A Monte Carlo Tree Search approach to Active Malware Analysis

A Monte Carlo Tree Search approach to Active Malware Analysis
复制标题

用于主动恶意软件分析的蒙特卡罗树搜索方法

DOI:
--
复制
发表时间:
2017
期刊:
International Joint Conference on Artificial Intelligence
影响因子:
--
通讯作者:
A. Farinelli
A. Farinelli
中科院分区:
--
文献类型:
--
作者:
Riccardo Sartea;A. Farinelli

文献摘要

被引文献

相似文献

主动恶意软件分析 (AMA) 侧重于通过执行触发恶意软件响应的操作来获取有关危险软件的知识。 AMA 的一个关键问题是设计策略来选择信息最丰富的操作进行分析。为了设计这样的动作,我们将 AMA 建模为分析代理和恶意软件样本之间的随机博弈,并提出了一种基于蒙特卡罗树搜索的强化学习算法。至关重要的是,我们的方法不需要预先指定的恶意软件模型,但与大多数现有分析技术相比,我们在与恶意软件交互时生成这样的模型。我们使用聚类技术对通过分析真实恶意软件样本生成的模型来评估我们的解决方案。结果表明,即使没有关于样本的任何先验信息,我们的方法也比现有技术学习得更快。
Active Malware Analysis (AMA) focuses on acquiring knowledge about dangerous software by executing actions that trigger a response in the malware. A key problem for AMA is to design strategies that select most informative actions for the analysis. To devise such actions, we model AMA as a stochastic game between an analyzer agent and a malware sample, and we propose a reinforcement learning algorithm based on Monte Carlo Tree Search. Crucially, our approach does not require a pre-specified malware model but, in contrast to most existing analysis techniques, we generate such model while interacting with the malware. We evaluate our solution using clustering techniques on models generated by analyzing real malware samples. Results show that our approach learns faster than existing techniques even without any prior information on the samples.