call graph dataset
收藏资源简介:
该数据集旨在通过分析未知文件的调用图结构信息,将它们分类为恶意软件或正常软件。调用图是由程序分析工具生成的抽象对象,用于表示计算机程序中子例程之间的关系。每个节点代表一个函数,每条边代表一个函数对另一个函数的调用。数据集包含1361个可移植可执行文件,其中546个被视为正常文件,815个被视为恶意文件。调用图通过radare2工具从这些二进制文件中提取,并进行了统计处理以简化节点属性。
This dataset aims to classify unknown files as either malware or benign software by analyzing the call graph structure information of these files. The call graph, an abstract object generated by program analysis tools, represents the relationships between subroutines within a computer program. Each node in the graph represents a function, and each edge represents a call from one function to another. The dataset comprises 1,361 portable executable files, of which 546 are classified as benign and 815 as malicious. The call graphs were extracted from these binary files using the radare2 tool and underwent statistical processing to simplify node attributes.
数据集概述
数据集目的
本数据集旨在通过学习未知文件的调用图结构信息,将其分类为恶意软件(malware)或正常软件(goodware)。
数据集内容
提取方法
- 数据集包含1361个PE(便携式可执行文件),其中546个为正常文件,815个为恶意文件。
- 使用radare2工具从这些二进制文件中提取调用图。
- 每个节点代表一个函数,每条边代表一个函数调用另一个函数。
- 统计每个节点中频繁操作码(如mov, call, lea等)的调用次数,以提取相关信息。
数据集组织
- 调用图分为两个子集:一个用于正常文件,另一个用于恶意文件。
- 每个子集的数据以列表形式存储,每个元素包含两个字典:
- 节点与属性的映射
- 节点与邻居节点的映射
数据集统计
正常文件(Goodware)
- 图的数量:546
- 平均节点数:648.1
- 平均度数:3.3
- 中位数度数:2.7
- 最大度数:10.1
- 孤立节点数:130812
- 孤立节点平均数:239.6
- 自环数:0
恶意文件(Malware)
- 图的数量:815
- 平均节点数:871.5
- 平均度数:3.6
- 中位数度数:3.7
- 最大度数:34.4
- 孤立节点数:231990
- 孤立节点平均数:284.7
- 自环数:0
数据集使用
数据集可通过以下步骤加载:
- 克隆数据集仓库。
- 解压数据集文件。
- 使用pickle模块加载调用图数据。




