arXiv:2412.08514cs.CRcs.LG2024-12被引 5

用二维码和Aztec码转换恶意软件特征,提升深度学习识别效果

Image-Based Malware Classification Using QR and Aztec Codes

  • 将可执行文件特征转为二维码和Aztec码图像输入CNN
  • 在一组数据上超越现有方法,在另一组表现较差
  • 适合对新型特征工程感兴趣的恶意软件研究者

近年来,基于图像的恶意软件检测技术受到关注,多项研究证明卷积神经网络(CNN)在解析可执行文件生成的图像方面有效。本文提出一种创新方法:将可执行文件中提取的特征转化为QR码和Aztec码图像,利用其结构模式增强CNN的学习能力。我们设计并实现了针对这些码图像特性的专用CNN架构,并在两个包含大量良性样本的大型恶意软件数据集上进行综合分析。实验结果显示,部分数据集上基于二维码和Aztec码训练的CNN性能优于当前最优方法,但在另一数据集上则不如传统技术。这表明将二维码与Aztec码作为特征工程手段在恶意软件领域具有巨大潜力,但仍需进一步研究以明确其优势与局限性。

原文摘要 · Abstract (English)

In recent years, the use of image-based techniques for malware detection has gained prominence, with numerous studies demonstrating the efficacy of deep learning approaches such as Convolutional Neural Networks (CNN) in classifying images derived from executable files. In this paper, we consider an innovative method that relies on an image conversion process that consists of transforming features extracted from executable files into QR and Aztec codes. These codes capture structural patterns in a format that may enhance the learning capabilities of CNNs. We design and implement CNN architectures tailored to the unique properties of these codes and apply them to a comprehensive analysis involving two extensive malware datasets, both of which include a significant corpus of benign samples. Our results yield a split decision, with CNNs trained on QR and Aztec codes outperforming the state of the art on one of the datasets, but underperforming more typical techniques on the other dataset. These results indicate that the use of QR and Aztec codes as a form of feature engineering holds considerable promise in the malware domain, and that additional research is needed to better understand the relative strengths and weaknesses of such an approach.

恶意软件图像分类特征工程CNN

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。