An End-to-End Raw Bytes Based Malware Classifier via Self-Attention Residual Convolutional Network

Zihan Hou, Xiaoyong Li, Linghui Li, Jie Yuan, Kaiyang Deng · 2022

Malware classification has always been a fundamental and cutting-edge problem in the field of cyber security. The rapidly evolution of malware variant makes the malware recognition challenging. Most of existing methods are based on symbolic execution, fingerprints, behavior sequences, manually designed feature, etc., which increase the workload of security experts and slow down the security response speed. In this paper, we propose an end-to-end raw byte based method for malware classification. Our proposed model mainly consists of a convolutional module, self-attention residual module and MLP based classifier. The convolutional module is directly used to process the byte stream to extract the high-level feature of the malware. The self-attention residual module is designed to capture the relevant information scattered in different blocks of the malware. The MLP based classifier is to calculate the category probability of the malware. We conduct extensive experiments on the well-known BODMAS dataset which contains 300GB of malwares. Our proposed method achieves 90.0% macro-F1 and is proved to be rational and effective for malware classification.

Read the paper · More papers on PaperTik