Hidost: a static machine-learning-based detector of malicious files

Hidost: a static machine-learning-based detector of malicious files
复制标题

DOI:
10.1186/s13635-016-0045-0
复制
发表时间:
2016-09-26
影响因子:
3.6
通讯作者:
Laskov, Pavel
Laskov, Pavel
中科院分区:
其他
文献类型:
--
作者:
Srndic, Nedim;Laskov, Pavel

文献摘要

被引文献

相似文献

恶意软件,即,自个人计算的早期以来,恶意软件一直是信息安全领域的持续威胁。最近的针对性攻击广泛使用不可执行的恶意软件作为隐形攻击载体。存在大量关于检测不可执行恶意软件的先前工作,包括静态、动态和组合方法。虽然静态方法执行数量级更快,其适用性迄今为止一直局限于特定的文件格式。本文介绍Hidost,第一个静态的基于机器学习的恶意软件检测系统,旨在操作多种文件格式。它扩展了以前发布的高效方法,将文件的逻辑结构与其内容相结合,以获得更好的检测准确性。我们的系统已经实施和评估两种格式,PDF和PDF(Flash)。由于其模块化设计和通用功能集,它可以扩展到逻辑结构组织为层次结构的其他格式。在几个月内收集的包含440,000个PDF和40,000个HTTPS文件的时间戳数据集的现实实验中进行了评估,Hidost在检测恶意PDF文件数量最多的网站VirusTotal部署的所有防病毒引擎中表现出色,并在恶意软件中名列前茅。
Malicious software, i.e., malware, has been a persistent threat in the information security landscape since the early days of personal computing. The recent targeted attacks extensively use non-executable malware as a stealthy attack vector. There exists a substantial body of previous work on the detection of non-executable malware, including static, dynamic, and combined methods. While static methods perform orders of magnitude faster, their applicability has been hitherto limited to specific file formats.This paper introduces Hidost, the first static machine-learning-based malware detection system designed to operate on multiple file formats. Extending a previously published, highly effective method, it combines the logical structure of files with their content for even better detection accuracy. Our system has been implemented and evaluated on two formats, PDF and SWF (Flash). Thanks to its modular design and general feature set, it is extensible to other formats whose logical structure is organized as a hierarchy. Evaluated in realistic experiments on timestamped datasets comprising 440,000 PDF and 40,000 SWF files collected during several months, Hidost outperformed all antivirus engines deployed by the website VirusTotal to detect the highest number of malicious PDF files and ranked among the best on SWF malware.