信息网络安全 ›› 2026, Vol. 26 ›› Issue (7): 1028-1043.doi: 10.3969/j.issn.1671-1122.2026.07.003
收稿日期:2026-05-14
出版日期:2026-07-10
发布日期:2026-09-03
通讯作者:
寇亮
E-mail:kouliang@hdu.edu.cn
作者简介:寇亮(1988—),男,山东,副教授,博士,主要研究方向为人工智能安全|屠国炫(2002—),男,浙江,硕士研究生,主要研究方向为AI智能体开发和AI安全|潘晓晨(2002—),男,安徽,硕士研究生,主要研究方向为AI安全|张纪林(1980—),男,山东,教授,博士,主要研究方向为大数据安全。
基金资助:
Kou Liang(
), Tu Guoxuan, Pan Xiaochen, Zhang Jilin
Received:2026-05-14
Online:2026-07-10
Published:2026-09-03
Contact:
Kou Liang
E-mail:kouliang@hdu.edu.cn
摘要:
在恶意软件检测中,利用应用程序编程接口(API)序列的上下文语义是一种有效方法,但该方法运行时,参数的安全语义仍未得到充分探索。尽管近期研究尝试通过静态标记引入运行时参数,但此类方法通常无法捕捉动态语义的模糊性,即运行时参数的风险会随API上下文变化,且往往无法检测出逃避聚类模式的异常个体。为此,文章提出一种用于恶意软件检测的多视图敏感度挖掘框架MvSe-Mal。首先,采用统计风险分析量化API操作的内在安全级别。其次,整合互补挖掘策略建立三维敏感度量化机制,利用聚类分析捕捉群体恶意行为,通过个体异常检测精准定位异常个体,并引入API亲和度衡量参数与恶意API的关联强度。最后,实现了一种敏感度感知的特征线性调制(Sens-FiLM)机制。相较于简单的静态拼接,该机制将敏感度级别作为动态条件,重新校准深度神经网络的中间特征表示,使模型能够基于实时敏感度上下文,自适应地突出高风险行为模式并抑制噪声。在两个深度神经网络模型上的大量实验结果表明,MvSe-Mal显著优于仅依赖API序列的基线模型及现有结合参数的检测方法,验证了文章所提策略的有效性。
中图分类号:
寇亮, 屠国炫, 潘晓晨, 张纪林. 基于多视图敏感度挖掘与特征调制的恶意软件检测[J]. 信息网络安全, 2026, 26(7): 1028-1043.
Kou Liang, Tu Guoxuan, Pan Xiaochen, Zhang Jilin. Enhancing malware detection via multi-view sensitivity mining and Sens-FiLM modulation[J]. Netinfo Security, 2026, 26(7): 1028-1043.
表1
同一参数在不同API中的敏感度情况
| API 调用 | 输入参数 | API表现类型 | 敏感度 |
|---|---|---|---|
| GetFileAttributes | C:\Users\Default\AppData\Roaming\malicious.dll | 查询文件属性 | 低 |
| LoadLibrary | C:\Users\Default\AppData\Roaming\malicious.dll | 加载动态链接库 | 中 |
| CreateService | C:\Users\Default\AppData\Roaming\malicious.dll | 创建自动启动服务 | 高 |
| ReadFile | C:\Windows\System32\config\SAM | 读取文件内容 | 低 |
| RegLoadKey | C:\Windows\System32\config\SAM | 加载注册表元数据文件 | 中 |
| SetFileAttributes | C:\Windows\System32\config\SAM | 修改文件属性 | 高 |
表2
与先进方法的对比结果
| 数据集 | 方法 | 是否使用参数 | 准确率 | 精确率 | 召回率 | F1分数 |
|---|---|---|---|---|---|---|
| 验证集 | 文献[ | 否 | 86.63% | 85.27% | 88.81% | 86.92% |
| 文献[ | 否 | 96.40% | 96.56% | 96.21% | 96.40% | |
| 文献[ | 是 | 97.97% | 98.69% | 97.26% | 97.97% | |
| 文献[ | 是 | 98.16% | 98.66% | 97.66% | 98.16% | |
| MvSe-Mal (TextCNN) | 是 | 98.67% | 99.18% | 96.80% | 97.98% | |
| 测试集 | 文献[ | 否 | 67.11% | 61.62% | 90.70% | 73.38% |
| 文献[ | 否 | 85.54% | 94.98% | 75.04% | 83.84% | |
| 文献[ | 是 | 91.76% | 97.64% | 85.59% | 91.22% | |
| 文献[ | 是 | 98.52% | 98.63% | 98.41% | 98.52% | |
| MvSe-Mal (TextCNN) | 是 | 98.40% | 98.92% | 96.25% | 97.56% |
表3
与基线方法的对比结果(训练结果)
| 方法 | 准确率 | 精确率 | 召回率 | F1分数 |
|---|---|---|---|---|
| Naive Bayes | 83.62% | 86.10% | 80.20% | 83.04% |
| KNN | 78.10% | 94.70% | 59.54% | 73.11% |
| Logistic | 89.27% | 91.12% | 87.03% | 89.03% |
| DT | 96.44% | 97.91% | 94.92% | 96.39% |
| TextCNN | 99.56% | 99.63% | 99.49% | 99.56% |
| BiLSTM | 97.47% | 97.97% | 96.96% | 97.46% |
| MvSe-Mal-BiLSTM | 96.26% | 94.03% | 94.79% | 94.41% |
| MvSe-Mal-TextCNN | 99.39% | 99.93% | 98.24% | 99.08% |
