Adversarial Evasion-Resilient Hardware Malware Detectors

Adversarial Evasion-Resilient Hardware Malware Detectors
复制标题

对抗性规避硬件恶意软件检测器

DOI:
--
复制
发表时间:
2018
期刊:
2018 IEEE/ACM International Conference on Computer-Aided Design (ICCAD)
影响因子:
--
通讯作者:
Lei Yu
Lei Yu
中科院分区:
--
文献类型:
--
作者:
Khaled N. Khasawneh;N. Abu;D. Ponomarev;Lei Yu

文献摘要

被引文献

相似文献

机器学习为计算和自主系统提供了诱人的可能性:数据驱动的组件和系统经过训练,可以学习它们的环境,并提供与人类相当或超过人类的决策。然而,对手可以学习分类器的行为并构建对抗性示例,导致他们做出错误的决定,从而可能带来灾难性的后果。我们探索这个空间的背景下,硬件恶意软件检测器(HMD),这是最近提出的防御恶意软件的扩散。这些检测器使用低级功能,这些功能可以由现代CPU上的硬件性能监控单元收集,以将恶意软件检测为计算异常。攻击者可以有效地对现有的HMD进行逆向工程,并使用逆向工程模型来创建逃避检测的恶意软件。为了解决这个关键问题,我们开发了规避弹性检测器,利用对抗机器学习的最新结果,在逆向工程和规避的弹性方面提供理论上可量化的优势。具体来说,这些检测器使用多个基本检测器,并在它们之间随机切换,从而提供针对逆向工程的保护,从而避免规避。检测器依赖于基线分类器的多样性,其规避优势与它们不一致的频率相关。因此,研究不同基线检测器的决策如何相关至关重要:一个称为可转移性的特征。我们研究了不同分类器算法和内部设置之间的可转移性,发现不可微算法是对抗性设置中操作的最佳候选者。
Machine learning offers tantalizing possibilities in computing and autonomous systems: data driven components and systems are trained to learn their environment and offer decisions comparable or surpassing those of humans. However, adversaries can learn the behavior of classifiers and construct adversarial examples that cause them to make wrong decisions, with potentially disastrous consequences. We explore this space in the context of Hardware Malware Detectors (HMDs), which have recently been proposed as a defense against the proliferation of malware. These detectors use low-level features, that can be collected by the hardware performance monitoring units on modern CPUs to detect malware as a computational anomaly. An adversary can reverse engineer existing HMDs effectively and use the reverse engineered model to create malware that evades detection. To address this critical problem, we developed evasion-resilient detectors that leverage recent results in adversarial machine learning to provide a theoretically quantifiable advantage in resilience to reverse engineering and evasion. Specifically, these detectors use multiple base detectors and switch between them stochastically, providing protection against reverse engineering and therefore evasion. The detectors rely on diversity of the baseline classifiers and their evasion advantage correlates with how often they disagree. Thus, it's critical to study how correlated the decisions from different baseline detectors are: a characteristic called transferability. We study transferability across different classifier algorithms and internal settings discovering that non-differentiable algorithms make the best candidates for operation in adversarial settings.