Monotonic-HMDs: Exploiting Monotonic Features to Defend Against Evasive Malware
Monotonic-HMDs: Exploiting Monotonic Features to Defend Against Evasive Malware
复制标题
单调头戴式显示器:利用单调特征防御规避恶意软件
DOI:
--
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
Khaled N. Khasawneh
中科院分区:
文献类型:
--
作者:
Md. Shohidul Islam;Behnam Omidi;Khaled N. Khasawneh
Machine learning-based hardware malware detectors (HMDs) offer a potential game-changing advantage in defending systems against malware. However, HMDs suffer from adversarial attacks; they can be effectively reverse-engineered and subsequently be evaded, allowing malware to hide from detection. Adversarial evasion attacks requires adding benign features to the program execution to be able to evade detection. Against these attacks, in this paper, we propose MonotonicHMDs, which are HMDs built using monotonic features to defend against adversarial evasion attacks. Specifically, MonotonicHMDs are build using monotonic malicious features only. Thus, Monotonic-HMDs ensures that an adversary cannot evade the detection by simply adding benign features to the malware programs since they are not used in the Monotonic-HMD model. In addition, adding malicious features will only increase the probability of detecting the input program as malware. Our experimental results demonstrate that Monotonic-HMDs offer effective defense against adversarial attacks without sacrificing significant detection accuracy, which can be interpreted as a cost for security in classifying malware. Importantly, our results shows that for evasive malware that can completely evade current HMDs, the proposed Monotonic-HMDs achieve 83% detection accuracy and maintain this accuracy even under more aggressive attacks. Moreover, Monotonic-HMDs reduce the inference time, i.e., time to perform one detection, by 61.11%. Furthermore, the hardware implementation results of the Monotonic-HMDs shows that Monotonic-HMDs offers area and power consumption savings compared to current HMDs.