Towards Scalable, Resilient, and Interpretable Approaches for Machine Learning based Malware Detectors
Towards Scalable, Resilient, and Interpretable Approaches for Machine Learning based Malware Detectors
批准号:
RGPIN-2020-04738
负责人:
Saad, Sherif
金额:
$2.11万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2022
资助国家:
加拿大
项目状态:
已结题
起止时间:
2022-01-01 至 2023-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Many cybersecurity experts think that antimalware-system-leveraging machine learning will be the solution to modern malware attacks. In the literature, various malware detection techniques using machine learning with encouraging detection accuracy have been proposed. However, malware attacks in the wild continue to grow and manage to bypass malware detection systems powered by machine learning techniques. There is a significant difference between the accuracy of malware detection techniques in the literature and their accuracy in a production environment. Three reasons explain the limitations of machine-learning-based (ML-based) malware detection systems in the wild. First, unlike other areas that utilize machine learning, malware instances continue to evolve and change. This mostly requires the retraining of machine learning models, which is an expensive and complicated task. The training cost for ML-based malware detectors in production introduces a scalability challenge that is not properly addressed in the literature. Second, malware authors apply dynamic evading techniques and leverage adversary machine learning techniques to bypass detection. Because machine learning models are not designed to work in adversarial settings, to overcome adversarial malware threats, we need to design resilient and robust ML-based malware detectors. Third, but not least, adopting sophisticated machine learning techniques in a production environment is challenging because, most of the time, it is not possible to understand how machine learning systems make malware detection decisions. Therefore, tuning and maintaining these systems is a challenge for cybersecurity analysts. Hence, the interpretability of machine learning models is an important requirement for malware detectors that have not yet been investigated. The main goal of this research program is to investigate and overcome the limitations of ML-based malware detectors. The research program focuses on three main directions to reach its goal. First, reduce the cost of retraining machine learning systems for malware detection in production. Second, design techniques to interpret malware detection results produced by machine learning systems in a manner that is useful to malware analysts. Third, develop a framework to help the malware detection systems mitigate adversarial malware attacks. This research program will contribute to the training of several HQP: students will develop theoretical and practical skills in applied machine learning and malware analysis. It will contribute to positioning Canada as a leader in malware security research, and we will contribute to AssemblyLine (an open-source malware analysis platform published in 2017 by the communications security establishment of Canada). In addition, several products could efficiently utilize our research outcome, which would lead to the creation of spin-off companies, or existing antimalware companies could utilize the technology through licensing.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Towards Scalable, Resilient, and Interpretable Approaches for Machine Learning based Malware Detectors
-
批准号:RGPIN-2020-04738
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.11万
-
财政年份:2021
-
负责人:Saad, Sherif
-
依托单位:
Towards Scalable, Resilient, and Interpretable Approaches for Machine Learning based Malware Detectors
-
批准号:RGPIN-2020-04738
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.11万
-
财政年份:2020
-
负责人:Saad, Sherif
-
依托单位:
Towards Scalable, Resilient, and Interpretable Approaches for Machine Learning based Malware Detectors
-
批准号:DGECR-2020-00275
-
项目类别:Discovery Launch Supplement
-
资助金额:$0.91万
-
财政年份:2020
-
负责人:Saad, Sherif
-
依托单位:
国内基金
海外基金
Scalable Learning and Optimization: High-dimensional Models and Online Decision-Making Strategies for Big Data Analysis
-
批准号:--
-
项目类别:合作创新研究团队
-
资助金额:--
-
批准年份:2024
-
负责人:姚韬
-
依托单位: