Dynamic Malicious Code Detection Based on Improved Graph Embedding Model

Mingdi Xu, Yu Wang, Feng Cui, Chaoyang Jin, Hui Tong · 2022 4th International Conference on Natural Language Processing (ICNLP) · 2022

With the continuous development of science and technology, the generation of malicious code is becoming much easier than ever before, and various variants emerge in endlessly, which makes the detection of malicious code increasingly difficult and causes irreversible losses to users’ systems, information, and assets. Aiming at this problem, this paper proposes an intelligent malicious code detection method based on an improved graph embedding model. The method uses heterogeneous information network to describe the malicious code dynamic features API, DLL, FILE, uses meta-graph and CBOW-based improved graph embedding model in the embedding processing part of the network, and finally multiple meta-graph features are comprehensively classified by SVM classification network and policy voting method, and the classification results are obtained. The experiment uses data sets collected from various channels for training and verification, and the classification accuracy rate reaches 97.0%, and the false positive rate is only 0.3%. Compared with other methods’ performance analysis, this method has better accuracy and precision in malicious code detection, and is better than other existing methods.

Read the paper · More papers on PaperTik