Performance Monitoring Counter Based Intelligent Malware Detection and Design Alternatives

Performance Monitoring Counter Based Intelligent Malware Detection and Design Alternatives
复制标题

基于性能监控计数器的智能恶意软件检测和设计替代方案

DOI:
10.1109/access.2022.3157812
复制
发表时间:
2022
期刊:
影响因子:
3.9
通讯作者:
Byeong Kil Lee
Byeong Kil Lee
中科院分区:
计算机科学3区
文献类型:
--
作者:
Jordan Pattee;Shafayat Mowla Anik;Byeong Kil Lee

文献摘要

被引文献

相似文献

用于恶意软件检测的硬件解决方案正变得越来越重要,因为基于软件的解决方案很容易受到智能恶意软件的危害。然而,硬件解决方案的成本,包括设计复杂性和动态功耗是不可忽视的。许多现有的硬件解决方案都是基于统计学习块,具有系统调用、网络流量或处理器行为的异常特征。在这些解决方案中,学习技术的性能主要依赖于训练数据的质量。然而,对于基于处理器行为的解决方案,由于处理器中性能监视计数器(PMC)的数量有限,因此只能同时监视少数行为事件。因此,从架构特征获得的数据的质量和数量已经成为基于PMC的恶意软件检测的关键问题。在本文中,为了强调选择恶意软件检测的架构特征的重要性,恶意软件工作负载和良性工作负载之间的统计差异的特征的基础上,从性能计数器的信息。大多数恶意软件都可以通过基本特征轻松检测到,但某些恶意软件类型在统计上与良性工作负载非常相似,需要更深入地处理。因此,我们专注于多个步骤来研究基于PMC的恶意软件检测的关键问题:(i)恶意软件的统计特征;(ii)基于分布的特征选择;(iii)检测时间和准确性的权衡分析;以及(iv)为基于硬件的恶意软件检测提供架构设计方案。我们的研究结果表明,现有的性能计数器的数量是不够的,以达到所需的准确性。为了更准确地实时检测恶意软件,我们提出了两个准确性改进方案(与额外的PMC等)。和硬件加速方案。这两种方案在增加硬件成本(不到芯片复杂度的1%)的情况下,检测精度提高了5~10%,检测速度提高了10%。
Hardware solutions for malware detection are becoming increasingly important as software-based solutions can be easily compromised by intelligent malware. However, the cost of hardware solutions including design complexity and dynamic power consumption cannot be ignored. Many of the existing hardware solutions are based on statistical learning blocks with abnormal features of system calls, network traffics, or processor behaviors. Among those solutions, the performance of the learning techniques relies primarily on the quality of the training data. However, for the processor behavior-based solutions, only a few behavioral events can be monitored simultaneously due to the limited number of PMCs (Performance Monitoring Counters) in a processor. As a result, the quality and quantity of the data obtained from architectural features have become a critical issue for PMC-based malware detection. In this paper, to emphasize the importance of selecting architectural features for malware detection, the statistical differences between malware workloads and benign workloads were characterized based on the information from performance counters. Most malware can easily be detected with basic characteristics, but some malware types are statistically very similar to benign workloads which need to be handled more in-depth. Hence, we focus on multiple steps to investigate critical issues of PMC-based malware detection: (i) statistical characterization of malware; (ii) distribution-based feature selection; (iii) trade-off analysis of detection time and accuracy; and (iv) providing architectural design alternatives for hardware-based malware detection. Our results show that the existing number of performance counters is not enough to achieve the desired accuracy. For more accurate malware detection in real-time, we propose both accuracy improvement schemes (with additional PMCs, etc.) and hardware acceleration schemes. Both schemes provide accuracy improvement (5~10%) and detection speedup (up to 10%) with the additional hardware cost (less than 1% of the chip complexity).