Mimicking Anti-Viruses with Machine Learning and Entropy Profiles.

Mimicking Anti-Viruses with Machine Learning and Entropy Profiles.
复制标题

DOI:
10.3390/e21050513
复制
发表时间:
2019-05-21
期刊:
Entropy (Basel, Switzerland)
影响因子:
--
通讯作者:
Llorente JL
Llorente JL
中科院分区:
其他
文献类型:
--
作者:
Menéndez HD;Llorente JL

文献摘要

参考文献

被引文献

相似文献

反病毒软件的质量依赖于从二进制文件中提取的简单模式。虽然这些模式已被证明可以检测软件的细节,但它们对隐藏策略(如多态性或变形)非常敏感。这些限制也使得防病毒软件可预测,从而造成安全漏洞。任何拥有足够的反病毒行为信息的黑客都可以制作自己的软件副本,而无需访问原始实现或数据库。在这项工作中,我们展示了如何通过将熵模式与分类算法相结合来实现这一点。我们的研究结果,应用于57个不同的反病毒引擎,表明我们可以模仿他们的行为,在最好的情况下,准确率接近98%,在最坏的情况下,应用于Windows的磁盘驻留恶意软件。
The quality of anti-virus software relies on simple patterns extracted from binary files. Although these patterns have proven to work on detecting the specifics of software, they are extremely sensitive to concealment strategies, such as polymorphism or metamorphism. These limitations also make anti-virus software predictable, creating a security breach. Any black hat with enough information about the anti-virus behaviour can make its own copy of the software, without any access to the original implementation or database. In this work, we show how this is indeed possible by combining entropy patterns with classification algorithms. Our results, applied to 57 different anti-virus engines, show that we can mimic their behaviour with an accuracy close to 98% in the best case and 75% in the worst, applied on Windows’ disk resident malware.
DOI: 10.1145/3162625
发表时间: 2018-01-01
影响因子: 4.4
作者:
Garcia, Joshua;Hammad, Mahmoud;Malek, Sam
通讯作者: Malek, Sam
DOI: 10.1016/j.eswa.2017.11.032
发表时间: 2018-04-01
影响因子: 8.5
作者:
Calleja, Alejandro;Martin, Alejandro;Clark, David
通讯作者: Clark, David
DOI: 10.1214/aos/1013203451
发表时间: 2001-10-01
影响因子: 4.5
作者:
Friedman, JH
通讯作者: Friedman, JH
DOI: 10.1214/aos/1016218223
发表时间: 2000-04-01
影响因子: 4.5
作者:
Friedman, J;Hastie, T;Tibshirani, R
通讯作者: Tibshirani, R
DOI: 10.1016/j.patcog.2018.07.023
发表时间: 2018-12-01
影响因子: 8
作者:
Biggio, Battista;Roli, Fabio
通讯作者: Roli, Fabio