Adversarial Machine Learning in Malware Detection: Arms Race between Evasion Attack and Defense

Adversarial Machine Learning in Malware Detection: Arms Race between Evasion Attack and Defense
复制标题

DOI:
10.1109/eisic.2017.21
复制
发表时间:
2017-09
期刊:
2017 European Intelligence and Security Informatics Conference (EISIC)
影响因子:
--
通讯作者:
Lingwei Chen;Yanfang Ye;T. Bourlai
Lingwei Chen;Yanfang Ye;T. Bourlai
中科院分区:
其他
文献类型:
--
作者:
Lingwei Chen;Yanfang Ye;T. Bourlai

文献摘要

被引文献

相似文献

由于恶意软件对计算机和互联网用户造成了严重的损害和不断发展的威胁,因此它的检测对反恶意软件行业和研究人员都具有极大的兴趣。近年来,基于机器学习的系统已经成功地部署在恶意软件检测中,其中基于使用不同特征表示的训练样本构建不同类型的分类器。不幸的是,随着分类器越来越广泛地部署,击败它们的动机也越来越强。在本文中,我们探讨了恶意软件检测中的对抗机器学习。特别是,一个基于学习的分类器的基础上,Windows应用程序编程接口(API)调用提取的可移植可执行文件(PE)的输入,我们提出了一个有效的规避攻击模型(命名为EvnAttack),通过考虑不同的贡献的功能分类问题。为了抵御规避攻击,我们进一步提出了一个安全学习的恶意软件检测范式(名为SecDefender),它不仅采用分类器再训练技术,而且还引入了安全正则化项,该项考虑了攻击者操作特征的规避成本,以提高系统的安全性。在Comodo云安全中心的真实的样本集上的综合实验结果证明了所提方法的有效性。
Since malware has caused serious damages and evolving threats to computer and Internet users, its detection is of great interest to both anti-malware industry and researchers. In recent years, machine learning-based systems have been successfully deployed in malware detection, in which different kinds of classifiers are built based on the training samples using different feature representations. Unfortunately, as classifiers become more widely deployed, the incentive for defeating them increases. In this paper, we explore the adversarial machine learning in malware detection. In particular, on the basis of a learning-based classifier with the input of Windows Application Programming Interface (API) calls extracted from the Portable Executable (PE) files, we present an effective evasion attack model (named EvnAttack) by considering different contributions of the features to the classification problem. To be resilient against the evasion attack, we further propose a secure-learning paradigm for malware detection (named SecDefender), which not only adopts classifier retraining technique but also introduces the security regularization term which considers the evasion cost of feature manipulations by attackers to enhance the system security. Comprehensive experimental results on the real sample collections from Comodo Cloud Security Center demonstrate the effectiveness of our proposed methods.