When Machine Learning Meets Hardware Cybersecurity: Delving into Accurate Zero-Day Malware Detection
When Machine Learning Meets Hardware Cybersecurity: Delving into Accurate Zero-Day Malware Detection
复制标题
当机器学习遇到硬件网络安全:深入研究准确的零日恶意软件检测
DOI:
--
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
H. Sayadi
中科院分区:
文献类型:
--
作者:
Z. He;Tahereh Miari;Hosein Mohammadi Makrani;Mehrdad Aliasgari;H. Homayoun;H. Sayadi
Cybersecurity for the past decades has been in the front line of global attention as a critical threat to the information technology infrastructures. According to recent security reports, malicious software (a.k.a. malware) is rising at an alarming rate in numbers as well as harmful purposes to compromise security of computing systems. To address the high complexity and computational overheads of conventional software-based detection techniques, Hardware-Supported Malware Detection (HMD) has proved to be efficient for detecting malware at the processors’ microarchitecture level with the aid of Machine Learning (ML) techniques applied on Hardware Performance Counter (HPC) data. Existing ML-based HMDs while accurate in recognizing known signatures of malicious patterns, have not explored detecting unknown (zero-day) malware data at run-time which is a more challenging problem, since its HPC data does not match any known attack applications’ signatures in the existing database. In this work, we first present a review of recent ML-based HMDs utilizing built-in HPC registers information. Next, we examine the suitability of various standard ML classifiers for zero-day malware detection and demonstrate that such methods are not capable of detecting unknown malware signatures with high detection rate. Lastly, to address the challenge of run-time zero-day malware detection, we propose an ensemble learning-based technique to enhance the performance of the standard malware detectors despite using a small number of microarchitectural features that are captured at run-time by existing HPCs. The experimental results demonstrate that our proposed approach by applying AdaBoost ensemble learning on Random Forrest classifier as a regular classifier achieves 92% F-measure and 95% TPR with only 2% false positive rate in detecting zero-day malware using only the top 4 microarchitectural features.
DOI:
10.1109/mwscas48704.2020.9184539
发表时间:
2020
期刊:
2020 IEEE 63rd International Midwest Symposium on Circuits and Systems (MWSCAS
影响因子:
--
作者:
Sayadi, Hossein;Wang, Han;Miari, Tahereh;Makrani, Hosein Mohammadi;Aliasgari, Mehrdad;Rafatirad, Setareh;Homayoun, Houman
通讯作者:
Homayoun, Houman
DOI:
10.1145/3386263.3407585
发表时间:
2020
期刊:
Proceedings of 2020 Great Lakes Symposium on VLSI (GLSVLSI'20
影响因子:
--
作者:
Sayadi, Hossein;Gao, Yifeng;Mohammadi Makrani, Hosein;Mohsenin, Tinoosh;Sasan, Avesta;Rafatirad, Setareh;Lin, Jessica;Homayoun, Houman
通讯作者:
Homayoun, Houman