Automatic Malware Description via Attribute Tagging and Similarity Embedding
Sophos 一家基于算法的安全公司
abstract
With the rapid proliferation and increased sophistication of malicious software, detection methods no longer rely only on manually generated signatures but have also incorporated more general approaches like machine learning detection.
Although powerful for conviction of malicious artifacts, these methods do not produce any further information about the type of threat that has been detected neither allows for identifying relationships between malware samples.
In this work, we address the information
本文提出了一种基于深度学习的恶意软件标记模型,该模型能够生成人类可解释的恶意软件描述,同时提供了一个表示恶意样本的相似性空间。这种方法在95%的情况下能正确识别11种可能的标签描述,并且在1%的误报率下工作。此外,通过学习的表示空间,引入了恶意文件之间的相似性指数,不仅在识别相同家族的样本时更有效,而且比基于原始特征向量的表示小32倍。
订阅专栏 解锁全文
3964

被折叠的 条评论
为什么被折叠?



