arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.19900cs.CRcs.LG

Delphi Scanner:通过API序列建模实现高效且可解释的静态恶意软件检测

Delphi Scanner: efficient and interpretable static malware detection via API sequence modeling

  • Université Paris Cité(巴黎西岱大学)
  • Institut Polytechnique de Paris(巴黎理工学院)
  • Télécom Paris(巴黎电信学院)

机构由 AI 辅助整理,请以论文原文为准。

Bijied Brahimi, Vincent Cohadon, Gabriel Glazman, Rayan Al Mohaize, Omran Berjawi, Rida Khatoun

AI总结:

Delphi Scanner利用CNN建模API序列并辅以规则层解释,在19万PE文件上达95.35%准确率,模型仅1.53MB,且对分布外样本和对抗攻击具有鲁棒性,为本地恶意软件分流提供高效可解释方案。

AI中文摘要:

针对Windows可移植可执行文件的静态恶意软件检测需要在检测有效性、计算效率和可分析解释性之间取得谨慎平衡。本文介绍了Delphi Scanner,一个针对Windows PE文件的静态恶意软件检测系统,它在效率与行为解释之间取得平衡。该系统使用卷积神经网络(CNN)对Windows API序列进行建模以对PE文件进行分类,并采用基于规则层的解耦解释层,将API归类为高级恶意能力。在超过190,000个Windows PE文件上的评估中,系统达到了95.35%的准确率,模型大小仅为1.53 MB。在5,647个分布外MalwareBazaar样本、配对的加壳与未加壳可执行文件以及三种对抗性操纵策略上的鲁棒性实验,确认了系统在训练分布之外的泛化能力以及对功能保持型逃避技术的抵抗力。总体而言,这些结果表明,基于API序列的静态分析为本地部署场景中的恶意软件分流提供了一个实用、可解释且高效的基础。

英文摘要:

Static malware detection for Windows Portable Executable files demands a careful balance between detection effectiveness, computational efficiency, and analytical interpretability. This paper introduces Delphi Scanner, a static malware detection system for Windows PE files that balances efficiency with behavioral interpretation. It uses a convolutional neural network (CNN) to model Windows API sequences to classify PE and a decoupled interpretation layer based on a rule-based layer to categorize APIs into high-level malicious capabilities. Evaluated on over 190,000 Windows PE files, the system achieves 95.35% accuracy with a 1.53~MB model footprint. Robustness experiments on 5,647 out-of-distribution MalwareBazaar samples, paired packed and unpacked executables, and three adversarial manipulation strategies confirm generalization beyond the training distribution and resistance to functionality-preserving evasion techniques. Overall, these results demonstrate that API sequence-based static analysis offers a practical, interpretable, and efficient foundation for malware triage in local deployment scenarios.

↑