Explainable Machine Learning for Intrusion Detection via Hardware Performance Counters

Explainable Machine Learning for Intrusion Detection via Hardware Performance Counters
复制标题

通过硬件性能计数器进行入侵检测的可解释机器学习

DOI:
--
复制
发表时间:
2022
影响因子:
2.9
通讯作者:
K. Basu
K. Basu
中科院分区:
计算机科学3区
文献类型:
--
作者:
Abraham Peedikayil Kuruvila;Xingyu Meng;Shamik Kundu;Gaurav Pandey;K. Basu

文献摘要

参考文献

被引文献

相似文献

在过去的十年中,恶意软件的指数级增长已经威胁到了大量物联网(IoT)设备的系统安全。此外,计算机体系结构的改进包括推测性分支和乱序执行,这为对手在这些设备中进行微体系结构攻击提供了新的机会。恶意软件和微架构攻击都是对计算系统的迫切威胁,因为它们的行为范围从窃取敏感数据到整个系统故障。反病毒软件(AVS)和攻击者之间的猫捉老鼠游戏,AVS的频繁支持导致了巨大的计算开销。因此,基于硬件性能计数器(HPC)的检测策略(通过机器学习(ML)分类器进行增强)作为识别这些恶意威胁的低开销解决方案而受到欢迎。然而,机器学习模型是作为黑盒子运行的,这导致了人类无法理解的决策。模型结果的清晰度有助于开发更强大的系统。现有的可解释的框架只能确定每个功能的预测,这并不提供有意义的可解释的结果,基于HPC的入侵检测的影响。在本文中,我们通过提出一个可解释的基于HPC的双重回归(HPCDR)ML框架来解决这个问题。我们提出的技术提供了相关的透明度,通过隔离的应用程序的最恶意的瞬态窗口,从而允许用户有效地定位程序内的有害指令。我们评估了HPCDR的五个微架构攻击和两个恶意软件。HPCDR能够成功识别每个入侵应用程序中表现出的最恶意的功能。
The exponential proliferation of Malware over the past decade has threatened system security across a plethora of Internet of Things (IoT) devices. Furthermore, the improvements in computer architectures to include speculative branching and out-of-order executions have engendered new opportunities for adversaries to carry out microarchitectural attacks in these devices. Both Malware and microarchitectural attacks are imperative threats to computing systems, as their behaviors range from stealing sensitive data to total system failure. With the cat-and-mouse game between Anti-Virus Software (AVS) and attackers, the frequent bolstering of AVS induces large computational overhead. Consequently, hardware performance counter (HPC)-based detection strategies augmented with machine learning (ML) classifiers have gained popularity as a low overhead solution in identifying these malicious threats. However, ML models are operated as black boxes, which results in decisions that are not human understandable. Clarity of the models’ results facilitates the development of more robust systems. Existing explainable frameworks are only capable of determining each feature’s impact on a prediction which does not provide meaningful interpretable outcomes for HPC-based intrusion detection. In this article, we address this issue by proposing an explainable HPC-based double regression (HPCDR) ML framework. Our proposed technique provides relevant transparency through isolation of the most malevolent transient window of an application, thereby allowing a user to efficiently locate the pernicious instructions within the program. We evaluated HPCDR on five microarchitectural attacks and two Malware. HPCDR was successfully able to identify the most malicious function manifested in each intrusive application.
检测“逃避的幽灵”的挑战
DOI: 10.1109/lca.2020.2976069
发表时间: 2020
影响因子: 2.3
作者:
Li, Congmiao;Gaudiot, Jean-Luc
通讯作者: Gaudiot, Jean-Luc
使用硬件性能计数器检测幽灵攻击
DOI: 10.1109/tc.2021.3082471
发表时间: 2022
影响因子: 3.7
作者:
Li, Congmiao;Gaudiot, Jean-Luc
通讯作者: Gaudiot, Jean-Luc
使用可解释的机器学习进行硬件辅助恶意软件检测
DOI: 10.1109/iccd50377.2020.00113
发表时间: 2020
期刊: International Conference on Computer Design (ICCD
影响因子: --
作者:
Pan, Zhixin;Sheldon, Jennifer;Mishra, Prabhat
通讯作者: Mishra, Prabhat