Malware detection on binary executables provides a high availability to even binaries which are not disassembled or decompiled. However, a binary-level approach could cause ambiguity problems. In this paper, we propose a new feature engineering technique that use minimal knowledge about the internal layout on a binary. The proposed feature avoids the ambiguity problems by integrating the information about the layout with structural entropy. The experimental results show that our feature improves accuracy and F1-score by 3.3% and 0.07, respectively, on a CNN based malware detector with realistic benign and malicious samples.
翻译:针对二进制可执行文件的恶意软件检测方法具有高可用性,甚至适用于未经反汇编或反编译的二进制文件。然而,二进制级别的检测方法可能引发歧义问题。本文提出一种新型特征工程技术,仅需利用二进制文件内部布局的极少信息即可实现检测。该特征通过将布局信息与结构熵相融合,有效避免了歧义问题。实验结果表明,基于该特征并结合CNN的恶意软件检测器,在真实场景的良性样本与恶意样本测试中,准确率与F1分数分别提升了3.3%和0.07。