2024 INTERNATIONAL CONFERENCE ON NETWORKING AND NETWORK APPLICATIONS, NANA 2024(2024)
Fujian Normal Univ
被引用0|浏览3
摘要
Few shot malware detection methods can quickly deal with unknown software and secure the network environment. However, the existing methods face two major challenges: one is that the malware itself is characterized by complexity and variability, which makes it difficult for traditional detection methods to cope with it; and the other is that the model overfitting problem is highlighted in the case of limited number of samples. In this paper, we propose a few shot malware detection method based on malware variants and model enhancement. The malware is first converted into a three-channel image, after which a spatial transformation network is combined with an attention mechanism inside the model to address the problem of proliferation of malware variants. To overcome the model overfitting problem, a model training algorithm based on self-distillation is proposed to obtain more robust and discriminative prototype features. Experimental results show that the proposed scheme can effectively identify both known and unknown malware, and the performance and generalization ability are better than existing schemes.