CN116340944B - Malicious code classification method and system based on RGB image and lightweight model - Google Patents
Malicious code classification method and system based on RGB image and lightweight model Download PDFInfo
- Publication number
- CN116340944B CN116340944B CN202310608993.XA CN202310608993A CN116340944B CN 116340944 B CN116340944 B CN 116340944B CN 202310608993 A CN202310608993 A CN 202310608993A CN 116340944 B CN116340944 B CN 116340944B
- Authority
- CN
- China
- Prior art keywords
- operation code
- image
- file
- markov
- byte
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000000034 method Methods 0.000 title claims abstract description 20
- 239000011159 matrix material Substances 0.000 claims description 31
- 230000007704 transition Effects 0.000 claims description 16
- 238000012549 training Methods 0.000 claims description 12
- 230000004927 fusion Effects 0.000 claims description 9
- 238000000605 extraction Methods 0.000 claims description 6
- 238000012546 transfer Methods 0.000 claims description 5
- 230000000295 complement effect Effects 0.000 claims description 4
- 230000006872 improvement Effects 0.000 claims description 3
- 238000013145 classification model Methods 0.000 claims 2
- 239000000284 extract Substances 0.000 abstract description 4
- 238000001514 detection method Methods 0.000 description 11
- 230000000694 effects Effects 0.000 description 7
- 230000006870 function Effects 0.000 description 6
- 230000008569 process Effects 0.000 description 5
- 230000004913 activation Effects 0.000 description 4
- 238000013528 artificial neural network Methods 0.000 description 4
- 238000010586 diagram Methods 0.000 description 4
- 238000013135 deep learning Methods 0.000 description 3
- 238000005516 engineering process Methods 0.000 description 3
- 230000003068 static effect Effects 0.000 description 3
- 238000012360 testing method Methods 0.000 description 3
- 108010003272 Hyaluronate lyase Proteins 0.000 description 2
- 238000003491 array Methods 0.000 description 2
- 230000008901 benefit Effects 0.000 description 2
- 238000004364 calculation method Methods 0.000 description 2
- 210000002569 neuron Anatomy 0.000 description 2
- 238000011176 pooling Methods 0.000 description 2
- 238000012935 Averaging Methods 0.000 description 1
- 230000009286 beneficial effect Effects 0.000 description 1
- 230000008859 change Effects 0.000 description 1
- 238000006243 chemical reaction Methods 0.000 description 1
- 230000007547 defect Effects 0.000 description 1
- 230000001627 detrimental effect Effects 0.000 description 1
- 238000002474 experimental method Methods 0.000 description 1
- 230000007774 longterm Effects 0.000 description 1
- 239000000463 material Substances 0.000 description 1
- 230000007246 mechanism Effects 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 238000003062 neural network model Methods 0.000 description 1
- 238000012545 processing Methods 0.000 description 1
- 238000011160 research Methods 0.000 description 1
- 230000000007 visual effect Effects 0.000 description 1
- 238000012800 visualization Methods 0.000 description 1
- 238000007794 visualization technique Methods 0.000 description 1
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/562—Static detection
- G06F21/563—Static detection by source code analysis
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/561—Virus type analysis
-
- Y—GENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
- Y02—TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
- Y02D—CLIMATE CHANGE MITIGATION TECHNOLOGIES IN INFORMATION AND COMMUNICATION TECHNOLOGIES [ICT], I.E. INFORMATION AND COMMUNICATION TECHNOLOGIES AIMING AT THE REDUCTION OF THEIR OWN ENERGY USE
- Y02D10/00—Energy efficient computing, e.g. low power processors, power management or thermal management
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Health & Medical Sciences (AREA)
- Virology (AREA)
- General Health & Medical Sciences (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Image Analysis (AREA)
Abstract
Description
Claims (5)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202310608993.XA CN116340944B (en) | 2023-05-29 | 2023-05-29 | Malicious code classification method and system based on RGB image and lightweight model |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN202310608993.XA CN116340944B (en) | 2023-05-29 | 2023-05-29 | Malicious code classification method and system based on RGB image and lightweight model |
Publications (2)
Publication Number | Publication Date |
---|---|
CN116340944A CN116340944A (en) | 2023-06-27 |
CN116340944B true CN116340944B (en) | 2023-08-18 |
Family
ID=86889812
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN202310608993.XA Active CN116340944B (en) | 2023-05-29 | 2023-05-29 | Malicious code classification method and system based on RGB image and lightweight model |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN116340944B (en) |
Families Citing this family (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN116861431B (en) * | 2023-09-05 | 2023-11-21 | 国网山东省电力公司信息通信公司 | Malicious software classification method and system based on multichannel image and neural network |
CN117034274A (en) * | 2023-10-08 | 2023-11-10 | 广东技术师范大学 | Malicious software classification method, device, equipment and medium based on feature fusion |
