Evaluating the Possibility of Evasion Attacks to Machine Learning-Based Models for Malicious PowerShell Detection

Evaluating the Possibility of Evasion Attacks to Machine Learning-Based Models for Malicious PowerShell Detection
复制标题

评估对基于机器学习的恶意 PowerShell 检测模型进行规避攻击的可能性

DOI:
10.1007/978-3-031-21280-2_14
复制
发表时间:
2022
期刊:
Information Security Practice and Experience
影响因子:
--
通讯作者:
Mimura Mamoru
Mimura Mamoru
中科院分区:
--
文献类型:
--
作者:
Mezawa Yuki;Mimura Mamoru

文献摘要

相似文献

在网络攻击中,PowerShell已经成为攻击者的便捷工具。之前的一项研究提出了一种结合自然语言处理(NLP)技术和机器学习模型的PowerShell脚本分类方法。虽然已经指出机器学习的准确性会因对抗性输入而降低,但没有关于PowerShell分类的评估报告。在本研究中,我们对基于机器学习的恶意PowerShell检测模型进行了规避攻击的可能性评估。除了单词袋、潜在语义索引(LSI)和支持向量机(SVM)之外,我们还将Doc2Vec、RandomForest和XGBoost与之前的模型结合起来。因此,我们确认在PowerShell中可能存在逃避攻击。特别是,使用Doc2Vec的模型最大降低了0.78的召回率。效果主要取决于NLP技术,并且在LSI的任何机器学习模型中几乎没有差异。
In cyber attacks, PowerShell has become a convenient tool for attackers. A previous study proposed a classification method for PowerShell scripts that combines natural language processing (NLP) techniques and machine learning models. Although it has been pointed out that the accuracy of machine learning is degraded by adversarial input, no evaluation has been reported for PowerShell classification. In this study, we evaluated the possibility of evasion attacks to the machine learning-based model for malicious PowerShell detection. In addition to Bag-of-Words, Latent Semantic Indexing (LSI), and Support Vector Machine (SVM), we combined Doc2Vec, RandomForest, and XGBoost with the previous models. As a result, we confirmed that evasion attacks are possible in PowerShell. In particular, the models using Doc2Vec decreased the recall rate by 0.78 at maximum. The effect mainly depends on the NLP technique, and there was almost no difference in any machine learning models with LSI.