malware-families-catalog
收藏资源简介:
恶意软件家族目录是一个包含2,899个真实世界恶意软件家族的数据集,这些家族提取自EMBER 2018(Elastic恶意软件基准)数据集,并经过分类整理,旨在服务于安全团队、安全运营中心(SOC)分析师和事件响应人员。该数据集对恶意软件家族进行了系统化编目,每个家族对应一条记录。数据集总计包含2,899个家族,其中245个经过人工整理和分类,其余2,654个属于未分类的长尾家族。所有家族被划分为19个高级别类别,例如木马、银行木马、勒索软件、蠕虫、间谍软件、广告软件、后门、远程访问木马(RAT)、下载器、投放器、Rootkit、挖矿程序、信息窃取程序、潜在有害程序(PUA)、病毒、键盘记录器、僵尸程序、漏洞利用程序以及未知类别。每条记录包含以下字段:归一化的恶意软件家族名称(基于avclass标签)、在EMBER 2018数据集中拥有该标签的二进制样本数量、该家族所属的高级类别、对该家族的简要事实性描述以及标准化的事件响应指导建议。数据以Parquet格式提供(同时有JSONL镜像),适用于恶意软件分类、威胁情报分析、安全事件响应辅助以及网络安全研究等任务。数据集采用Apache-2.0许可证发布。
The Malware Family Catalog is a dataset containing 2,899 real-world malware families extracted and curated from the EMBER 2018 (Elastic Malware Benchmark) dataset, intended to serve security teams, Security Operations Center (SOC) analysts, and incident responders. This dataset systematically catalogs malware families, with each entry corresponding to one family. In total, the dataset includes 2,899 families, of which 245 have been manually curated and classified, while the remaining 2,654 are unclassified long-tail families. All families are categorized into 19 high-level categories, such as Trojan, Trojan-Banker, Ransomware, Worm, Spyware, Adware, Backdoor, Remote Access Trojan (RAT), Downloader, Dropware, Rootkit, Cryptominer, Information Stealer, Potentially Unwanted Application (PUA), Virus, Keylogger, Bot, Exploit, and Unknown Category. Each entry contains the following fields: normalized malware family name (based on avclass labels), number of binary samples with this tag in the EMBER 2018 dataset, the high-level category the family belongs to, a concise factual description of the family, and standardized incident response guidance recommendations. The data is provided in Parquet format with a JSONL mirror available, and is applicable to tasks including malware classification, threat intelligence analysis, security incident response assistance, and cybersecurity research. The dataset is released under the Apache-2.0 license.
数据集概述
Malware Families Catalog 是一个包含 2,899 个真实世界恶意软件家族的数据集,基于 EMBER 2018 基准提取,专为安全团队、SOC 分析师和事件响应设计。
关键信息
- 总家族数: 2,899
- 已分类(精选): 245
- 未分类(长尾): 2,654
- 类别数量: 19
- 数据来源: EMBER 2018 v2 (Elastic Malware Benchmark)
- 许可证: Apache-2.0
- 数据格式: Parquet (同时提供 JSONL 镜像),每个记录对应一个恶意软件家族
- 语言: 英语
- 任务类别: 文本分类、表格分类
- 标签: 恶意软件、网络安全、威胁情报、事件响应、SOC、EMBER、分类、安全
- 数据集大小: 1K < n < 10K
数据字段结构
每个记录包含以下字段:
| 字段 | 类型 | 描述 |
|---|---|---|
| family | string | 标准化的恶意软件家族名称(avclass 标签) |
| sample_count | int | EMBER 2018 中带有此标签的二进制样本数量 |
| category | string | 高级类别(共19个,见类别词汇表) |
| description | string | 该家族的简短事实描述 |
| cta | string | 标准化的事件响应指导 |
类别词汇表
| 类别 | 定义 |
|---|---|
| trojan | 伪装成合法软件,执行后释放隐藏负载的恶意软件。包括没有更具体分类的通用特洛伊木马。 |
| banker | 拦截凭证、浏览器会话或交易数据,针对金融机构和加密货币钱包的银行木马。 |
| ransomware | 加密文件或锁屏,要求支付赎金以解密或恢复访问的恶意软件。 |
| worm | 无需用户操作即可通过网络或可移动媒体自我传播的恶意软件。 |
| spyware | 设计用于秘密收集系统或用户信息的软件,包括按键记录、屏幕截图和浏览历史。 |
| adware | 显示不想要的广告的软件,通常与其他软件捆绑,难以移除。 |
| backdoor | 绕过正常认证,为攻击者提供对受损系统持久控制的远程访问恶意软件。 |
| rat | 远程访问木马,具备广泛远程控制能力的后门,常用于定向攻击。 |
| downloader | 主要功能是从远程服务器获取并执行额外负载的轻量级恶意软件。 |
| dropper | 包含并安装次要负载的恶意软件,通常从自身提取而非下载。 |
| rootkit | 通过深度颠覆操作系统来隐藏自身及其他恶意组件的恶意软件。 |
| miner | 未经授权使用受害者 CPU 或 GPU 资源的加密货币挖矿恶意软件。 |
| infostealer | 专注于窃取凭证、cookies、自动填充数据和加密货币钱包的数据窃取恶意软件。 |
| pua | 可能不需要的应用程序,表现出侵入性行为但不严格属于恶意软件。 |
| virus | 附加到合法文件并在执行这些文件时传播的自我复制代码。 |
| keylogger | 主要功能是记录按键以捕获密码和其他敏感输入的恶意软件。 |
| bot | 将受感染机器连接到僵尸网络,用于 DDoS、垃圾邮件或其他协调攻击的软件。 |
| exploit | 利用软件特定漏洞获取未授权访问或执行的代码。 |
| unknown | avclass 标签无法清晰映射到单一高级类别的长尾家族。 |
类别分布
| 类别 | 家族数量 |
|---|---|
| unknown | 2,654 |
| trojan_generic | 67 |
| pua | 29 |
| rat | 23 |
| banking_trojan | 18 |
| adware | 17 |
| infostealer | 13 |
| file_infector | 9 |
| worm | 9 |
| pua_tool | 6 |
| packer | 6 |
| rogueware | 6 |
| spam_bot | 5 |
| ransomware | 5 |
| loader | 4 |
| downloader | 4 |
| click_fraud | 4 |
| worm_banker | 3 |
| browser_hijacker | 3 |
| cryptominer | 3 |
| generic_detection | 2 |
| ransomware_worm | 1 |
| ransomware_file_infector | 1 |
| ddos_bot | 1 |
| pos_malware | 1 |
| spyware | 1 |
| adware_botnet | 1 |
| trojan_tool | 1 |
| trojan | 1 |
| bootkit | 1 |
样本数量前50的恶意软件家族(前10名展示)
| 排名 | 家族名 | 类别 | 样本数量 |
|---|---|---|---|
| 1 | xtrat | rat | 35,969 |
| 2 | zbot | banking_trojan | 24,075 |
| 3 | ramnit | worm_banker | 20,595 |
| 4 | sality | file_infector | 18,572 |
| 5 | installmonster | pua | 16,691 |
| 6 | zusy | banking_trojan | 14,120 |
| 7 | emotet | loader | 12,943 |
| 8 | vtflooder | pua_tool | 12,150 |
| 9 | fareit | infostealer | 10,955 |
| 10 | adposhel | adware | 8,951 |
快速开始(代码示例)
python from datasets import load_dataset ds = load_dataset("Jordan123234/malware-families-catalog") print(ds["train"][0])
{family: emotet, sample_count: 12058, category: banker, description: ..., cta: ...}