CN117972701B (en) * | 2024-04-01 | 2024-06-07 | 山东省计算中心(国家超级计算济南中心) | Anti-confusion malicious code classification method and system based on multi-feature fusion |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN113468531A (en) * | 2021-07-15 | 2021-10-01 | 杭州电子科技大学 | Malicious code classification method based on deep residual error network and mixed attention mechanism |
CN113806746A (en) * | 2021-09-24 | 2021-12-17 | 沈阳理工大学 | Malicious code detection method based on improved CNN network |
CN115630358A (en) * | 2022-07-20 | 2023-01-20 | 哈尔滨工业大学(深圳) | Malicious software classification method and device, computer equipment and storage medium |
Family Cites Families (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US11461468B2 (en) * | 2019-11-06 | 2022-10-04 | Mcafee, Llc | Visual identification of malware |
US11790085B2 (en) * | 2020-10-29 | 2023-10-17 | Electronics And Telecommunications Research Institute | Apparatus for detecting unknown malware using variable opcode sequence and method using the same |
-
2023
- 2023-05-29 CN CN202310608993.XA patent/CN116340944B/en active Active
Patent Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN113468531A (en) * | 2021-07-15 | 2021-10-01 | 杭州电子科技大学 | Malicious code classification method based on deep residual error network and mixed attention mechanism |
CN113806746A (en) * | 2021-09-24 | 2021-12-17 | 沈阳理工大学 | Malicious code detection method based on improved CNN network |
CN115630358A (en) * | 2022-07-20 | 2023-01-20 | 哈尔滨工业大学(深圳) | Malicious software classification method and device, computer equipment and storage medium |
Non-Patent Citations (1)
Title |
---|
A PE header-based method for malware detection using clustering and deep embedding techniques;Tina Rezaei等;《Journal of Information Security and Applications》;第60卷;1-12 * |
Also Published As
Publication number | Publication date |
---|---|
CN116340944A (en) | 2023-06-27 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN116340944B (en) | Malicious code classification method and system based on RGB image and lightweight model | |
EP3451165B1 (en) | Neural network operation device and method supporting few-bit floating-point number | |
CN108985317B (en) | Image classification method based on separable convolution and attention mechanism | |
CN109086722B (en) | Hybrid license plate recognition method and device and electronic equipment | |
CN109344618B (en) | Malicious code classification method based on deep forest | |
CN113806746B (en) | Malicious code detection method based on improved CNN (CNN) network | |
CN115937655B (en) | Multi-order feature interaction target detection model, construction method, device and application thereof | |
CN111027576B (en) | Cooperative significance detection method based on cooperative significance generation type countermeasure network | |
CN108304573A (en) | Target retrieval method based on convolutional neural networks and supervision core Hash | |
EP4237977B1 (en) | Method for detection of malware | |
CN111461129B (en) | Context prior-based scene segmentation method and system | |
CN111259397A (en) | Malware classification method based on Markov graph and deep learning | |
Maryum et al. | Cassava leaf disease classification using deep neural networks | |
Shen et al. | Feature fusion-based malicious code detection with dual attention mechanism and BiLSTM | |
CN111400713B (en) | Malicious software population classification method based on operation code adjacency graph characteristics | |
CN111241550B (en) | Vulnerability detection method based on binary mapping and deep learning | |
Zhu et al. | Malware homology determination using visualized images and feature fusion | |
CN115828248B (en) | Malicious code detection method and device based on interpretive deep learning | |
CN116258917B (en) | Method and device for classifying malicious software based on TF-IDF transfer entropy | |
CN116595525A (en) | Threshold mechanism malicious software detection method and system based on software map | |
CN116975864A (en) | Malicious code detection method and device, electronic equipment and storage medium | |
CN114861178B (en) | Malicious code detection engine design method based on improved B2M algorithm | |
Cho | Dynamic RNN-CNN based malware classifier for deep learning algorithm | |
CN111079143B (en) | Trojan horse detection method based on multi-dimensional feature map | |
CN114358058A (en) | Wireless communication signal open set identification method and system based on deep neural network |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
CB03 | Change of inventor or designer information | ||
CB03 | Change of inventor or designer information |
Inventor after: Zhao Dawei Inventor after: Sun Chenyu Inventor after: Yang Shumian Inventor after: Xu Lijuan Inventor after: Li Xin Inventor after: Zhang Yuxin Inventor after: Xu Qingling Inventor before: Zhao Dawei Inventor before: Sun Chenyu Inventor before: Yang Shumian Inventor before: Xu Lijuan Inventor before: Li Xin Inventor before: Zhang Yuxin Inventor before: Xu Qingling |
|
EE01 | Entry into force of recordation of patent licensing contract | ||
EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20230627 Assignee: Shandong Geek Security Technology Co.,Ltd. Assignor: SHANDONG COMPUTER SCIENCE CENTER(NATIONAL SUPERCOMPUTER CENTER IN JINAN)|Qilu University of Technology (Shandong Academy of Sciences) Contract record no.: X2024980000068 Denomination of invention: A Malicious Code Classification Method and System Based on RGB Images and Lightweight Models Granted publication date: 20230818 License type: Common License Record date: 20240104 |