arXiv:2605.31199cs.CRcs.AI2026-05

为动态恶意软件分析设计轻量级语义框架,提升行为建模清晰度与计算效率。

MAECO-Lite: Modular Ontology for Dynamic Malware Analysis

论文配图:MAECO-Lite: Modular Ontology for Dynamic Malware Analysis
图 1 · 摘自论文原文
  • 基于统一基础本体论,拆分持久实体与运行事件,避免概念混淆。
  • 在描述逻辑学习任务中,新模型推理性能显著优于原标准。
  • 适合威胁情报、自动化分析系统开发者使用,尤其关注语义精准性。

以实用且语义精确的方式捕获动态恶意软件行为,仍是网络威胁情报中的重大挑战。尽管MAEC和STIX等标准提供了广泛使用的恶意软件属性与观测词汇表,但其数据结构复杂,常模糊关键本体区分。特别是将持久性恶意软件实体与执行期间生成的事件混同,违背了本体设计的基本原则。本文基于统一基础本体论(UFO)对核心MAEC与STIX构建进行本体学分析,揭示其在实体、倾向与运行事件上的本体错配,阻碍动态行为的连贯表示,并限制执行轨迹推理能力。基于此,我们提出MAECO-Lite,一种面向动态恶意软件分析的轻量级模块化本体。该本体以样本、进程、操作、系统实体及MITRE ATT&CK技术为核心,明确区分持久实体与运行事件。初步评估显示,采用描述逻辑概念学习算法时,简化后的本体显著提升学习性能,证明基于本体的建模能同时增强语义清晰性与计算可用性。

原文摘要 · Abstract (English)

Capturing dynamic malware behavior in a practical but still semantically precise manner remains a significant challenge in cyber threat intelligence. While standards such as MAEC and STIX provide widely adopted vocabularies for describing malware artifacts and observations, they represent data with considerable complexity in structures that often obscure important ontological distinctions. In particular, they tend to conflate enduring malware artifacts with the events generated during execution, thereby flattening distinctions that are central in foundational standards for ontology design. In this paper, we conduct a foundational ontological analysis of core MAEC and STIX constructs relevant to dynamic malware analysis relying on Unified Foundational Ontology (UFO) as a theoretical lens. Our analysis reveals some ontological mismatches arising from the conflation of artifacts, dispositions, and runtime events in MAEC and STIX that complicate coherent representation of dynamic malware behavior and, from a practical perspective, limit the ability to reason about execution traces. Based on these insights, we propose MAECO-Lite, a lightweight ontology designed to represent data and operationalize their processing for dynamic malware analysis. The ontology adopts a modular structure centered on samples, processes, actions, system artifacts, and MITRE ATT&CK Techniques, while maintaining a clear separation between enduring entities and runtime events. An initial evaluation using description logic concept learning algorithms shows that the simplified ontology significantly improves learning performance, demonstrating that ontologically grounded modelling can enhance both semantic clarity and computational usability.

恶意软件分析本体建模威胁情报轻量级

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。