A Brain-inspired Approach for Malware Detection using Sub-semantic Hardware Features

A Brain-inspired Approach for Malware Detection using Sub-semantic Hardware Features
复制标题

使用子语义硬件功能检测恶意软件的受大脑启发的方法

DOI:
10.1145/3583781.3590293
复制
发表时间:
2023
期刊:
Proceedings Great Lakes Symposium on VLSI
影响因子:
--
通讯作者:
Alouani, Ihsen
Alouani, Ihsen
中科院分区:
--
文献类型:
--
作者:
Parsa, Maryam;Khasawneh, Khaled N.;Alouani, Ihsen

文献摘要

参考文献

相似文献

尽管为增强计算机系统对恶意软件攻击的弹性做出了重大努力,但大量可利用的漏洞仍然是一个重大挑战。虽然很难防止危害,但传统的基于签名的静态分析技术很容易绕过变形/多态恶意软件或零日漏洞。动态检测技术,特别是那些利用机器学习(ML)的技术,有可能通过监控程序行为来识别以前看不见的签名。然而,经典的ML模型是功率和资源密集型的,并且可能不适合预算有限的设备。这种约束在安全性和资源利用率之间创建了一个具有挑战性的权衡,这不能通过模型压缩和修剪来完全解决。相比之下,神经形态架构为低功耗脑启发系统提供了一个有前途的解决方案。在这项工作中,我们探讨了新的使用神经形态架构的恶意软件检测。我们通过在尖峰域中编码子语义微架构级别的特征并提出用于硬件感知恶意软件检测的尖峰神经网络(SNN)架构来实现这一点。我们的研究结果表明,有前途的恶意软件检测性能与89%的F1分数。最终,这项工作主张神经形态架构,由于其低功耗,代表了恶意软件检测的有希望的候选者,特别是对于物联网和边缘设备中的能量约束处理器。
Despite significant efforts to enhance the resilience of computer systems against malware attacks, the abundance of exploitable vulnerabilities remains a significant challenge. While preventing compromises is difficult, traditional signature-based static analysis techniques are susceptible to bypassing through metamorphic/polymorphic malware or zero-day exploits. Dynamic detection techniques, particularly those utilizing machine learning (ML), have the potential to identify previously unseen signatures by monitoring program behavior. However, classical ML models are power and resource intensive and may not be suitable for devices with limited budgets. This constraint creates a challenging tradeoff between security and resource utilization, which cannot be fully addressed through model compression and pruning. In contrast, neuromorphic architectures offer a promising solution for low-power brain-inspired systems. In this work, we explore the novel use of neuromorphic architectures for malware detection. We accomplish this by encoding sub-semantic micro-architecture level features in the spiking domain and proposing a Spiking Neural Network (SNN) architecture for hardware-aware malware detection. Our results demonstrate promising malware detection performance with an 89% F1-score. Ultimately, this work advocates that neuromorphic architectures, due to their low power consumption, represent a promising candidate for malware detection, especially for energy-constraint processors in IoT and Edge devices.
DOI: 10.1145/2897937.2898099
发表时间: 2016-06
期刊: 2016 53nd ACM/EDAC/IEEE Design Automation Conference (DAC)
影响因子: --
作者:
Theodore Winograd;H. Salmani;H. Mahmoodi;K. Gaj;H. Homayoun
通讯作者: Theodore Winograd;H. Salmani;H. Mahmoodi;K. Gaj;H. Homayoun
通过电压超标增强硬件恶意软件检测器的安全性
DOI: --
发表时间: 2021
期刊:
影响因子: --
作者:
Md. Shohidul Islam;Ihsen Alouani;Khaled N. Khasawneh
通讯作者: Khaled N. Khasawneh
DOI: 10.1038/s43588-021-00184-y
发表时间: 2022-01-01
期刊: NATURE COMPUTATIONAL SCIENCE
影响因子: --
作者:
Schuman, Catherine D.;Kulkarni, Shruti R.;Kay, Bill
通讯作者: Kay, Bill
随机 HMD:通过欠压实现对抗性弹性硬件恶意软件检测器
DOI: --
发表时间: 2023
期刊: Proceedings ACM IEEE Design Automation Conference
影响因子: --
作者:
Islam, Md Shohidul;Alouani, Ihsen;Khasawneh, Khaled N.
通讯作者: Khasawneh, Khaled N.
ROOM:实时约束下的对抗性机器学习攻击
DOI: --
发表时间: 2022
期刊: IEEE International Joint Conference on Neural Network
影响因子: --
作者:
Amira Guesmi;Khaled N. Khasawneh;Nael B. Abu;Ihsen Alouani
通讯作者: Ihsen Alouani