用生物演化方法自动追踪恶意软件家族进化,发现不同家族突变速度差异巨大。
MalTree: Tracing Malware Evolution from Embeddings at Scale

- 借鉴生物系统发育算法,结合结构、行为和图像特征建模恶意软件演化
- 87%的演化关系与真实时间线一致,部分家族突变速度超其他家族10倍以上
- 适合安全研究者构建主动防御体系,可快速分析如Mirai等大规模威胁
恶意软件检测仍以被动应对为主:基于已知样本训练的机器学习模型在威胁演进时迅速失效。理解恶意软件家族间的演化关系有助于实现主动防御,但传统逆向工程需数月甚至数年才能揭示此类谱系。本文提出MalTree框架,采用受生物信息学启发的系统发育技术(UPGMA与邻接法),结合结构、行为及图像特征,在大规模上自动建模恶意软件演化。引入VirusTotal时间戳进行时间验证,评估推断树是否反映实际演化顺序。结果表明,MalTree达到87%的时间一致性,说明推断的演化关系与现实出现时间高度吻合。分析显示,某些家族突变速率比其他家族快逾10倍,提示检测策略应按家族特性定制。案例研究包括Mirai僵尸网络,其推断关系与已知情报完全一致。本框架为从逐样本分类转向基于谱系的演化建模提供了基础。
原文摘要 · Abstract (English)
Malware detection remains largely reactive: machine learning models trained on known samples degrade as threats evolve. Understanding evolutionary relationships among malware families can inform proactive defense, but traditional reverse engineering can take months to years to uncover such lineage relationships. We propose MalTree, a framework that applies bioinformatics inspired phylogenetic techniques (UPGMA and Neighbor-Joining) at scale to model malware evolution automatically using structural, behavioral, and image-based features. We introduce temporal validation using VirusTotal timestamps to assess whether inferred trees reflect actual evolutionary order. MalTree achieves 87% temporal consistency, indicating that inferred evolutionary relationships closely align with real-world emergence timelines. Our analysis shows that some families mutate over 10 times faster than others, suggesting that detection strategies should be tailored to family-specific evolutionary tempos. Case studies, including the Mirai botnet, confirm that inferred relationships from our phylogenetic tree align with documented threat intelligence. Our framework provides a foundation for shifting malware analysis from sample-by-sample classification toward lineage-aware evolutionary modeling.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。