表4
与基线方法的对比结果(测试结果)
| 方法 | 准确率 | 精确率 | 召回率 | F1分数 |
|---|---|---|---|---|
| Naive Bayes | 71.85% | 82.36% | 55.60% | 66.38% |
| KNN | 65.86% | 91.07% | 35.17% | 50.74% |
| Logistic | 71.69% | 84.80% | 52.85% | 65.12% |
| DT | 76.32% | 90.28% | 58.99% | 71.36% |
| TextCNN | 95.54% | 97.65% | 93.33% | 95.44% |
| BiLSTM | 84.16% | 93.36% | 73.55% | 82.28% |
| MvSe-Mal-BiLSTM | 96.48% | 94.22% | 95.30% | 94.76% |
| MvSe-Mal-TextCNN | 98.40% | 98.92% | 96.25% | 97.56% |
| [1] | Michalowski M. 50+ Malware statistics for 2025[EB/OL]. (2026-01-01) [2026-04-24]. https://spacelift.io/blog/malware-statistics#malware-impact-and-costs. |
| [2] | Baghirov E. Techniques of malware detection: research review[C]//2021 IEEE 15th International Conference on Application of Information and Communication Technologies (AICT). New York: IEEE, 2021: 1-6. |
| [3] |
Meng Zhaoyi, Zhang Jiale, Guo Jiaqi, et al. Detecting android malware by visualizing APP behaviors from multiple complementary views[J]. IEEE Transactions on Information Forensics and Security, 2025, 20: 2915-2929.
doi: 10.1109/TIFS.2025.3547301 URL |
| [4] |
Ding Yuxin, Dai Wei, Yan Shengli, et al. Control flow-based opcode behavior analysis for malware detection[J]. Computers & Security, 2014, 44: 65-74.
doi: 10.1016/j.cose.2014.04.003 URL |
| [5] |
Cesare S, Xiang Yang, Zhou Wanlei. Control flow-based malware variantdetection[J]. IEEE Transactions on Dependable and Secure Computing, 2014, 11(4): 307-317.
doi: 10.1109/TDSC.2013.40 URL |
| [6] | Sharif M I, Lanzi A, Giffin J T, et al. Impeding malware analysis using conditional code obfuscation[EB/OL]. (2026-01-01) [2026-04-24]. https://air.unimi.it/handle/2434/455576. |
| [7] |
Chen Xiaohui, Hao Zhiyu, Li Lun, et al. CruParamer: learning on parameter-augmented API sequences for malware detection[J]. IEEE Transactions on Information Forensics and Security, 2022, 17: 788-803.
doi: 10.1109/TIFS.2022.3152360 URL |
| [8] |
Chen Tieming, Zeng Huan, Lyu Mingqi, et al. CTIMD: cyber threat intelligence enhanced malware detection using API call sequences with parameters[J]. Computers & Security, 2024, 136: 103518.
doi: 10.1016/j.cose.2023.103518 URL |
| [9] |
Zhang Zhaoqi, Qi Panpan, Wang Wei. Dynamic malware analysis with feature engineering and feature learning[J]. Proceedings of the AAAI Conference on Artificial Intelligence, 2020, 34(1): 1210-1217.
doi: 10.1609/aaai.v34i01.5474 URL |
| [10] |
Zhu Huijuan, Chen Xilong, Wang Liangmin, et al. A dynamic analysis-powered explanation framework for malware detection[J]. IEEE Transactions on Knowledge and Data Engineering, 2024, 36(12): 7483-7496.
doi: 10.1109/TKDE.2024.3436891 URL |
| [11] |
Li Ce, Lyu Qiujian, Li Ning, et al. A novel deep framework for dynamic malware detection based on API sequence intrinsic features[J]. Computers & Security, 2022, 116: 102686.
