This paper proposes a method based on parameter optimization meta-learning and hard example mining to deal with the problem of low classification accuracy in malware classification due to the few samples of the emerging malwares. Firstly, each malware is decompiled into binary files and then transformed into gray-scale images. Secondly, we use a parameter optimization-based meta-learning method to train the shallow neural network, and obtain its initialization parameters. Based on these parameters, the new model can be easily fine-tuned and applied to new tasks. At the same time, combined with the method of hard sample mining, the model is organized purposefully to improve the convergence speed and classification accuracy. Finally, comparison experiments with the existing deep learning methods are done on the Malimg and BIG-2015 datasets. Experimental results show that the classification accuracy is 0.996 7 and 0.993 3 on Malimg and Big-2015, respectively, which outperforms the existing methods.
JIT T, FANGB X, CUIX, et al. Research on deep learning-powered malware attack and defense techniques[J]. Chinese Journal of Computers, 2021, 44(4):669-695. DOI:10.11897/SP.J.1016.2021.00669(Ch ).
[4]
JUNGB H, BAE S I, CHOIC, et al. Packer identification method based on byte sequences [J]. Concurrency and Computation: Practice and Experience, 2020, 32(8):e5082. DOI: 10.1002/cpe.5082 .
[5]
CHOIS Y, LIM C G, KIMY M. Automated link tracing for classification of malicious websites in malware distribution networks [J]. Journal of Information Processing Systems, 2019, 15(1):100-115. DOI:10.3745/JIPS.03.0107 .
[6]
SANTOSI, BREZOF, UGARTE-PEDREROX, et al. Opcode sequences as representation of executables for data-mining-based unknown malware detection[J]. Information Sciences, 2013, 231(5): 64-82. DOI:10.1016/j.ins.2011.08.020 .
[7]
YUANZ L, LUY Q, XUEY B. Droiddetector: Android malware characterization and detection using deep learning [J]. Tsinghua Science and Technology, 2016, 21(1): 114-123. DOI:10.1109/TST.2016.7399288 .
[8]
CABAUG, BUHUM, OPRISAC P. Malware classification based on dynamic behavior [C]// 2016 18th International Symposium on Symbolic and Numeric Algorithms for Scientific Computing(SYNASC). New York:IEEE Press,2016:315-318. DOI:10.1109/SYNASC.2016.057 .
[9]
DAMODARANA, TROIAF D, VISAGGIOC A, et al. A comparison of static, dynamic, and hybrid analysis for malware detection [J]. Journal of Computer Virology and Hacking Techniques, 2017, 13(1): 1-12. DOI:10.1007/s11416-015-0261-z .
[10]
NATARAJL, KARTHIKEYANS, JACOBG, et al. Malware images: Visualization and automatic classification [C]// Proceedings of the 8th International Symposium on Visualization for Cyber Security. New York:ACM Press, 2011:1-7. DOI:10.1145/2016904.2016908 .
[11]
AZABA, LAYTONR, ALAZABM,et al. Mining malware to detect variants [C]// 2014 5th Cybercrime and Trustworthy Computing Conference. New York:IEEE Press, 2014: 44-53. DOI: 10.1109/CTC.2014.11 .
[12]
LIW J, GEJ G, DAIG Q. Detecting malware for Android platform: An SVM-based approach [C]// 2015 IEEE 2nd International Conference on Cyber Security and Cloud Computing. New York:IEEE Press, 2015: 464-469. DOI:10.1109/CSCloud.2015.50 .
[13]
GIBERTD, MATEUC, PLANESJ, et al. Using convolutional neural networks for classification of malware represented as images [J]. Journal of Computer Virology and Hacking Techniques, 2019, 15(1):15-28. DOI:10.1007/s11416-018-0323-0 .
CHENX H, WEIS N, QINZ Z. Malware family classification based on deep learning visualization[J]. Computer Engineering and Applications, 2021, 57(22): 131-138. DOI:10.3778/j.issn.1002-8331.2007-0291(Ch ).
ZHENGR, WANGQ Y, FUJ M, et al. A novel malware classification model based on deep learning [J]. Journal of Cyber Security, 2020, 5(1):1-9. DOI: 10.19363/J.cnki.cn10-1380/tn.2020.01.01 (Ch ).
[20]
MAKANDARA, PATROTA. Malware class recognition using image processing techniques [C]// 2017 International Conference on Data Management, Analytics and Innovation (ICDMAI). New York:IEEE Press, 2017:76-80. DOI:10.1109/ICDMAI.2017.8073489 .
[21]
NARAYANANB N, DJANEYE-BOUNDJOUO, KEBEDET M. Performance analysis of machine learning and pattern recognition algorithms for malware classification [C]// 2016 IEEE National Aerospace and Electronics Conference (NAECON) and Ohio Innovation Summit (OIS). New York:IEEE Press.2016:338-342. DOI:10.1109/NAECON.2016.7856826 .
[22]
KALASHM, ROCHANM, MOHAMMEDN, et al. Malware classification with deep convolutional neural networks [C]// 2018 9th IFIP International Conference on New Technologies, Mobility and Security (NTMS). New York:IEEE Press,2018:1-5. DOI:10.1109/NTMS.2018.8328749 .
[23]
RONENR, RADUM, FEUERSTEINC, et al. Microsoft Malware Classification Challenge [DB/OL]. [2021-06-05].
[24]
TOBIYAMAS, YAMAGUCHIY, SHIMADAH, et al. Malware detection with deep neural network using process behavior [C]// 2016 IEEE 40th Annual Computer Software and Applications Conference(COMPSAC). New York:IEEE Press,2016:577-582. DOI: 10.1109/COMPSAC.2016.151 .
[25]
CUIZ H, XUEF, CAIX J, et al. Detection of malicious code variants based on deep learning[J]. IEEE Transactions on Industrial Informatics, 2018, 14(7): 3187-3196. DOI:10.1109/TII.2018.2822680 .
[26]
RAFIQUEM F, ALIM, QURESHIA S, et al. Malware Classification using Deep Learning based Feature Extraction and Wrapper based Feature Selection Technique[EB/OL]. [2021-06-05].
[27]
SHRIVASTAVAA, GUPTAA, GIRSHICKR. Training region-based object detectors with online hard example mining [C]// 2016 Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition. New York: IEEE Press, 2016:761-769. DOI: 10.1109/cvpr.2016.89 .
[28]
FINNC, ABBEELP, LEVINES. Model-agnostic meta-learning for fast adaptation of deep networks [C]// International Conference on Machine Learning. New York:IEEE Press, 2017:1126-1135. DOI: 10.1109/icra.2017.7989383 .
[29]
MITSUHASHIR, SHINAGAWAT. High-Accuracy Malware Classification with a Malware-Optimized Deep Learning Model [DB/OL]. [2021-06-05].