DeepMal:maliciousness-Preserving adversarial instruction learning against static malware detection

来源 :网络空间安全科学与技术(英文版) | 被引量 : 0次 | 上传用户:pangdunpiwen
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
Outside the explosive successful applications of deep learning(DL)in natural language processing,computer vision,and information retrieval,there have been numerous Deep Neural Networks(DNNs)based alternatives for common security-related scenarios with malware detection among more popular.Recently,adversarial learning has gained much focus.However,unlike computer vision applications,malware adversarial attack is expected to guarantee malwares\'original maliciousness semantics.This paper proposes a novel adversarial instruction learning technique,DeepMal,based on an adversarial instruction learning approach for static malware detection.So far as we know,DeepMal is the first practical and systematical adversarial learning method,which could directly produce adversarial samples and effectively bypass static malware detectors powered by DL and machine learning(ML)models while preserving attack functionality in the real world.Moreover,our method conducts small-scale attacks,which could evade typical malware variants analysis(e.g.,duplication check).We evaluate DeepMal on two real-world datasets,six typical DL models,and three typical ML models.Experimental results demonstrate that,on both datasets,DeepMal can attack typical malware detectors with the mean F1-score and F1-score decreasing maximal 93.94%and 82.86%respectively.Besides,three typical types of malware samples(Trojan horses,Backdoors,Ransomware)proveto preserve original attack functionality,and the mean duplication check ratio of malware adversarial samples is below 2.0%.Besides,DeepMal can evade dynamic detectors and be easily enhanced by learning more dynamic features with specific constraints.
其他文献
Reading text in images automatically has become an attractive research topic in computer vision.Specifically,end-to-end spotting of scene text has attracted significant research attention,and relatively ideal accuracy has been achieved on several datasets
前言rn2020年受市场不利因素影响,公司生产经营结果并不理想,偏离了预算轨道,距离年预算目标还有一定差距.为了应对新挑战,确保完成全年生产经营目标,做为公司采购主要支出品种进口矿,在降本增效方面显得格外重要.鉴于公司长期以来进口原料端使用品种较为单一,多为市场澳洲主流中低品矿资源,不利于近年来在铁矿石市场高位震荡时期采购降本.通过不断优化烧结配料结构、以性价比测算排序为采购原则,1-8月份在首钢公司板块内进口矿采购跑赢市场6.70美元/千t,1-8月份生铁成本实现2391.66元/t(期间成本含生产不利
期刊
Named Entity Recognition(NER)for cyber security aims to identify and classify cyber security terms from a large number of heterogeneous multisource cyber security texts.In the field of machine learning,deep neural networks automatically learn text feature
前言rn随着信息技术的发展和对审计工作的影响,推进审计信息化建设既是落实国家对审计工作的部署要求,也是拓展审计监督广度和深度、消除监督盲区、实现审计全覆盖的重要举措,更是内部审计在新形势下为企业健康发展保驾护航的客观需要.
期刊
前言rn当前钢铁行业市场对各种断面规格的铸坯都存在不同程度的需求,其中无论是板卷产品,还是以方坯为基料的各种轧制产品都能用于生产各种规格的管线制品.目前,较常见的方法有两种:第一种是利用板卷进行焊接制管,另一种是使用方坯基料轧制后的产品或圆坯进行直接轧制穿管.在第二种制管工艺中,生产相同规格的管线直接使用圆坯可以减少方坯轧制成圆坯料的一道工序,对于生产成本的降低起到了重要的作用,而降低生产成本一直是生产企业追求的目标,所以在生产相同规格的管线方面,圆坯具有绝对的成本优势.
期刊
前言rn随着市场经济的发展,社会分工日益细化,委托加工这种合作方式日益受到各行各业的青睐和重视.通钢在2019年就本着优势互补、利益共享的原则,着手开展委托加工业务,通过委托加工,优化生产组织模式,解决效益与维系客户之间存在的矛盾,进一步提升公司品牌价值.
期刊
前言rn随着钢材市场上各种品种钢比例的不断提升,以及客户对钢材产品质量要求的日益提高,为了满足市场,国内的钢厂都在采取措施提高钢材产品的质量.rn45钢主要用于汽车、航空工业及各种机械结构件,具有较高的屈服强度、抗拉强度和韧性,因而市场需求量较大.自通钢二炼钢厂停产后,炼钢事业部在3#连铸机开始生产45钢,2018年为了提升产品质量以及扩大推进产品产量,3#机生产的45钢产量明显增加,年产量达到20.44万t占年总产量的4.97%,在大规模生产的环境下,关注产品质量以及如何提升产品质量成为生产45钢的主要
期刊
前言rn转炉活动烟罩提升装置是转炉炼钢的重要辅助设备之一,是使连接炉口上方的活动烟罩在吹炼与加料过程中做相应的升降,其作用一是防止在吹炼过程中钢水钢渣飞溅造成安全事故,二是将转炉吹炼过程产生的混合气体、粉尘及高温热能导入固定段烟道后经后续设备进行处理利用.一旦活动烟罩链条产生拉伸变形,会导致烟罩下沉,造成设备事故,直接影响人身安全及转炉生产.本文介绍炼钢事业部为避免活动烟罩提升链条在生产中发生变形、断裂等故障,从设备点检四大标准出发,以提高性能、便于点检、见效快、成本低为改造初衷进行的一系列改造,包括材质
期刊
The IEEE 1588 precision time protocol(PTP)is very important for many industrial sectors and applications that require time synchronization accuracy between computers down to microsecond and even nanosecond levels.Nevertheless,PTP and its underlying networ
前言rn压力管道在企业的生产中得到了广泛的应用,但压力管道的相关事故也时有发生.因此只有按期或定期做好压力管道的全面检验,才能有效避免事故的发生.本文仅就压力管道全面检验的必要性和重点检验项目进行论述.
期刊