When Machine Learning Meets Hardware Cybersecurity: Delving into Accurate Zero-Day Malware Detection

When Machine Learning Meets Hardware Cybersecurity: Delving into Accurate Zero-Day Malware Detection
复制标题

当机器学习遇到硬件网络安全:深入研究准确的零日恶意软件检测

DOI:
--
复制
发表时间:
2021
期刊:
IEEE International Symposium on Quality Electronic Design
影响因子:
--
通讯作者:
H. Sayadi
H. Sayadi
中科院分区:
--
文献类型:
--
作者:
Z. He;Tahereh Miari;Hosein Mohammadi Makrani;Mehrdad Aliasgari;H. Homayoun;H. Sayadi

文献摘要

参考文献

被引文献

相似文献

过去几十年来,网络安全作为对信息技术基础设施的重大威胁一直处于全球关注的前沿。根据最近的安全报告,恶意软件(又称恶意软件)的数量正在以惊人的速度增长,其有害目的也损害了计算系统的安全。为了解决传统基于软件的检测技术的高复杂性和计算开销问题,事实证明,借助应用于硬件性能计数器 (HPC) 数据的机器学习 (ML) 技术,硬件支持的恶意软件检测 (HMD) 可以有效地在处理器微架构级别检测恶意软件。现有的基于 ML 的 HMD 虽然能够准确识别恶意模式的已知签名,但尚未探索在运行时检测未知(零日)恶意软件数据,这是一个更具挑战性的问题,因为其 HPC 数据与现有数据库中任何已知攻击应用程序的签名不匹配。在这项工作中,我们首先回顾了最近利用内置 HPC 寄存器信息的基于 ML 的 HMD。接下来,我们检查各种标准 ML 分类器对于零日恶意软件检测的适用性,并证明此类方法无法以高检测率检测未知的恶意软件签名。最后,为了解决运行时零日恶意软件检测的挑战,我们提出了一种基于集成学习的技术,以增强标准恶意软件检测器的性能,尽管使用了现有 HPC 在运行时捕获的少量微架构特征。实验结果表明,我们提出的方法通过在随机 Forrest 分类器上应用 AdaBoost 集成学习作为常规分类器,在仅使用前 4 个微架构特征检测零日恶意软件时,实现了 92% 的 F 测量和 95% 的 TPR,误报率仅为 2%。
Cybersecurity for the past decades has been in the front line of global attention as a critical threat to the information technology infrastructures. According to recent security reports, malicious software (a.k.a. malware) is rising at an alarming rate in numbers as well as harmful purposes to compromise security of computing systems. To address the high complexity and computational overheads of conventional software-based detection techniques, Hardware-Supported Malware Detection (HMD) has proved to be efficient for detecting malware at the processors’ microarchitecture level with the aid of Machine Learning (ML) techniques applied on Hardware Performance Counter (HPC) data. Existing ML-based HMDs while accurate in recognizing known signatures of malicious patterns, have not explored detecting unknown (zero-day) malware data at run-time which is a more challenging problem, since its HPC data does not match any known attack applications’ signatures in the existing database. In this work, we first present a review of recent ML-based HMDs utilizing built-in HPC registers information. Next, we examine the suitability of various standard ML classifiers for zero-day malware detection and demonstrate that such methods are not capable of detecting unknown malware signatures with high detection rate. Lastly, to address the challenge of run-time zero-day malware detection, we propose an ensemble learning-based technique to enhance the performance of the standard malware detectors despite using a small number of microarchitectural features that are captured at run-time by existing HPCs. The experimental results demonstrate that our proposed approach by applying AdaBoost ensemble learning on Random Forrest classifier as a regular classifier achieves 92% F-measure and 95% TPR with only 2% false positive rate in detecting zero-day malware using only the top 4 microarchitectural features.
DOI: 10.1109/mwscas48704.2020.9184539
发表时间: 2020
期刊: 2020 IEEE 63rd International Midwest Symposium on Circuits and Systems (MWSCAS
影响因子: --
作者:
Sayadi, Hossein;Wang, Han;Miari, Tahereh;Makrani, Hosein Mohammadi;Aliasgari, Mehrdad;Rafatirad, Setareh;Homayoun, Houman
通讯作者: Homayoun, Houman
StealthMiner:基于微架构特征的运行时隐形恶意软件检测的专业时间序列机器学习
DOI: 10.1145/3386263.3407585
发表时间: 2020
期刊: Proceedings of 2020 Great Lakes Symposium on VLSI (GLSVLSI'20
影响因子: --
作者:
Sayadi, Hossein;Gao, Yifeng;Mohammadi Makrani, Hosein;Mohsenin, Tinoosh;Sasan, Avesta;Rafatirad, Setareh;Lin, Jessica;Homayoun, Houman
通讯作者: Homayoun, Houman