检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:蒋周杰 陈意 熊子漫[3] 郭春 申国伟[1,2] JIANG Zhoujie;CHEN Yi;XIONG Ziman;GUO Chun;SHEN Guowei(State Key Laboratory of Public Big Data,School of Computer Science and Technology,Guizhou University,Gui-yang 550025,China;Engineering Research Center of Text Computing&Cognitive Intelligence of Ministry of Education,Guiyang 550025,China;School of Continuing Education,Guizhou University,Guiyang 550025,China)
机构地区:[1]贵州大学计算机科学与技术学院公共大数据重点实验室,贵阳550025 [2]文本计算与认知智能教育部工程研究中心,贵阳550025 [3]贵州大学继续教育学院,贵阳550025
出 处:《计算机科学与探索》2024年第2期526-537,共12页Journal of Frontiers of Computer Science and Technology
基 金:国家自然科学基金(62162009);贵州省科技支撑计划(黔科合支撑[2022]一般071)。
摘 要:基于灰度图像和深度学习的恶意软件检测方法具有无需特征工程和检测精度高的特点,通过对抗样本能够欺骗该类检测方法。然而当前大部分研究所生成的对抗样本难以在不破坏原文件功能完整性的情况下大幅度降低该类检测方法对其的判别准确性。在分析可移植可执行(PE)文件的结构以及加载机制的基础上,提出一种不破坏PE文件原有功能且可添加量不受限的字节码攻击方法(BAUAA)。BAUAA通过在PE文件中分散于各区段之后且不会载入内存的“区段附加空间”添加字节码来生成对抗样本,并且由于该空间具有可添加量不受限的特点,可使得生成的对抗样本所转化的灰度图像在尺寸和纹理上发生变化,从而能够影响基于灰度图像和深度学习的恶意软件检测方法对其的判别准确性。实验结果表明,基于灰度图像和深度学习的恶意软件检测方法判别BAUAA所生成对抗样本的准确率明显低于其判别非对抗样本的准确率。为避免在现实中滥用BAUAA,提出一种针对性的对抗样本检测方法。Malware detection methods based on gray images and deep learning have the characteristics of high de-tection accuracy and no need of feature engineering.Unfortunately,adversarial examples(AEs)can deceive such de-tection methods.However,it is difficult to reduce the detection accuracy of this kind of detection method greatly without destroying the functional integrity of the original file.By analyzing the structure and loading mechanism of portable executable(PE)files,this paper proposes an unrestricted add-amount bytecode attack(BAUAA).BAUAA generates adversarial samples by adding bytecode to a“section additional space”in the PE file that is scattered after each section and is not loaded into memory,and because of the unlimited amount of this space that can be added,the generated adversarial samples can be transformed into grayscale images that vary in size and texture,which can affect the discrimination accuracy of gray images and deep learning-based malware detection methods.The experimental results show that the detection accuracy of the malware detection method based on gray images and deep learning for the AEs generated by BAUAA is significantly lower than that for the non-AEs.To avoid the abuse of BAUAA in reality,it proposes a targeted AE detection method.
关 键 词:对抗样本 恶意软件检测 灰度图像 可移植可执行(PE)文件
分 类 号:TP309.5[自动化与计算机技术—计算机系统结构]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.3