通过多模态执行路径分析,精准识别变种勒索软件。
Intelligent Code Embedding Framework for High-Precision Ransomware Detection via Multimodal Execution Path Analysis
- 融合高维嵌入与动态启发式,分析程序执行路径
- 在不同加密速度下仍保持高精度与低误报率
- 适合资源受限环境,可扩展应对新型威胁
面对日益复杂的攻击手法,传统检测方法面临挑战。本文提出一种基于多模态执行路径分析的智能代码嵌入框架,结合高维嵌入与动态启发式机制,捕捉多种勒索软件变种的行为模式。实验表明,在不同加密速度和混淆执行流条件下,该框架显著优于基线方法,提升了精确率、召回率与准确率。系统具备可扩展性与计算高效性,适用于从资源受限到高性能基础设施的各类场景。同时,显著降低误报率并优化检测延迟,即使对采用复杂加密机制的勒索软件家族亦有良好表现。模块化设计支持新增模态,增强未来适应性。量化分析显示系统具有优异能效,适合部署于严苛运营约束环境。结果证明,先进计算技术与动态自适应能力对防御复杂威胁至关重要。
原文摘要 · Abstract (English)
Modern threat landscapes continue to evolve with increasing sophistication, challenging traditional detection methodologies and necessitating innovative solutions capable of addressing complex adversarial tactics. A novel framework was developed to identify ransomware activity through multimodal execution path analysis, integrating high-dimensional embeddings and dynamic heuristic derivation mechanisms to capture behavioral patterns across diverse attack variants. The approach demonstrated high adaptability, effectively mitigating obfuscation strategies and polymorphic characteristics often employed by ransomware families to evade detection. Comprehensive experimental evaluations revealed significant advancements in precision, recall, and accuracy metrics compared to baseline techniques, particularly under conditions of variable encryption speeds and obfuscated execution flows. The framework achieved scalable and computationally efficient performance, ensuring robust applicability across a range of system configurations, from resource-constrained environments to high-performance infrastructures. Notable findings included reduced false positive rates and enhanced detection latency, even for ransomware families employing sophisticated encryption mechanisms. The modular design allowed seamless integration of additional modalities, enabling extensibility and future-proofing against emerging threat vectors. Quantitative analyses further highlighted the system's energy efficiency, emphasizing its practicality for deployment in environments with stringent operational constraints. The results underline the importance of integrating advanced computational techniques and dynamic adaptability to safeguard digital ecosystems from increasingly complex threats.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。