A Model Based on GCN and TCN for Malicious Code Detection in Power Information System

Qionglan Na, Shijun Zhang, Xin Li, Ji Lai, Yixi Yang, Jing Zeng · 2024

In recent years, as more and more Android mobile devices are connected to the power grid information system, accurate malicious code detection is very important to protect the information security of power grid. Existing methods for detecting Android malware primarily focus on learning features from a single structural type, neglecting the analysis of application semantics. This paper addresses the limitations of traditional detection methods, which fail to comprehensively capture feature semantics. To overcome this challenge, we propose an innovative Android malware detection model that combines Graph Convolutional Networks (GCN) and Temporal Convolutional Networks (TCN). Our model not only accurately extracts structural information from samples but also emphasizes the semantic analysis of malicious behavior. In our approach, we first characterize the topological relationships between multiple types of key system calls using a graph representation. The high-level structural information of nodes in the system call graph is then aggregated using a diffusion graph convolutional network, significantly improving the efficiency of feature learning. Next, we leverage a TCN network to capture the contextual semantics of opcode sequences. By assigning high weights to sequences with malicious features, we identify strong correlations within the features. Finally, we employ a decoder with Softmax function to output the prediction classification probability by fusing the structure information and context features. To validate the effectiveness of our model, we conduct experiments on real datasets. These experiment results demonstrate the model's validity to accurately detect and classify Android malware.

Read the paper · More papers on PaperTik