doi: 10.1016/j.cose.2022.102686 URL |
| [12] | Cui Lei, Cui Jiancong, Ji Yuede, et al. API2Vec: learning representations of API sequences for malware detection[C]// The 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis. New York: ACM, 2023: 261-273. |
| [13] |
Wong G W, Huang Yiting, Guo Yingren, et al. Attention-based API locating for malware techniques[J]. IEEE Transactions on Information Forensics and Security, 2024, 19: 1199-1212.
doi: 10.1109/TIFS.2023.3330337 URL |
| [14] |
Babu S, Singh V. BD-MDLC: behavior description-based enhanced malware detection for windows environment using longformer classifier[J]. Computers & Security, 2024, 146: 104031.
doi: 10.1016/j.cose.2024.104031 URL |
| [15] |
Li Ce, Cheng Zijun, Zhu He, et al. DMalNet: dynamic malware analysis based on API feature engineering and graph learning[J]. Computers & Security, 2022, 122: 102872.
doi: 10.1016/j.cose.2022.102872 URL |
| [16] |
Trizna D, Demetrio L, Biggio B, et al. Nebula: self-attention for dynamic malware analysis[J]. IEEE Transactions on Information Forensics and Security, 2024, 19: 6155-6167.
doi: 10.1109/TIFS.2024.3409083 URL |
| [17] | Agrawal R, Stokes J W, Marinescu M, et al. Neural sequential malware detection with parameters[C]// 2018 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). New York: IEEE, 2018: 2656-2660. |
| [18] |
Kanungo T, Mount D M, Netanyahu N S, et al. An efficient K-Means clustering algorithm: analysis and implementation[J]. IEEE Transactions on Pattern Analysis and Machine Intelligence, 2002, 24(7): 881-892.
doi: 10.1109/TPAMI.2002.1017616 URL |
| [19] |
Zhao Ying, Karypis G, Fayyad U. Hierarchical clustering algorithms for document datasets[J]. Data Mining and Knowledge Discovery, 2005, 10(2): 141-168.
doi: 10.1007/s10618-005-0361-3 URL |
| [20] | Schubert E, Sander J, Ester M, et al. DBSCAN revisited, revisited: why and how you should (still) use DBSCAN[J]. ACM Transactions on Database Systems, 2017, 42(3): 1-21. |
| [21] | Ng A, Jordan M, Weiss Y. On spectral clustering: analysis and an algorithm[EB/OL]. [2026-04-24]. https://proceedings.neurips.cc/paper_files/paper/2001/file/801272ee79cfde7fa5960571fee36b9b-Paper.pdf. |
| [22] | Liu F T, Ting Kaiming, Zhou Zhihua. Isolation forest[C]// 2008 Eighth IEEE International Conference on Data Mining. New York: IEEE, 2008: 413-422. |
| [23] | Perez E, Strub F, De V H, et al. FiLM: visual reasoning with a general conditioning layer[J]. Proceedings of the AAAI Conference on Artificial Intelligence, 2018, 32(1): 3942-3951. |
| [24] | Zhang Shu, Zheng Dequan, Hu Xinchen, et al. Bidirectional long short-term memory networks for relation classification[C]// The 29th Pacific Asia Conference on Language, Information and Computation. Shanghai: PACLIC, 2015: 73-78. |
| [25] | Kim Y. Convolutional neural networks for sentence classification[C]// The 2014 Conference on Empirical Methods in Natural Language Processing (EMNLP). Stroudsburg: ACL, 2014: 1746-1751. |
| [26] | Datacon 2019. Malicious-code-dataset[DS/OL]. (2019-01-01) [2026-04-24]. https://github.com/kericwy1337. |
| [27] |
Amer E, Zelinka I. A dynamic windows malware detection and prediction method based on contextual understanding of API call sequence[J]. Computers & Security, 2020, 92: 101760.
doi: 10.1016/j.cose.2020.101760 URL |
| [28] |
Ndibanje B, Kim K H, Kang Y J, et al. Cross-method-based analysis and classification of malicious behavior by API calls extraction[J]. Applied Sciences, 2019, 9(2): 239.
doi: 10.3390/app9020239 URL |
| [29] |
Cieslak M C, Castelfranco A M, Roncalli V, et al. T-distributed stochastic neighbor embedding (t-SNE): a tool for eco-physiological transcriptomic analysis[J]. Marine Genomics, 2020, 51: 100723.
doi: 10.1016/j.margen.2019.100723 URL |
| [30] |
Zhu Huijuan, Wang Liangmin, Zhong Sheng, et al. A hybrid deep network framework for android malware detection[J]. IEEE Transactions on Knowledge and Data Engineering, 2022, 34(12): 5558-5570.
