自动为恶意脚本生成高质量中文描述,提升威胁研究效率。
AutoMalDesc: Large-Scale Script Analysis for Cyber Threat Research
- 基于自优化学习框架,逐步提升摘要质量。
- 在3600个样本上实现总结与分类双提升。
- 适合安全研究员和自动化威胁分析系统使用。
尽管自动化恶意软件检测系统已取得显著进展,但为威胁检测生成全面的自然语言解释仍是开放难题。本文提出AutoMalDesc,一种自动化静态分析摘要框架,初始训练后可独立大规模运行。该方法采用迭代式自适应学习流程,通过合成数据生成与验证循环持续提升输出质量,无需大量人工标注。在五种脚本语言共3600个多样化样本上的评估显示,各轮次间均有统计显著提升,总结质量与分类准确率同步增长。综合定量指标(基于既定恶意软件标签)与定性评估(人类专家及大模型判断),验证了生成摘要的技术精确性与语言连贯性。为促进复现与领域推进,我们发布超过10万份脚本样本数据集,包含0.9千份标注种子集与3.6千份测试集,以及完整方法与评估框架。
原文摘要 · Abstract (English)
Generating thorough natural language explanations for threat detections remains an open problem in cybersecurity research, despite significant advances in automated malware detection systems. In this work, we present AutoMalDesc, an automated static analysis summarization framework that, following initial training on a small set of expert-curated examples, operates independently at scale. This approach leverages an iterative self-paced learning pipeline to progressively enhance output quality through synthetic data generation and validation cycles, eliminating the need for extensive manual data annotation. Evaluation across 3,600 diverse samples in five scripting languages demonstrates statistically significant improvements between iterations, showing consistent gains in both summary quality and classification accuracy. Our comprehensive validation approach combines quantitative metrics based on established malware labels with qualitative assessment from both human experts and LLM-based judges, confirming both technical precision and linguistic coherence of generated summaries. To facilitate reproducibility and advance research in this domain, we publish our complete dataset of more than 100K script samples, including annotated seed (0.9K) and test (3.6K) datasets, along with our methodology and evaluation framework.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。