Traditional signature-based malicious code detection methods often need better resistance to obfuscation and variability. In this paper, we propose an improved deep learning detection method with R-FCN and migration learning based on malicious family code visualization of typical texture features by constructing a shareable fully convolutional network independent of ROIs and an unshared ROI-wise word sub-network, which improves the detection location sensitivity problem caused by texture image translation due to the invariance-induced degradation of detection location sensitivity while accelerating model convergence. Aiming at the problem of uneven distribution of malicious texture and background regions during code visualization and the decrease of detection rate due to the negative samples of malicious code texture after obfuscation and mutation, the model introduces the complex negative samples mining algorithm OHEM and non-maximum suppression algorithm NMS, which, by calculating the IoU cross ratio between the malicious texture and the background texture, eliminating the similar edges of the malicious texture, and re-training the complex negative samples, can effectively improve the classification and localization detection accuracy. Experimental results show that the improved method proposed in this paper outperforms other malicious code visual texture detection methods regarding classification accuracy, border regression detection rate, and mAP.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Detection Method for Visual Texture of Malware Based on Improved R-FCN and Transfer Learning

  • Jian Chen,
  • Zhibin Yang,
  • Lei Wang,
  • Jun Jiang,
  • Ruitong Liu,
  • Heng Ji,
  • Yuntao Zhao,
  • Yuerong Li

摘要

Traditional signature-based malicious code detection methods often need better resistance to obfuscation and variability. In this paper, we propose an improved deep learning detection method with R-FCN and migration learning based on malicious family code visualization of typical texture features by constructing a shareable fully convolutional network independent of ROIs and an unshared ROI-wise word sub-network, which improves the detection location sensitivity problem caused by texture image translation due to the invariance-induced degradation of detection location sensitivity while accelerating model convergence. Aiming at the problem of uneven distribution of malicious texture and background regions during code visualization and the decrease of detection rate due to the negative samples of malicious code texture after obfuscation and mutation, the model introduces the complex negative samples mining algorithm OHEM and non-maximum suppression algorithm NMS, which, by calculating the IoU cross ratio between the malicious texture and the background texture, eliminating the similar edges of the malicious texture, and re-training the complex negative samples, can effectively improve the classification and localization detection accuracy. Experimental results show that the improved method proposed in this paper outperforms other malicious code visual texture detection methods regarding classification accuracy, border regression detection rate, and mAP.