StealthMiner: Specialized Time Series Machine Learning for Run-Time Stealthy Malware Detection based on Microarchitectural Features

StealthMiner: Specialized Time Series Machine Learning for Run-Time Stealthy Malware Detection based on Microarchitectural Features
复制标题

StealthMiner:基于微架构特征的运行时隐形恶意软件检测的专业时间序列机器学习

DOI:
10.1145/3386263.3407585
复制
发表时间:
2020
期刊:
Proceedings of 2020 Great Lakes Symposium on VLSI (GLSVLSI'20
影响因子:
--
通讯作者:
Homayoun, Houman
Homayoun, Houman
中科院分区:
--
文献类型:
--
作者:
Sayadi, Hossein;Gao, Yifeng;Mohammadi Makrani, Hosein;Mohsenin, Tinoosh;Sasan, Avesta;Rafatirad, Setareh;Lin, Jessica;Homayoun, Houman

文献摘要

参考文献

被引文献

相似文献

硬件辅助恶意软件检测 (HMD) 技术部署机器学习 (ML) 分类器,根据现代微处理器的硬件性能计数器 (HPC) 捕获的微架构特征来检测恶意应用程序的模式。现有的 HMD 方法限制了其对检测在应用程序执行期间作为单独线程生成的恶意应用程序的分析,因此在运行时检测嵌入式恶意软件模式仍然是一个重要的挑战。嵌入式恶意软件是指有害的隐形网络攻击,其中恶意代码隐藏在良性应用程序中,并且传统的恶意软件检测方法无法检测到。在 HMD 方法中,当 HPC 数据直接输入机器学习分类器时,在良性应用程序中嵌入恶意代码会导致 HPC 信息污染,因为收集的 HPC 特征将良性和恶意软件微架构事件结合在一起。为了应对这一挑战,在本文中,我们提出了 StealthMiner,这是一种专门的时间序列机器学习方法,可使用分支指令功能(最突出的微架构功能)在运行时准确检测嵌入式恶意软件。结果表明,StealthMiner 只需一项 HPC 功能即可在运行时检测嵌入式恶意软件,平均检测性能为 94%,比最先进的 HMD 方法的检测性能高出 42%。
Hardware-Assisted Malware Detection (HMD) techniques deploy Machine Learning (ML) classifiers to detect patterns of malicious applications based on microarchitectural features captured by modern microprocessors' Hardware Performance Counters (HPCs). Existing HMD methods have limited their analysis on detecting malicious applications that are spawned as a separate thread during application execution, hence detecting embedded malware patterns at run-time still remains an important challenge. Embedded malware refers to harmful stealthy cyber attacks in which the malicious code is hidden within benign applications and remains undetected by traditional malware detection approaches. In HMD methods, when the HPC data is directly fed into a machine learning classifier, embedding malicious code inside the benign applications leads to contamination of HPC information, as the collected HPC features combine benign and malware microarchitectural events together. To address this challenge, in this paper we propose StealthMiner, a specialized time series machine learning approach to accurately detect embedded malware at run-time using branch instructions feature, the most prominent microarchitectural feature. The results indicate that StealthMiner can detect embedded malware at run-time with 94% detection performance on average with only one HPC feature, outperforming the detection performance of state-of-the-art HMD methods by 42%.
SCARF:使用低级硬件功能实时检测侧信道攻击
DOI: 10.1109/iolts50870.2020.9159708
发表时间: 2020
期刊: IEEE International Symposium on On-Line Testing and Robust System Design
影响因子: --
作者:
Wang, Han;Sayadi, Hossein;Rafatirad, Setareh;Sasan, Avesta;Homayoun, Houman
通讯作者: Homayoun, Houman
DOI: 10.1109/tc.2019.2945767
发表时间: 2020-03
影响因子: 3.7
作者:
Nader Sehatbakhsh;A. Nazari;Monjur Alam;Frank T. Werner;Yuanda Zhu;A. Zajić;Milos Prvulović
通讯作者: Nader Sehatbakhsh;A. Nazari;Monjur Alam;Frank T. Werner;Yuanda Zhu;A. Zajić;Milos Prvulović
基于 FPGA 的多加速器的可扩展多队列数据传输方案
DOI: --
发表时间: 2018
期刊: ICCD
影响因子: --
作者:
Siavash Rezaei;Kanghee Kim;E. Bozorgzadeh
通讯作者: E. Bozorgzadeh
DOI: --
发表时间: 2018
期刊:
影响因子: --
作者:
山本恵美子; 田中共子; 兵藤好美; 片山はるみ;2.著者名 山本恵美子・田中共子・兵藤好美・畠中香織;山本恵美子,田中共子,兵藤好美,畠中香織;兵藤好美,柘野浩子;兵藤好美,柘野浩子;兵藤好美,柘野浩子;兵藤好美,柘野浩子;兵藤好美,柘野浩子;兵藤好美,柘野浩子;兵藤好美,柘野浩子;兵藤好美,柘野浩子;兵藤好美,柘野浩子;兵藤好美,柘野浩子;兵藤好美,柘野浩子;兵藤好美,柘野浩子;兵藤好美・田中共子;柘野浩子・兵藤好美;兵藤好美・中村美枝子・田中共子
通讯作者: 兵藤好美・中村美枝子・田中共子
2SMaRT:基于两阶段机器学习的运行时专用硬件辅助恶意软件检测方法
DOI: 10.23919/date.2019.8715080
发表时间: 2019
期刊: 2019 Design, Automation & Test in Europe Conference & Exhibition (DATE)
影响因子: --
作者:
H. Sayadi;Hosein Mohammadi Makrani;Sai Manoj Pudukotai Dinakarrao;T. Mohsenin;Avesta Sasan;S. Rafatirad;H. Homayoun
通讯作者: H. Homayoun