Malware Behavior Detection System with RAG-Enhanced eBPF and Advanced Language Model
Sihang Yu, Zhaoxiang Li, Jinshan Chen, Xuhui Deng, Chen Hou · 2024
The article focuses on the malware threat within network security, especially the challenge of behavior detection on Linux systems. Traditional methods have limitations since static analysis is affected by various factors and dynamic analysis can be bypassed. To overcome these challenges, we propose an integrated approach using eBPF and language models. Its primary contributions are implementing malware behavior monitoring with eBPF for high-precision data collection, introducing a few-shot prompt-based log parsing and data structuring method to optimize inference, achieving integrated detection of malicious behavior using eBPF and LLMs to streamline log processing, and proposing an anomaly detection scheme with RAG-enhanced knowledge integration to improve the recognition of unknown behaviors and reduce training costs. Experiments involved identifying mining malware samples and behavior data from Virus Total and MalwareBazaar and executing them in a simulated Linux environment to analyze behavior. The results show that the accuracy reached 98.56%, and the introduction of RAG increased the recognition accuracy for unknown behavior logs by 15%.