Feature fusion-based malicious code detection with dual attention mechanism and BiLSTM
Malicious code has become an important factor threatening network security. Single feature-based malicious code detection methods have achieved good detection results, but when faced with some similar malicious code families, the detection effect is often poor. To address this concern, we propose a...
Saved in:
Published in | Computers & security Vol. 119; p. 102761 |
---|---|
Main Authors | , , , , |
Format | Journal Article |
Language | English |
Published |
Amsterdam
Elsevier Ltd
01.08.2022
Elsevier Sequoia S.A |
Subjects | |
Online Access | Get full text |
ISSN | 0167-4048 1872-6208 |
DOI | 10.1016/j.cose.2022.102761 |
Cover
Summary: | Malicious code has become an important factor threatening network security. Single feature-based malicious code detection methods have achieved good detection results, but when faced with some similar malicious code families, the detection effect is often poor. To address this concern, we propose a feature fusion-based malicious code detection with dual attention mechanism and Bi-directional Long Short-Term Memory (BiLSTM). The dual attention mechanism module gives different focuses on the channel and space of feature maps to extract local texture features of malicious code grayscale images. At the same time, the BiLSTM module extracts global texture structure features of malicious code grayscale images, and fuse local texture features with global texture features, which can not only reflect the detailed characteristics of malicious code, but also retain the overall structural characteristics. Finally, we use the focal loss function to reduce the impact of data imbalance. The experimental results show that our feature fusion approach has a better detection effect compared with the single feature approach, especially in the detection of similar malicious code families. |
---|---|
Bibliography: | ObjectType-Article-1 SourceType-Scholarly Journals-1 ObjectType-Feature-2 content type line 14 |
ISSN: | 0167-4048 1872-6208 |
DOI: | 10.1016/j.cose.2022.102761 |