Robust Malware Detection for Internet of (Battlefield) Things Devices Using Deep Eigenspace Learning

Robust Malware Detection for Internet of (Battlefield) Things Devices Using Deep Eigenspace Learning
复制标题

DOI:
10.1109/tsusc.2018.2809665
复制
发表时间:
2019-01-01
影响因子:
3.9
通讯作者:
Choo, Kim-Kwang Raymond
Choo, Kim-Kwang Raymond
中科院分区:
计算机科学2区
文献类型:
--
作者:
Azmoodeh, Amin;Dehghantanha, Ali;Choo, Kim-Kwang Raymond

文献摘要

被引文献

相似文献

军事环境中的物联网(IoT)通常由各种各样的互联网连接的设备和节点(例如,医疗设备和可穿戴作战制服)。这些物联网设备和节点是网络犯罪分子的重要目标,特别是国家赞助或民族国家行为者。一个常见的攻击媒介是使用恶意软件。在本文中,我们提出了一种基于深度学习的方法,通过设备的操作代码(OpCode)序列来检测战场物联网(IoBT)恶意软件。我们将OpCodes转化为向量空间,并应用深度特征空间学习方法来分类恶意和良性应用程序。我们还展示了我们提出的恶意软件检测方法的鲁棒性及其针对垃圾代码插入攻击的可持续性。最后,我们在Github上提供了我们的恶意软件样本,希望这将有利于未来的研究工作(例如,以便于评估未来的恶意软件检测方法)。
Internet of Things (IoT) in military settings generally consists of a diverse range of Internet-connected devices and nodes (e.g., medical devices and wearable combat uniforms). These loT devices and nodes are a valuable target for cyber criminals, particularly state-sponsored or nation state actors. A common attack vector is the use of malware. In this paper, we present a deep learning based method to detect Internet Of Battlefield Things (IoBT) malware via the device's Operational Code (OpCode) sequence. We transmute OpCodes into a vector space and apply a deep Eigenspace learning approach to classify malicious and benign applications. We also demonstrate the robustness of our proposed approach in malware detection and its sustainability against junk code insertion attacks. Lastly, we make available our malware sample on Github, which hopefully will benefit future research efforts (e.g., to facilitate evaluation of future malware detection approaches).