Using Knowledge Graphs and Reinforcement Learning for Malware Analysis

Using Knowledge Graphs and Reinforcement Learning for Malware Analysis
复制标题

DOI:
10.1109/bigdata50022.2020.9378491
复制
发表时间:
2020-12
期刊:
2020 IEEE International Conference on Big Data (Big Data)
影响因子:
--
通讯作者:
Aritran Piplai;P. Ranade;Anantaa Kotal;Sudip Mittal;S. Narayanan;A. Joshi
Aritran Piplai;P. Ranade;Anantaa Kotal;Sudip Mittal;S. Narayanan;A. Joshi
中科院分区:
其他
文献类型:
--
作者:
Aritran Piplai;P. Ranade;Anantaa Kotal;Sudip Mittal;S. Narayanan;A. Joshi

文献摘要

相似文献

用于检测攻击的机器学习算法受到这样一个事实的限制,即它们无法纳入分析师拥有的背景知识。这限制了它们在检测新攻击时的适用性。强化学习不同于用于网络安全领域的传统机器学习算法。与传统的最大似然算法相比,强化学习不需要输入输出空间的映射,也不需要特定的用户定义的度量来比较数据点。这对于网络安全领域非常重要,特别是对于恶意软件检测和缓解,因为并不是所有问题都有一个已知的正确答案。为了了解恶意软件的存在并缓解恶意软件的存在,安全研究人员经常不得不采取引导试错的方法。在本文中,我们结合以网络安全知识图(CKGs)表示的先验知识来指导RL算法的探索以检测恶意软件。CKG捕获网络实体之间的语义关系,包括从开源挖掘的实体。我们的目标不是尝试随机猜测和观察环境的变化,而是利用已验证的网络攻击知识来指导我们的强化学习算法有效地识别检测恶意文件名的方法,以便删除它们以减轻网络攻击。我们证明了这样的引导系统在检测恶意软件方面优于基本的RL系统。
Machine learning algorithms used to detect attacks are limited by the fact that they cannot incorporate the back-ground knowledge that an analyst has. This limits their suitability in detecting new attacks. Reinforcement learning is different from traditional machine learning algorithms used in the cybersecurity domain. Compared to traditional ML algorithms, reinforcement learning does not need a mapping of the input-output space or a specific user-defined metric to compare data points. This is important for the cybersecurity domain, especially for malware detection and mitigation, as not all problems have a single, known, correct answer. Often, security researchers have to resort to guided trial and error to understand the presence of a malware and mitigate it.In this paper, we incorporate prior knowledge, represented as Cybersecurity Knowledge Graphs (CKGs), to guide the exploration of an RL algorithm to detect malware. CKGs capture semantic relationships between cyber-entities, including that mined from open source. Instead of trying out random guesses and observing the change in the environment, we aim to take the help of verified knowledge about cyber-attack to guide our reinforcement learning algorithm to effectively identify ways to detect the presence of malicious filenames so that they can be deleted to mitigate a cyber-attack. We show that such a guided system outperforms a base RL system in detecting malware.