Fast and Accurate Machine Learning-based Malware Detection via RC4 Ciphertext Analysis*

Fast and Accurate Machine Learning-based Malware Detection via RC4 Ciphertext Analysis*
复制标题

通过 RC4 密文分析进行快速、准确的基于机器学习的恶意软件检测*

DOI:
--
复制
发表时间:
2019
期刊:
International Conference on Computing, Networking and Communications
影响因子:
--
通讯作者:
Mingon Kang
Mingon Kang
中科院分区:
--
文献类型:
--
作者:
Junggab Son;Euiseong Ko;Uday Bhaskar Boyanapalli;Donghyun Kim;Youngsoon Kim;Mingon Kang

文献摘要

参考文献

被引文献

相似文献

最近的恶意软件通过采用有助于隐藏恶意意图和/或行为的密码来提高其生存能力。到目前为止,已经做出了许多努力来检测恶意软件,并通过监控网络数据包来防止它破坏客户端。然而,由于从密文中提取信息的难度,这些传统的检测方案倾向于将加密的分组视为合法的。对网络上的每个数据包进行加密分析可能是解决这个问题的一个可行的方法。然而,这种方法在计算上是昂贵的并且缺乏准确性,因此它不是实际的解决方案。为了解决这个问题,我们首先介绍了一个发现,一个固定的加密密钥产生的唯一的统计模式的RC 4密文。据我们所知,这种独特的签名从未在文献中讨论过。然后,我们提出了一个基于机器学习的检测方案,可以有效地识别恶意软件包,准确地利用发现。该方案直接分析网络数据包而不需要解密密文。此外,我们的分析表明,该方案只需要一个很小的网络数据包的子集。
Recent malware increases its viability by employing ciphers which help to hide malicious intention and/or behavior against detection schemes. So far, many efforts have been made to detect malware and to prevent it from damaging clients by monitoring network packets. However, these conventional detection schemes tend to treat an encrypted packet as legitimate due to the hardness of extracting information from ciphertexts. Cryptoanalysis of each packet flowing over a network might be one feasible solution to the problem. However, this approach is computationally expensive and lacks accuracy, and thus it is consequently not a practical solution. To address the problem, we firstly introduce a discovery that a fixed encryption key generates unique statistical patterns on RC4 ciphertexts. To the best of our knowledge, this unique signature has never been discussed in the literature. Then, we propose a machine learning-based detection scheme that can identify malware packets efficiently and accurately by leveraging the discovery. The proposed scheme directly analyze network packets without decrypting ciphertexts. Moreover, our analysis demonstrates the proposed scheme requires only a tiny subset of the network packet.
使用隐写分析检测加壳的可执行文件
DOI: 10.1109/euvip.2014.7018361
发表时间: 2014
期刊: --
影响因子: --
作者:
Burgess C
通讯作者: Burgess C