APTMalInsight: Identify and cognize APT malware based on system call information and ontology knowledge framework

Weijie Han*, Jingfeng Xue, Yong Wang, Fuquan Zhang, Xianwei Gao

*此作品的通讯作者

科研成果: 期刊稿件文章同行评审

46 引用 (Scopus)

摘要

APT attacks have posed serious threats to the security of cyberspace nowadays which are usually tailored for specific targets. Identification and understanding of APT attacks remains a key issue for society. Attackers often utilize malware as the weapons to launch cyber-attacks. For this reason, detecting APT malware and gaining an insight of its malicious behaviors can strengthen the power to understand and counteract APT attacks. Based on the above motivation, this paper proposes a novel APT malware detection and cognition framework named APTMalInsight aiming at identifying and cognizing APT malware by leveraging system call information and ontology knowledge. We systematically study APT malware and extracts dynamic system call information to describe its behavioral characteristics. With respect to the established feature vectors, the APT malware can be detected and clustered into their belonging families accurately. Furthermore, a horizontal comparison between APT malware and the traditional malware is conducted from the perspective of behavior types, to understand the behavioral characteristics of APT malware in depth. On the above basis, the ontology model is introduced to construct the APT malware knowledge framework to represent its typical malicious behaviors, thereby implementing the systematic cognition of APT malware and providing contextual understanding of APT attacks. The evaluation results based on real APT malware samples demonstrate that the detection and clustering accuracy can reach up to 99.28% and 98.85% respectively. In addition, APTMalInsight supplies an effective cognition framework for APT malware and enhances the capability to understand APT attacks.

源语言英语
页(从-至)633-664
页数32
期刊Information Sciences
546
DOI
出版状态已出版 - 6 2月 2021

指纹

探究 'APTMalInsight: Identify and cognize APT malware based on system call information and ontology knowledge framework' 的科研主题。它们共同构成独一无二的指纹。

引用此