构建了含视觉与熵特征的多类恶意软件数据集,助力高效检测。
TUANDROMD-X: Advanced Entropy and Visual Analytics Dataset for Enhanced Malware Detection and Classification

- 基于静态分析提取样本的视觉与熵特征
- 涵盖多种恶意软件家族与良性程序,支持多分类研究
- 降低特征工程开销,适合安全研究员快速验证模型
恶意软件及其攻击日益普遍且复杂,攻击者不断采用新型技术以逃避传统和基于签名的防御机制。为应对这一挑战,亟需更先进的防御方案。机器学习方法在抵御恶意软件攻击方面表现出高效性,但其开发与测试依赖高质量数据集,包含多种恶意软件家族及良性程序样本。当前此类数据集的缺乏仍是恶意软件研究的主要瓶颈。本文提出TUANDROMD-X,一个包含每一样本视觉与熵特征的多类别恶意软件数据集,可有效区分恶意软件与良性程序。该数据集基于静态分析构建,避免了高成本的动态分析与复杂特征工程,显著降低使用门槛。TUANDROMD-X有助于研究人员和网络安全专家更快地设计与评估新型恶意软件检测系统。
原文摘要 · Abstract (English)
Malware and malware-based attacks are becoming more prevalent and complex. Attackers regularly come up with new techniques that have the ability to evade conventional and signature-based malware defense. In order to address such threats, there is an increasing demand for advanced and better defense solutions. Machine learning-based techniques are efficiently capable of defending against malware and malware-based attacks. Nevertheless, creating and efficiently testing such techniques demand high-quality datasets having samples of various malware families as well as goodware. The lack of such datasets continues to be a major bottleneck in malware research. In this paper, we introduce TUANDROMD-X, a multiclass malware dataset with visual and entropy-based features of each sample, distinctly identifying malware from goodware. The dataset is created based on static analysis, lowering the overhead that comes with high feature engineering and dynamic analysis. As a result, TUANDROMD-X facilitates researchers and cyber-security experts to design faster and better malware detection systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。