构建融合拓扑特征的函数调用图数据集,提升恶意软件检测效率。
AMD-FCG: An Enhanced Function Call Graph Dataset with Integrated Topological Features for Malware Detection and Classification

- 构建含拓扑特征的增强型函数调用图数据集
- 支持多类恶意软件检测,无需动态分析
- 适合安全研究人员与检测系统开发者
由于恶意软件具有复杂的结构和行为,其检测在网络安全领域构成重大挑战。现有方法中,分析恶意软件的结构与行为模式是最可靠手段之一,可通过函数调用图(FCG)获取。为有效覆盖各类恶意软件家族,需具备足够规模的数据集,并包含良性应用以保障检测过程的安全性。本文提出AMD-FCG,一个集成拓扑特征的增强型函数调用图数据集,提升了检测流程的准确性与鲁棒性,简化了工作流,避免了动态分析和复杂处理,可直接用于开发更高效、创新的恶意软件检测系统。
原文摘要 · Abstract (English)
As malware illustrates a complex structure and behavior, detection of these has been a significant challenge in the domain of cybersecurity along with related services in daily life. So, it becomes crucial to have a reliable and adaptive solution to address the issue. Among the several detection methods developed over the years, one of the most reliable ones is studying and analyzing the structural and behavioral patterns of malware. These patterns of sophisticated malware can be obtained with the help of Function Call Graphs (FCGs). However, to effectively cover numerous groups of families of malware, it is required to have a sufficiently large dataset for the system to operate on. In order to ensure accuracy and robustness of the system, the dataset should comprise samples of different malwares and a benign application for secure execution of the detection process. This paper introduces AMD-FCG, an enhanced Function Call Graph dataset integrated with topological features of malwares. The framework enhances the detection procedure, streamlining the workflow for cybersecurity professionals and also eliminating the need for dynamic analysis and extensive processing. Therefore, it can be used to develop and deploy more efficient and innovative malware detection systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。