关于APT的研究基于TCN-GAN的恶意软件分类.
1School of Information and Communication, National University of Defense Technology, Wuhan, China.
PloS one
|June 10, 2025
概括
这项研究通过将改进的特征提取与时间卷积网络 (TCN) 和生成对抗网络 (GAN) 结合起来,以扩展样本,提高高级持久威胁 (APT) 恶意软件识别,在追踪恶意软件来源方面达到99.8%的准确性.
科学领域:
- 网络安全 网络安全
- 恶意软件分析 恶意软件分析
- 机器学习 机器学习
背景情况:
- 高级持久威胁 (APT) 恶意软件由于其隐蔽性和破坏性,对大型组织构成重大风险.
- 识别APT恶意软件来源对于有效的网络安全防御和归因至关重要.
- 现有的方法在APT恶意软件分类中的有限样本和数据不平衡方面扎.
研究的目的:
- 开发一种准确的方法来追踪和归因高级持久威胁 (APT) 恶意软件组.
- 通过增强功能提取和采用先进的机器学习模型来改进APT恶意软件的分类和识别.
- 为了应对在APT恶意软件分析中样本规模不足和数据不平衡的挑战.
主要方法:
- 从APT恶意软件中创新提取图像和拆解指令N-gram功能.
- 应用时间卷积网络 (TCN) 模型用于恶意软件分类.
- 使用生成对抗网络 (GAN) 来增强APT恶意软件样本数据集.
主要成果:
- 在识别和分类 APT 恶意软件方面实现了 99.8% 的准确性和精确率.
- 与公开和自建数据集的现有方法相比,表现出优异的性能.
- 通过基于GAN的数据增强,成功地减轻了有限样本和数据不平衡的影响.
结论:
- 拟议的方法为APT恶意软件的归因和识别提供了一个高度准确的方法.
- 这项研究为开发针对APT团体的有效对策和问责策略提供了坚实的基础.
- 整合TCN和GAN为网络安全中高级恶意软件分析提供了一个有希望的方向.
相关概念视频
Group Polarization
Group polarization is the strengthening of an original group attitude following the discussion of views within a group (Teger & Pruitt, 1967). That is, if a group initially favors a viewpoint, after discussion the group consensus is likely a stronger endorsement of the viewpoint. Conversely, if the group was initially opposed to a viewpoint, group discussion would likely lead to stronger opposition.
Methods of Classification and Identification
Bacterial identification relies on a diverse array of techniques to classify and understand microorganisms, each tailored to uncover specific characteristics. Traditional morphological approaches, while still valuable, are limited for closely related or structurally simple organisms. Modern methods integrate biochemical, serological, genetic, and advanced molecular tools to achieve greater accuracy.Morphological and Biochemical TechniquesMorphological characteristics, such as cell shape and...


