Semantics-Based Online Malware Detection: Towards Efficient Real-Time Protection Against Malware

被引:118
|
作者
Das, Sanjeev [1 ]
Liu, Yang [1 ]
Zhang, Wei [2 ]
Chandramohan, Mahintham [1 ]
机构
[1] Nanyang Technol Univ, Singapore 639798, Singapore
[2] Hong Kong Univ Sci & Technol, Hong Kong, Hong Kong, Peoples R China
基金
新加坡国家研究基金会;
关键词
Malware detection; hardware-enhanced architecture; runtime security; early prediction; reconfigurable malware detection;
D O I
10.1109/TIFS.2015.2491300
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Recently, malware has increasingly become a critical threat to embedded systems, while the conventional software solutions, such as antivirus and patches, have not been so successful in defending the ever-evolving and advanced malicious programs. In this paper, we propose a hardware-enhanced architecture, GuardOL, to perform online malware detection. GuardOL is a combined approach using processor and field-programmable gate array (FPGA). Our approach aims to capture the malicious behavior (i.e., high-level semantics) of malware. To this end, we first propose the frequency-centric model for feature construction using system call patterns of known malware and benign samples. We then develop a machine learning approach (using multilayer perceptron) in FPGA to train classifier using these features. At runtime, the trained classifier is used to classify the unknown samples as malware or benign, with early prediction. The experimental results show that our solution can achieve high classification accuracy, fast detection, low power consumption, and flexibility for easy functionality upgrade to adapt to new malware samples. One of the main advantages of our design is the support of early prediction-detecting 46% of malware within first 30% of their execution, while 97% of the samples at 100% of their execution, with <3% false positives.
引用
下载
收藏
页码:289 / 302
页数:14
相关论文
共 50 条
  • [21] A New Design of Smart Plug for Real-time IoT Malware Detection
    Li, Zhuoran
    Perez, Bryan
    Khan, Sabbir Ahmed
    Feldhaus, Brandon
    Zhao, Dan
    2021 IEEE MICROELECTRONICS DESIGN & TEST SYMPOSIUM (MDTS), 2021,
  • [22] Twitter Analysis for Real-Time Malware Discovery
    Concone, Federico
    De Paola, Alessandra
    Lo Re, Giuseppe
    Morana, Marco
    2017 AEIT INTERNATIONAL ANNUAL CONFERENCE, 2017,
  • [23] Real-Time Framework for Malware Detection Using Machine Learning Technique
    Mukesh, Sharma Divya
    Raval, Jigar A.
    Upadhyay, Hardik
    INFORMATION AND COMMUNICATION TECHNOLOGY FOR INTELLIGENT SYSTEMS (ICTIS 2017) - VOL 1, 2018, 83 : 173 - 182
  • [24] EasyDefense: Towards Easy and Effective Protection Against Malware for Smartphones
    Ren, Bingfei
    Liu, Chuanchang
    Cheng, Bo
    Feng, Yimeng
    Chen, Junliang
    PROCEEDINGS OF THE 23RD ANNUAL INTERNATIONAL CONFERENCE ON MOBILE COMPUTING AND NETWORKING (MOBICOM '17), 2017, : 570 - 572
  • [25] Semantics-Based Scheduling Approach of Ontology-Based Real-Time DBMS
    Achour, Fehima
    Jaziri, Wassim
    Bouazizi, Emna
    NEW TRENDS IN INTELLIGENT SOFTWARE METHODOLOGIES, TOOLS AND TECHNIQUES, 2021, 337 : 553 - 566
  • [26] Efficient malware detection based on machine learning for enhanced cloud privacy protection
    Salwa Shakir Baawi
    Zahraa Ch. Oleiwi
    Abbas M. Ali Al-Muqarm
    Dhiah Al-Shammary
    Fahim Sufi
    Evolving Systems, 2025, 16 (1)
  • [27] Using side channel TCP features for real-time detection of malware connections
    Stergiopoulos, George
    Chronopoulou, Georgia
    Bitsikas, Evangelos
    Tsalis, Nikolaos
    Gritzalis, Dimitris
    JOURNAL OF COMPUTER SECURITY, 2019, 27 (05) : 507 - 520
  • [28] RealMalSol: real-time optimized model for Android malware detection using efficient neural networks and model quantization
    Chaudhary, Maham
    Masood, Ammar
    NEURAL COMPUTING & APPLICATIONS, 2023, 35 (15): : 11373 - 11388
  • [29] MIDAS: Safeguarding IoT Devices Against Malware via Real-Time Behavior Auditing
    Xu, Yiwen
    Yin, Zijing
    Hou, Yiwei
    Liu, Jianzhong
    Jiang, Yu
    IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2022, 41 (11) : 4373 - 4384
  • [30] SafeGuard: a behavior based real-time malware detection scheme for mobile multimedia applications in android platform
    Jeong, Eun Su
    Kim, In Seok
    Lee, Dong Hoon
    MULTIMEDIA TOOLS AND APPLICATIONS, 2017, 76 (17) : 18153 - 18173