitish Srivastava, Geoffrey Hinton, Alex Krizhevsky, Ilya Sutskever, and Ruslan Salakhutdinov, (2013), “Dropout: A simple way to prevent neural networks from overfitting J. Mach. Learn. Res.”. 15(1):1929–1958.
- 13.N. Idika, A.P. Mathur, (2007), “A Survey of Malware Detection Techniques”, Purdue University.
- 14.Rabia Tahir, (2018), “A Study on Malware and Malware Detection Techniques”, International Journal of Education and Management, MECS.
- 15.Rahul Chauhan, Karmal K. Ghanshala, R.C Joshi, (2018), “Convolutional Neural Network (CNN) for Image Detection and Recognition”, First International Conference on Secure Cyber Computing and Communication.
- 16.Razvan Pascanu, Jack W. Stokes, Li Deng, Dong Yu, Mady Marinescu, Anil Thomas, (2015), “Malware Classification with Recurrent Networks”, IEEE ICASSP.
- 17.Ren, Z., Chen, G., & Lu, W. (2020), “Malware visualization methods based on deep convolution neural networks”, Multimedia Tools and Applications, 79, 10975-10993.
- 18.Sunoh Choi, Sungwook Jang, Youngsoo Kim, Jonghyun Kim, (2017), “Malware Detection using Malware Image and Deep Learning”, International Conference on Information and Communication Technology Convergence, Jeju, Korea (South).
- 19.P. V. Dinh, N. Shone, P. H. Dung, Q. Shi, N. V. Hung and T. Nguyen Ngoc, "Behaviour-aware Malware Classification: Dynamic Feature Selection," 2019 11th International Conference on Knowledge and Systems Engineering (KSE), Da Nang, Vietnam, 2019, pp. 1-5, doi: 10.1109/KSE.2019.8919491.
- 20.Tu Nguyen Minh, Hung Nguyen Viet, Anh Phan Viet, Loi Cao Van, Nathan Shone, “Detecting Malware Based on Dynamic Analysis Techniques Using Deep Graph Learning”, Lecture Notes in Computer Science, vol. 12466, 2020.
- 21.Nguyen, M.T., Nguyen, V.H. & Shone, N. Using deep graph learning to improve dynamic analysis-based malware detection in PE files. J Comput Virol Hack Tech 20, 153–172 (2024). https://doi.org/10.1007/s11416-023-00505-x.
- 22.Seonhee Seok, Howon Kim, (2016), “Visualized Malware Classification Based on Convolutional Network”, Journal of The Korea Institute of Information Security and Cryptology.
- 23.N. V. Hung, P. Ngoc Dung, T. N. Ngoc, V. Dinh Phai and Q. Shi, "Malware detection based on directed multi-edge dataflow graph representation and convolutional neural network," 2019 11th International Conference on Knowledge and Systems Engineering (KSE), Da Nang, Vietnam, 2019, pp. 1-5, doi: 10.1109/KSE.2019.8919284.
- 24.VirusShare.com, https://virusshare.com/.
- 25.VirusTotal.com, https://www.virustotal.com/.
- 26.Wenyi Huang, Jack W.Stokes, (2016), “MtNet: A Multi-Task Neural Network for Dynamic Malware Classification”, DIMVA.
- 27.Noi, N. H., & Ngoc, T. N. (2023). Learning Latent Representation with Limited Labels for IoT Anomaly Detection. Journal of Science and Technology on Information Security, 3(20), 14-22. https://doi.org/10.54654/isj.v3i20.986.
Bài viết liên quan
- Phát triển Framework ứng dụng AI hỗ trợ tự động khai thác lỗ hổng bảo mật
- Applying reinforcement learning in automated penetration testing
- Tự động chọn hàm bị loại bỏ trong kiểm thử bản vá khi sử dụng Thực thi tượng trưng lược bớt
- Ứng dụng mô hình học sâu trong phát hiện tấn công trinh sát mạng
- Nền tảng phân loại tấn công mạng dựa vào mô hình Autoencoder và công nghệ phân tích luồng trực tuyến
- Nâng cao hiệu quả mô hình học máy trong phát hiện tấn công lừa đảo website sử dụng đặc điểm hình thái trong phân tích URL