arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

防范组织面临的恶意软件风险:一种新颖的基于图的恶意软件检测方法

Guarding Organizations Against Malware Risk: A Novel Graph-Based Malware Detection Method

Yinan Gao, Jiarong Xu, Xiaohang Zhao, Xiao Fang

arXiv 2607.26634首次发表:更新:

发表机构

School of Management, Fudan University; School of Information Management and Engineering, Shanghai University of Finance and Economics; Lerner College of Business and Economics, University of Delaware(复旦大学管理学院; 上海财经大学信息管理与工程学院; 特拉华大学勒纳工商经济学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对恶意软件规避行为的问题,提出基于图的 MalGuard 方法,通过识别操作角色和学习程序图表示提升恶意软件检测性能,降低未检测恶意软件的预期成本。

AI 中文摘要

组织数字化扩大了网络安全风险,使网络安全成为信息系统(IS)领域日益重要的研究方向。在这些风险中,恶意软件已成为一种普遍且具有破坏性的威胁。基于字节的机器学习(ML)方法被广泛用于恶意软件检测,但仍易受到规避行为的影响,这些行为会操纵原始字节以逃避检测。基于图的方法受此类操纵的影响较小,因为它们将软件表示为程序图,可捕获执行行为。然而,这些方法并未明确识别共同实现有意义程序行为的基本块 cohesive 组,也未学习到足够具表达力的程序图表示以实现准确检测。为此,我们提出 MalGuard,一种用于组织恶意软件风险管理的基于图的恶意软件检测方法。MalGuard 引入了两项方法创新:操作角色识别方法和程序图表示学习方法。前者将这些基本块的 cohesive 组识别为操作角色,使检测器能够捕获从孤立基本块中可能无法看到的程序行为;后者通过建模操作角色之间的交互、保留稀疏恶意信号以及捕获层次图结构来学习具表达力的程序图表示。大量实验表明,MalGuard 提升了检测性能并降低了未检测到恶意软件的预期成本。

英文摘要

Organizational digitalization expands cybersecurity risks, making cybersecurity an increasingly important research area in Information Systems (IS). Among these risks, malware has become a pervasive and destructive threat. Byte-based machine learning (ML) methods are widely used for malware detection but remain vulnerable to evasive behaviors that manipulate raw bytes to evade detection. Graph-based methods are less affected by such manipulations because they represent software as program graphs that capture execution behavior. However, they do not explicitly identify cohesive groups of basic blocks that jointly realize meaningful program behaviors, nor do they learn sufficiently expressive program graph representations for accurate detection. To this end, we propose MalGuard, a graph-based malware detection method for organizational malware risk management. MalGuard introduces two methodological innovations: an operational role identification approach and a program graph representation learning method. The former identifies these cohesive groups of basic blocks as operational roles, enabling the detector to capture program behaviors that may not be visible from isolated basic blocks. The latter learns expressive program graph representations by modeling interactions among operational roles, preserving sparse malicious signals, and capturing hierarchical graph structure. Extensive experiments show that MalGuard improves detection performance and reduces the expected cost of undetected malware.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