Malware detection using machine learning based analysis of virtual memory access patterns

Malware detection using machine learning based analysis of virtual memory access patterns
复制标题

DOI:
10.23919/date.2017.7926977
复制
发表时间:
2017-03
期刊:
Design, Automation & Test in Europe Conference & Exhibition (DATE), 2017
影响因子:
--
通讯作者:
Zhixing Xu;Sayak Ray;P. Subramanyan;S. Malik
Zhixing Xu;Sayak Ray;P. Subramanyan;S. Malik
中科院分区:
其他
文献类型:
--
作者:
Zhixing Xu;Sayak Ray;P. Subramanyan;S. Malik

文献摘要

被引文献

相似文献

被称为恶意软件的恶意软件在复杂性上持续增长。过去的恶意软件检测提案主要集中在基于软件的检测器上,这些检测器容易受到损害。因此,最近的工作提出了硬件辅助的恶意软件检测。在本文中,我们介绍了一个新的框架,硬件辅助的恶意软件检测的基础上监测和分类的内存访问模式,使用机器学习。这通过减少用户对特定恶意软件签名的输入来提高自动化和覆盖率。我们的工作背后的关键见解是,恶意软件必须改变控制流和/或数据结构,这会在程序内存访问上留下指纹。在此基础上,我们提出了一个在线框架,用于检测恶意软件,使用机器学习来分类基于虚拟内存访问模式的恶意行为。该框架的新方面包括用于收集和总结每个函数/系统调用的内存访问模式的技术,以及两级分类架构。我们的实验评估集中在两个重要类别的恶意软件(i)内核rootkit和(ii)对用户程序的内存损坏攻击。该框架的检测率为99.0%,误报率低于5%,优于以前的硬件辅助恶意软件检测提案。
Malicious software, referred to as malware, continues to grow in sophistication. Past proposals for malware detection have primarily focused on software-based detectors which are vulnerable to being compromised. Thus, recent work has proposed hardware-assisted malware detection. In this paper, we introduce a new framework for hardware-assisted malware detection based on monitoring and classifying memory access patterns using machine learning. This provides for increased automation and coverage through reducing user input on specific malware signatures. The key insight underlying our work is that malware must change control flow and/or data structures, which leaves fingerprints on program memory accesses. Building on this, we propose an online framework for detecting malware that uses machine learning to classify malicious behavior based on virtual memory access patterns. Novel aspects of the framework include techniques for collecting and summarizing per-function/system-call memory access patterns, and a two-level classification architecture. Our experimental evaluation focuses on two important classes of malware (i) kernel rootkits and (ii) memory corruption attacks on user programs. The framework has a detection rate of 99.0% with less than 5% false positives and outperforms previous proposals for hardware-assisted malware detection.