Deep Learning-Based APT Malware and Variants Detection with Attribution Analysis

Binhui Tang, Peiyun Leng, Xuxiang Shen, Yuhang Wei · 2023

Malware has become one of the most severe security threats in cyber security, among which APT malware attacks are more threatening than advanced sustainable threat attacks. In this paper, we perform APT malware and variant detection based on deep learning and analyze the results by detecting and attribution. The variant detection of APT malware can inhibit the spread of malicious code, which is important for network security detection and defense. This paper proposes a detection and classification method for APT malware and its variants based on deep learning. Firstly, the feature representation method of APT malware based on RGB images is proposed to solve the gradient explosion and gradient disappearance of grayscale map feature extraction and generate images with rich texture information, which can mine deeper features of APT malware attacks. Secondly, this paper also improves the convolutional neural network model by combining the Self-Attention mechanism with the spatial pyramid pool SPP-net to solve the problem of image input of different sizes, as the accuracy is above 92.14%. Then, the experiment results prove the predictive analysis of the model to understand the organization to which the APT attack belongs and the way of its specific attack, providing the possibility of tracing the source. Finally, the visual analysis of APT threat characteristics is presented.

Read the paper · More papers on PaperTik