UMVD-FSL: Unseen Malware Variants Detection Using Few-Shot Learning

Candong Rong,Gaopeng Gou,Chengshang Hou,Zhen Li,Gang Xiong,Li Guo
DOI: https://doi.org/10.1109/IJCNN52387.2021.9533759
2021-01-01
Abstract:As the tool for launching cyber attacks, the ever-increasing malware variants pose a significant threat to the interconnected network community. The detection methods based on conventional machine learning techniques require lots of samples for training. However, in real-world scenarios, such as in the early stage of novel attacks appearance, only a small number of malicious samples can be obtained. Applying data-intensive traditional methods in the above scenarios will cause serious overfitting problems. Therefore, there is a need for few-shot detection. In his paper, we propose UMVD-FSL, a framework based on few-shot learning to detect unseen malware variants with a small set of data. We start with network traffic data generated by malware variants and benign applications and then convert them to grayscale images. The prototype-based few-shot learning model takes the grayscale images as the input and utilizes meta-training to generalize the meta-learner for adapting new tasks. When a new sample appears, the model performs classification by computing distances to prototype representation of each class. We evaluate different methods through a series of comparative experiments. Our method has the best performance on all subtasks. The experimental results indicate that our method is universal and robust in detecting malware variants from the same network environment and different network environments. The above points prove that our method can accomplish the task of few-shot unseen malware variants detection.
What problem does this paper attempt to address?