2SMaRT: A Two-Stage Machine Learning-Based Approach for Run-Time Specialized Hardware-Assisted Malware Detection

2SMaRT: A Two-Stage Machine Learning-Based Approach for Run-Time Specialized Hardware-Assisted Malware Detection
复制标题

2SMaRT:基于两阶段机器学习的运行时专用硬件辅助恶意软件检测方法

DOI:
10.23919/date.2019.8715080
复制
发表时间:
2019
期刊:
2019 Design, Automation & Test in Europe Conference & Exhibition (DATE)
影响因子:
--
通讯作者:
H. Homayoun
H. Homayoun
中科院分区:
--
文献类型:
--
作者:
H. Sayadi;Hosein Mohammadi Makrani;Sai Manoj Pudukotai Dinakarrao;T. Mohsenin;Avesta Sasan;S. Rafatirad;H. Homayoun

文献摘要

参考文献

被引文献

相似文献

硬件辅助恶意软件检测(HMD)已经成为一种利用在运行时收集的硬件性能计数器(HPC)信息来提高计算机系统安全性的有前途的解决方案。虽然最近的几项研究提出了基于机器学习的解决方案来识别使用HPC的恶意软件,但它们依赖于大量的微体系结构事件来实现高准确率和检测率。更重要的是,它们在很大程度上忽略了对运行时恶意软件类别的复杂性有效预测。正如我们在这项工作中所展示的,恶意软件分类器的检测性能高度依赖于可用HPC的数量,并且在不同类别的恶意软件之间存在显著差异。现代微处理器中可同时捕获的可用HPC数量有限,这使得使用现有解决方案具有高检测性能的运行时恶意软件检测成为一个具有挑战性的问题,因为它们需要多次运行应用程序来收集足够数量的微体系结构事件。对此,本文首先利用一种有效的特征约简方法识别出HMD中最重要的HPC。然后,我们开发了一种专门的两阶段运行时HMD,称为2SMaRT。2SMaRT首先使用多类分类技术将应用程序分类为良性或恶意软件类别(病毒、Rootkit、后门和特洛伊木马)。在第二阶段,为了有高的检测性能,2SMaRT部署了一个最适合每类恶意软件的机器学习模型。为了实现只依赖可用的HPC的有效运行时解决方案,2SMaRT使用集成学习技术进一步定制,以提高通用恶意软件检测器的性能。实验结果表明,在不同类别的恶意软件中,使用集成技术的2SMaRT在检测性能方面比使用8HPC的最先进的分类器高出31.25%。
Hardware-assisted Malware Detection (HMD) has emerged as a promising solution to improve the security of computer systems using Hardware Performance Counters (HPCs) information collected at run-time. While several recent studies proposed machine learning-based solutions to identify malware using HPCs, they rely on a large number of microarchitectural events to achieve high accuracy and detection rate. More importantly, they have largely overlooked complexity-effective prediction of malware classes at run-time. As we show in this work, the detection performance of malware classifiers is highly dependent on the number of available HPCs and varies significantly across classes of malware. The limited number of available HPCs in modern microprocessors that can be simultaneously captured makes run-time malware detection with high detection performance using existing solutions a challenging problem, as they require multiple runs of applications to collect a sufficient number of microarchitectural events. In response, in this paper, we first identify the most important HPCs for HMD using an effective feature reduction method. We then develop a specialized two-stage run-time HMD referred as 2SMaRT. 2SMaRT first classifies applications using a multiclass classification technique into either benign or one of the malware classes (Virus, Rootkit, Backdoor, and Trojan). In the second stage, to have a high detection performance, 2SMaRT deploys a machine learning model that works best for each class of malware. To realize an effective run-time solution that relies on only available HPCs, 2SMaRT is further customized using an ensemble learning technique to boost the performance of general malware detectors. The experimental results show that 2SMaRT using ensemble technique with just 4HPCs outperforms state-of-the-art classifiers with 8HPCs by up to 31.25% in terms of detection performance, on average across different classes of malware.
LUT-Lock:一种新颖的基于 LUT 的逻辑混淆,用于 FPGA 比特流和 ASIC 硬件保护
DOI: 10.1109/isvlsi.2018.00080
发表时间: 2018
期刊: 2018 IEEE Computer Society Annual Symposium on VLSI (ISVLSI
影响因子: --
作者:
Mardani Kamali, Hadi;Zamiri Azar, Kimia;Gaj, Kris;Homayoun, Houman;Sasan, Avesta
通讯作者: Sasan, Avesta