Hardware-Assisted Malware Detection and Localization Using Explainable Machine Learning

Hardware-Assisted Malware Detection and Localization Using Explainable Machine Learning
复制标题

DOI:
10.1109/tc.2022.3150573
复制
发表时间:
2022-12
影响因子:
3.7
通讯作者:
Zhixin Pan;Jennifer Sheldon;P. Mishra
Zhixin Pan;Jennifer Sheldon;P. Mishra
中科院分区:
计算机科学2区
文献类型:
--
作者:
Zhixin Pan;Jennifer Sheldon;P. Mishra

文献摘要

相似文献

恶意软件,通常被称为恶意软件,被广泛认为是对现代计算系统的严重威胁。基于软件的解决方案,如防病毒软件(AVS),是无效的,因为它们依赖于匹配的模式,可以很容易地被精心制作的恶意软件与混淆或其他偏差功能愚弄。虽然最近的恶意软件检测方法通过有效利用硬件特征提供了有希望的结果,但检测结果不能以有意义的方式解释。在本文中,我们提出了一个硬件辅助的恶意软件检测框架,使用可解释的机器学习。本文作出了三个重要贡献。首先,我们从理论上确定,我们提出的方法可以提供一个可解释的分类结果,以解决透明度的挑战。接下来,我们表明,通过有效利用硬件性能计数器和嵌入式跟踪缓冲区的可解释的结果可以导致准确定位的恶意行为。最后,我们使用决策树和递归神经网络进行了效率与精度的权衡分析。使用各种真实世界的恶意软件数据集进行的广泛评估表明,我们的框架可以产生准确和人类可理解的恶意软件检测结果,并具有可证明的保证。
Malicious software, popularly known as malware, is widely acknowledged as a serious threat to modern computing systems. Software-based solutions, such as anti-virus software (AVS), are not effective since they rely on matching patterns that can be easily fooled by carefully crafted malware with obfuscation or other deviation capabilities. While recent malware detection methods provide promising results through an effective utilization of hardware features, the detection results cannot be interpreted in a meaningful way. In this paper, we propose a hardware-assisted malware detection framework using explainable machine learning. This paper makes three important contributions. First, we theoretically establish that our proposed method can provide an interpretable explanation of classification results to address the challenge of transparency. Next, we show that the explainable outcome through effective utilization of hardware performance counters and embedded trace buffer can lead to accurate localization of malicious behavior. Finally, we have performed efficiency versus accuracy trade-off analysis using decision tree and recurrent neural networks. Extensive evaluation using a wide variety of real-world malware dataset demonstrates that our framework can produce accurate and human-understandable malware detection results with provable guarantees.