Abstract
Advanced malware variants attacks have been posing catastrophes to the cyber ecosystem. However, existing malware variants detection methods are feeble for detecting the advanced malware variants due to the twofold flaws. First, most detection methods focus on analyzing the isolated features instead of investigating the meaningful contextual interactions between fine-grained malware entities, resulting in poor performance. Second, the existing graph-based detection approaches are incapable of leveraging the temporal dependence information between execution behaviors to capture the malicious evolutionary patterns and incur expensive time costs when traversing vast invalid paths. To overcome these limitations, this paper proposes TI-MVD, a temporal interaction-enhanced malware variants detection framework. TI-MVD models the fine-grained malware objects with a temporal heterogeneous graph, which can simultaneously leverage the temporal and structural embedding features to detect malware variants. Concretely, a novel end-to-end interaction-enhanced embedding approach is proposed to learn the structural embedding, which is capable of incorporating explicit and implicit interactive information between node pairs to boost detection effectiveness. Meanwhile, a strong-correlated clique method exploiting two coupled GRUs is presented to handle the temporal interactions in a parallel manner, which can drastically reduce the time cost of temporal embedding. Experimental results on four real-world datasets demonstrate that our proposed TI-MVD outperforms the state-of-the-art methods by a large margin.
| Original language | English |
|---|---|
| Article number | 110850 |
| Journal | Knowledge-Based Systems |
| Volume | 278 |
| DOIs | |
| State | Published - 25 Oct 2023 |
Keywords
- Heterogeneous graph
- Interaction-enhanced model
- Malware variants detection
- Structural embedding
- Temporal graph embedding
Fingerprint
Dive into the research topics of 'TI-MVD: A temporal interaction-enhanced model for malware variants detection'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver