Proof: Pre-Training Model of Malware Family Classification Based on Active Defense
Résumé fourni par la source
Malware acts as a critical component in network attack and defense mechanisms. As Malware threats become more complex and diverse, timely automatic malware classification is urgently needed. Take into account consistency and system resource consumption, malware classification should be compatible with other security devices to form a comprehensive defense system. In this study, we proposed a pre-training framework Proof based on malware behavior captured by honeypoints inside and outside the protected system, and the framework’s performance in the categorization of malware families is evaluated. To describe malware, a structure called Malware Behavior Instruction Set (MBIS) was designed by selecting a subset of all behaviors captured by honeypoints. Then, a self-supervised pre-training model MBI2vec is applied to learn the internal mode of malicious code to guide the downstream malicious code family classification model composed of Bi-LSTM and attention mechanism. Finally, the Proof framework evaluated 846 malware samples from five malware families that we captured in the real world, and the f1-score of the classification result was 0.9554.
Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.
Contrôle bibliographique ouvert
DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.
- Titre Crossref
- Proof: Pre-Training Model of Malware Family Classification Based on Active Defense
- Date Crossref
- 01/07/2025
- Éditeur
- Institute of Electrical and Electronics Engineers (IEEE)
- Type
- journal-article
Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude et ne compte pas comme une seconde source scientifique indépendante.
Institutions déclarées
Une affiliation ne permet pas de déduire la nationalité d’un auteur.