科技视界
科技視界
과기시계
Science&Technology Vision
2013年
23期
19-19,44
,共2页
变长指令序列%粗糙集属性约简%数据挖掘%恶意代码检测
變長指令序列%粗糙集屬性約簡%數據挖掘%噁意代碼檢測
변장지령서렬%조조집속성약간%수거알굴%악의대마검측
Varible-length Opcode%Rough set attribute reduction%Data mining%Malware detection
针对定长的指令序列特征维数过高且存在分割特征的问题,本文提出了一种基于变长指令序列与粗糙集属性约简的恶意代码检测技术,采用变长的指令序列可以有效解决特征分割的问题,同时为了有效降低特征规模,只考虑常用的13个指令所构成的指令序列,然后利用粗糙集理论进行冗余特征约简,实验最终获得特征维数非常低并且相对定长的指令序列而言,其分类精度更高,漏报率更低。
針對定長的指令序列特徵維數過高且存在分割特徵的問題,本文提齣瞭一種基于變長指令序列與粗糙集屬性約簡的噁意代碼檢測技術,採用變長的指令序列可以有效解決特徵分割的問題,同時為瞭有效降低特徵規模,隻攷慮常用的13箇指令所構成的指令序列,然後利用粗糙集理論進行冗餘特徵約簡,實驗最終穫得特徵維數非常低併且相對定長的指令序列而言,其分類精度更高,漏報率更低。
침대정장적지령서렬특정유수과고차존재분할특정적문제,본문제출료일충기우변장지령서렬여조조집속성약간적악의대마검측기술,채용변장적지령서렬가이유효해결특정분할적문제,동시위료유효강저특정규모,지고필상용적13개지령소구성적지령서렬,연후이용조조집이론진행용여특정약간,실험최종획득특정유수비상저병차상대정장적지령서렬이언,기분류정도경고,루보솔경저。
In order to solve the problems of increase and separation features in fixed-length Opcode sequences,we propose a malware detection techniques base on variable-length Opcode sequences and rough set attribute reduction theory,using vaiable-length Opcode sequences can effectively solve the problem of separation features, and in order to effectively reduce the scale of features, we only consider the Opcode sequences which composed of the commonly used 13 instruction , afterwards we use rough set theory to reduct its, at last we get the features dimension is very low and contrast to fixed-length sequence of instructions, we get th higher classification accuracy, and false negative rate is lower from experiments ultimately.