doi: 10.1109/TKDE.2021.3067658 URL |
| [31] | Saxe J, Berlin K. Deep neural network based malware detection using two dimensional binary program features[C]// 2015 10th International Conference on Malicious and Unwanted Software (MALWARE). New York: IEEE, 2015: 11-20. |
| [32] | Hansen S S, Larsen T M T, Stevanovic M, et al. An approach for detection and family classification of malware based on behavioral analysis[C]// 2016 International Conference on Computing, Networking and Communications (ICNC). New York: IEEE, 2016: 1-5. |
| [33] | Zhang Xiaohan, Zhang Yuan, Zhong Ming, et al. Enhancing state-of-the-art classifiers with API semantics to detect evolved android malware[C]// The 2020 ACM SIGSAC Conference on Computer and Communications Security. New York: ACM, 2020: 757-770. |
| [34] | Rosenberg I, Shabtai A, Rokach L, et al. Generic black-box end-to-end attack against state of the art API call based malware classifiers[C]// International Symposium on Research in Attacks, Intrusions, and Defenses. Heidelberg: Springer, 2018: 490-510. |
| [35] | Salehi Z, Ghiasi M, Sami A. A miner for malware detection based on API function calls and their arguments[C]// The 16th CSI International Symposium on Artificial Intelligence and Signal Processing (AISP 2012). New York: IEEE, 2012: 563-568. |
| [36] |
Salehi Z, Sami A, Ghiasi M. MAAR: robust features to detect malicious activity based on API calls, their arguments and return values[J]. Engineering Applications of Artificial Intelligence, 2017, 59: 93-102.
doi: 10.1016/j.engappai.2016.12.016 URL |
| [1] | 孙浩然, 陈杰, 刘君. 多路径特征增强的深度学习矩形攻击防御方法[J]. 信息网络安全, 2026, 26(7): 1115-1127. |
| [2] | 李海龙, 张运豪, 沈燮阳, 邢宇航, 崔治安. 基于机器学习的恶意软件检测方法综述[J]. 信息网络安全, 2026, 26(4): 521-541. |
| [3] | 徐衍微, 涂敏, 张亮. 深度伪造语音真实性鉴定研究综述[J]. 信息网络安全, 2026, 26(3): 367-377. |
| [4] | 秦振凯, 罗起宁, 农熏衣, 于小川, 操晓春. 融合性别与情绪强度提示特征的多层次语音情感识别模型[J]. 信息网络安全, 2026, 26(3): 420-431. |
| [5] | 徐茹枝, 武晓欣, 吕畅冉. 基于Transformer的超分辨率网络对抗样本防御方法研究[J]. 信息网络安全, 2025, 25(9): 1367-1376. |
| [6] | 陈咏豪, 蔡满春, 张溢文, 彭舒凡, 姚利峰, 朱懿. 多尺度多层次特征融合的深度伪造人脸检测方法[J]. 信息网络安全, 2025, 25(9): 1456-1464. |
| [7] | 王新猛, 陈俊雹, 杨一涛, 李文瑾, 顾杜娟. 贝叶斯优化的DAE-MLP恶意流量识别模型[J]. 信息网络安全, 2025, 25(9): 1465-1472. |
| [8] | 金志刚, 李紫梦, 陈旭阳, 刘泽培. 面向数据不平衡的网络入侵检测系统研究综述[J]. 信息网络安全, 2025, 25(8): 1240-1253. |
| [9] | 王钢, 高雲鹏, 杨松儒, 孙立涛, 刘乃维. 基于深度学习的加密恶意流量检测方法研究综述[J]. 信息网络安全, 2025, 25(8): 1276-1301. |
| [10] | 魏松杰, 吴琴琴, 袁军翼. 基于运行参数增强API序列的勒索软件动态检测方法研究[J]. 信息网络安全, 2025, 25(5): 713-721. |
| [11] | 张兴兰, 陶科锦. 基于高阶特征与重要通道的通用性扰动生成方法[J]. 信息网络安全, 2025, 25(5): 767-777. |
| [12] | 金增旺, 江令洋, 丁俊怡, 张慧翔, 赵波, 方鹏飞. 工业控制系统安全研究综述[J]. 信息网络安全, 2025, 25(3): 341-363. |
| [13] | 陈红松, 刘新蕊, 陶子美, 王志恒. 基于深度学习的时序数据异常检测研究综述[J]. 信息网络安全, 2025, 25(3): 364-391. |
| [14] | 李海龙, 崔治安, 沈燮阳. 网络流量特征的异常分析与检测方法综述[J]. 信息网络安全, 2025, 25(2): 194-214. |
| [15] | 武浩莹, 陈杰, 刘君. 改进Simon32/64和Simeck32/64神经网络差分区分器[J]. 信息网络安全, 2025, 25(2): 249-259. |
| 阅读次数 | ||||||
|
全文 |
|
|||||
|
摘要 |
|
|||||