EVOLIoT: A Self-Supervised Contrastive Learning Framework for Detecting and Characterizing Evolving IoT Malware Variants

EVOLIoT: A Self-Supervised Contrastive Learning Framework for Detecting and Characterizing Evolving IoT Malware Variants
复制标题

DOI:
10.1145/3488932.3517393
复制
发表时间:
2022-05
期刊:
Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Mirabelle Dib;Sadegh Torabi;E. Bou-Harb;N. Bouguila;C. Assi
Mirabelle Dib;Sadegh Torabi;E. Bou-Harb;N. Bouguila;C. Assi
中科院分区:
其他
文献类型:
--
作者:
Mirabelle Dib;Sadegh Torabi;E. Bou-Harb;N. Bouguila;C. Assi

文献摘要

相似文献

近年来,针对物联网的新的、更复杂的恶意软件不断涌现。此外,Mirai等流行恶意软件家族的源代码的公开发布催生了各种变体,使得澄清它们的所有权、血统和正确标签变得更加困难。这种快速发展的环境也使部署和推广有效的学习模型以应对已停用、更新和/或新的威胁活动变得更加困难。本文提出了一种新的方法EVOLIoT,旨在通过检测漂移物联网恶意软件家族并了解其不同的演化轨迹来对抗概念漂移和家族间物联网恶意软件分类的局限性。我们介绍了一种稳健而有效的对比方法,该方法学习和比较物联网恶意软件二进制和代码的语义有意义的表示,而不需要昂贵的目标标签。我们发现,物联网二进制文件的演化可以作为一种增强策略来学习有效的表示,以对比(区分)相似的变体对。我们讨论了分析的影响和结果,并提供了几项评估研究,以突出物联网恶意软件的错综复杂的关系,以及我们通过对比学习的特征向量在跨架构物联网恶意软件二进制文件中保留语义和减少词汇表外大小方面的效率。
Recent years have witnessed the emergence of new and more sophisticated malware targeting the Internet of Things. Moreover, the public release of the source code of popular malware families such as Mirai has spawned diverse variants, making it harder to disambiguate their ownership, lineage, and correct label. Such a rapidly evolving landscape makes it also harder to deploy and generalize effective learning models against retired, updated, and/or new threat campaigns. In this paper, we present EVOLIoT, a novel approach aiming at combating "concept drift" and the limitations of inter-family IoT malware classification by detecting drifting IoT malware families and understanding their diverse evolutionary trajectories. We introduce a robust and effective contrastive method that learns and compares semantically meaningful representations of IoT malware binaries and codes without the need for expensive target labels. We find that the evolution of IoT binaries can be used as an augmentation strategy to learn effective representations to contrast (dis)similar variant pairs. We discuss the impact and findings of our analysis and present several evaluation studies to highlight the tangled relationships of IoT malware, as well as the efficiency of our contrastively learned feature vectors in preserving semantics and reducing out-of-vocabulary size in cross-architecture IoT malware binaries.