Analyzing and Detecting Emerging Internet of Things Malware: A Graph-Based Approach

Analyzing and Detecting Emerging Internet of Things Malware: A Graph-Based Approach
复制标题

DOI:
10.1109/jiot.2019.2925929
复制
发表时间:
2019-10-01
影响因子:
10.6
通讯作者:
Mohaisen, Aziz
Mohaisen, Aziz
中科院分区:
计算机科学1区
文献类型:
--
作者:
Alasmary, Hisham;Khormali, Aminollah;Mohaisen, Aziz

文献摘要

被引文献

相似文献

随着物联网(IoT)设备数量的稳步增长,针对这些设备的恶意软件(malware)数量也在等量增长。在本文中,我们利用控制流图(CFGs)构建了一种物联网恶意软件的检测机制。为了激励我们的检测机制,我们将物联网恶意软件的潜在特征与其他类型的恶意软件(android恶意软件)进行了对比,这些恶意软件也是基于linux的,具有多种功能。初步分析表明,Android恶意软件具有密度高、紧密性强、中间性强、节点数量多等特点。研究表明,物联网恶意软件样本具有大量的边缘,尽管节点数量较少,这显示出更丰富的流结构和更高的复杂性。我们利用这些不同的特征特征作为一种模式来构建一个高效的基于深度学习的检测模型来检测物联网恶意软件。为了测试我们的模型,我们使用了大约6000个恶意软件和良性物联网拆解样本的cfg,并显示出接近99.66%的检测准确率。
The steady growth in the number of deployed Internet of Things (IoT) devices has been paralleled with an equal growth in the number of malicious software (malware) targeting those devices. In this paper, we build a detection mechanism of IoT malware utilizing control flow graphs (CFGs). To motivate for our detection mechanism, we contrast the underlying characteristics of IoT malware to other types of malware-Android malware, which are also Linux-based-across multiple features. The preliminary analyses reveal that the Android malware have high density, strong closeness and betweenness, and a larger number of nodes. We show that IoT malware samples have a large number of edges despite a smaller number of nodes, which demonstrate a richer flow structure and higher complexity. We utilize those various characterizing features as a modality to build a highly effective deep learning-based detection model to detect IoT malware. To test our model, we use CFGs of about 6000 malware and benign IoT disassembled samples, and show a detection accuracy of approximate to 99.66%.