Skip to main navigation Skip to search Skip to main content

MalGraph: Hierarchical Graph Neural Networks for Robust Windows Malware Detection

  • Xiang Ling
  • , Lingfei Wu
  • , Wei Deng
  • , Zhenqing Qu
  • , Jiangyu Zhang
  • , Sheng Zhang
  • , Tengfei Ma
  • , Bin Wang
  • , Chunming Wu
  • , Shouling Ji
  • CAS - Institute of Software
  • Zhejiang University
  • JD.COM Silicon Valley Research Center
  • Hangzhou Hikvision Digital Technology Co. Ltd.

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

62 Scopus citations

Abstract

With the ever-increasing malware threats, malware detection plays an indispensable role in protecting information systems. Although tremendous research efforts have been made, there are still two key challenges hindering them from being applied to accurately and robustly detect malwares. Firstly, most of them represent executables with shallow features, but ignore their semantic and structural information. Secondly, they are primarily based on representations that can be easily modified by attackers and thus cannot provide robustness against adversarial attacks. To tackle the challenges, we present MalGraph, which first represents executables with hierarchical graphs and then uses an end-to-end learning framework based on graph neural networks for malware detection. In particular, a hierarchical graph consists of a function call graph that captures the interaction semantics among different functions at the inter-function level and corresponding control-flow graphs for learning the structural semantics of each function at the intra-function level. We argue the abstraction and hierarchy nature of hierarchical graphs makes them not only easy to capture rich structural information of executables, but also be immune to adversarial attacks. Evaluations show that MalGraph not only outperforms state-of-the-art malware detection, but also exhibits stronger robustness against adversarial attacks by a large margin.

Original languageEnglish
Title of host publicationINFOCOM 2022 - IEEE Conference on Computer Communications
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages1998-2007
Number of pages10
ISBN (Electronic)9781665458221
DOIs
StatePublished - 2022
Event41st IEEE Conference on Computer Communications, INFOCOM 2022 - Virtual, Online, United Kingdom
Duration: May 2 2022May 5 2022

Publication series

NameProceedings - IEEE INFOCOM
Volume2022-May
ISSN (Print)0743-166X

Conference

Conference41st IEEE Conference on Computer Communications, INFOCOM 2022
Country/TerritoryUnited Kingdom
CityVirtual, Online
Period05/2/2205/5/22

Keywords

  • Graph Neural Network
  • Malware Detection
  • Representation Learning
  • Software Security

Fingerprint

Dive into the research topics of 'MalGraph: Hierarchical Graph Neural Networks for Robust Windows Malware Detection'. Together they form a unique fingerprint.

Cite this