Malicious software detection method and device

Liu Yang,Wang Xuan,Long Hanlin,Tian Zhicheng,Qi Shuhan,Zhang Jiajia,Xia Wen,Tang Linlin
2021-01-01
Abstract:The invention discloses a malicious software detection method. The method comprises the following steps: determining to-be-detected target software; obtaining a system call name and a network activityevent of the target software; sorting the system call names and the network activity events of the target software in a unified mode according to timestamps, and generating aggregation dynamic characteristics of the target software through encoding; inputting the aggregation dynamic characteristics of the target software into a pre-trained target neural network model based on a sequence converterstructure to obtain an output result; and determining whether the target software is malicious software or not according to the output result. By applying the technical scheme provided by the invention, the malicious software in the terminal is effectively detected by combining the system call name of the software and the network activity event and utilizing the structure of the sequence converter, so that the normal operation of the terminal is prevented from being influenced, and the user experience is improved. The invention further discloses a malicious software detection device which hasthe corresponding technical effects.
What problem does this paper attempt to address?