Explainable Malware Detection through Integrated Graph Reduction and Learning Techniques

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Mohammadian, Hesamodin, Higgins, Griffin, Ansong, Samuel, Razavi-Far, Roozbeh, Ghorbani, Ali A.
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913599048384512
author Mohammadian, Hesamodin
Higgins, Griffin
Ansong, Samuel
Razavi-Far, Roozbeh
Ghorbani, Ali A.
author_facet Mohammadian, Hesamodin
Higgins, Griffin
Ansong, Samuel
Razavi-Far, Roozbeh
Ghorbani, Ali A.
contents Control Flow Graphs and Function Call Graphs have become pivotal in providing a detailed understanding of program execution and effectively characterizing the behavior of malware. These graph-based representations, when combined with Graph Neural Networks (GNN), have shown promise in developing high-performance malware detectors. However, challenges remain due to the large size of these graphs and the inherent opacity in the decision-making process of GNNs. This paper addresses these issues by developing several graph reduction techniques to reduce graph size and applying the state-of-the-art GNNExplainer to enhance the interpretability of GNN outputs. The analysis demonstrates that integrating our proposed graph reduction technique along with GNNExplainer in the malware detection framework significantly reduces graph size while preserving high performance, providing an effective balance between efficiency and transparency in malware detection.
format Preprint
id arxiv_https___arxiv_org_abs_2412_03634
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Explainable Malware Detection through Integrated Graph Reduction and Learning Techniques
Mohammadian, Hesamodin
Higgins, Griffin
Ansong, Samuel
Razavi-Far, Roozbeh
Ghorbani, Ali A.
Cryptography and Security
Machine Learning
Control Flow Graphs and Function Call Graphs have become pivotal in providing a detailed understanding of program execution and effectively characterizing the behavior of malware. These graph-based representations, when combined with Graph Neural Networks (GNN), have shown promise in developing high-performance malware detectors. However, challenges remain due to the large size of these graphs and the inherent opacity in the decision-making process of GNNs. This paper addresses these issues by developing several graph reduction techniques to reduce graph size and applying the state-of-the-art GNNExplainer to enhance the interpretability of GNN outputs. The analysis demonstrates that integrating our proposed graph reduction technique along with GNNExplainer in the malware detection framework significantly reduces graph size while preserving high performance, providing an effective balance between efficiency and transparency in malware detection.
title Explainable Malware Detection through Integrated Graph Reduction and Learning Techniques
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2412.03634