Next Article in Journal
The Implementation of a Gesture Recognition System with a Millimeter Wave and Thermal Imager
Previous Article in Journal
Surface-Plasmon-Resonance Amplification of FMD Detection through Dendrimer Conjugation
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Channel Features and API Frequency-Based Transformer Model for Malware Identification

School of Electrical and Information Engineering, Beijing University of Civil Engineering and Architecture, Beijing 100044, China
*
Author to whom correspondence should be addressed.
Sensors 2024, 24(2), 580; https://doi.org/10.3390/s24020580
Submission received: 7 December 2023 / Revised: 13 January 2024 / Accepted: 15 January 2024 / Published: 17 January 2024
(This article belongs to the Section Sensor Networks)

Abstract

Malicious software (malware), in various forms and variants, continues to pose significant threats to user information security. Researchers have identified the effectiveness of utilizing API call sequences to identify malware. However, the evasion techniques employed by malware, such as obfuscation and complex API call sequences, challenge existing detection methods. This research addresses this issue by introducing CAFTrans, a novel transformer-based model for malware detection. We enhance the traditional transformer encoder with a one-dimensional channel attention module (1D-CAM) to improve the correlation between API call vector features, thereby enhancing feature embedding. A word frequency reinforcement module is also implemented to refine API features by preserving low-frequency API features. To capture subtle relationships between APIs and achieve more accurate identification of features for different types of malware, we leverage convolutional neural networks (CNNs) and long short-term memory (LSTM) networks. Experimental results demonstrate the effectiveness of CAFTrans, achieving state-of-the-art performance on the mal-api-2019 dataset with an F1 score of 0.65252 and an AUC of 0.8913. The findings suggest that CAFTrans improves accuracy in distinguishing between various types of malware and exhibits enhanced recognition capabilities for unknown samples and adversarial attacks.
Keywords: malware identification; deep learning; dynamic analysis; API sequence; transformer malware identification; deep learning; dynamic analysis; API sequence; transformer

Share and Cite

MDPI and ACS Style

Qian, L.; Cong, L. Channel Features and API Frequency-Based Transformer Model for Malware Identification. Sensors 2024, 24, 580. https://doi.org/10.3390/s24020580

AMA Style

Qian L, Cong L. Channel Features and API Frequency-Based Transformer Model for Malware Identification. Sensors. 2024; 24(2):580. https://doi.org/10.3390/s24020580

Chicago/Turabian Style

Qian, Liping, and Lin Cong. 2024. "Channel Features and API Frequency-Based Transformer Model for Malware Identification" Sensors 24, no. 2: 580. https://doi.org/10.3390/s24020580

APA Style

Qian, L., & Cong, L. (2024). Channel Features and API Frequency-Based Transformer Model for Malware Identification. Sensors, 24(2), 580. https://doi.org/10.3390/s24020580

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop