Semantics-Based Online Malware Detection: Towards Efficient Real-Time Protection Against Malware

被引:118
|
作者
Das, Sanjeev [1 ]
Liu, Yang [1 ]
Zhang, Wei [2 ]
Chandramohan, Mahintham [1 ]
机构
[1] Nanyang Technol Univ, Singapore 639798, Singapore
[2] Hong Kong Univ Sci & Technol, Hong Kong, Hong Kong, Peoples R China
基金
新加坡国家研究基金会;
关键词
Malware detection; hardware-enhanced architecture; runtime security; early prediction; reconfigurable malware detection;
D O I
10.1109/TIFS.2015.2491300
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Recently, malware has increasingly become a critical threat to embedded systems, while the conventional software solutions, such as antivirus and patches, have not been so successful in defending the ever-evolving and advanced malicious programs. In this paper, we propose a hardware-enhanced architecture, GuardOL, to perform online malware detection. GuardOL is a combined approach using processor and field-programmable gate array (FPGA). Our approach aims to capture the malicious behavior (i.e., high-level semantics) of malware. To this end, we first propose the frequency-centric model for feature construction using system call patterns of known malware and benign samples. We then develop a machine learning approach (using multilayer perceptron) in FPGA to train classifier using these features. At runtime, the trained classifier is used to classify the unknown samples as malware or benign, with early prediction. The experimental results show that our solution can achieve high classification accuracy, fast detection, low power consumption, and flexibility for easy functionality upgrade to adapt to new malware samples. One of the main advantages of our design is the support of early prediction-detecting 46% of malware within first 30% of their execution, while 97% of the samples at 100% of their execution, with <3% false positives.
引用
下载
收藏
页码:289 / 302
页数:14
相关论文
共 50 条
  • [41] PhD Forum: Deep Learning-based Real-Time Malware Detection with Multi-Stage Analysis
    Yuan, Xiaoyong
    2017 IEEE INTERNATIONAL CONFERENCE ON SMART COMPUTING (SMARTCOMP), 2017, : 243 - 244
  • [42] A Chi-Square-Based Decision for Real-Time Malware Detection Using PE-File Features
    Belaoued, Mohamed
    Mazouzi, Smaine
    JOURNAL OF INFORMATION PROCESSING SYSTEMS, 2016, 12 (04): : 644 - 660
  • [43] HEAVEN: A Hardware-Enhanced AntiVirus ENgine to accelerate real-time, signature-based malware detection
    Botacin, Marcus
    Alves, Marco Zanata
    Oliveira, Daniela
    Gregio, Andre
    EXPERT SYSTEMS WITH APPLICATIONS, 2022, 201
  • [44] PAD: Towards Principled Adversarial Malware Detection Against Evasion Attacks
    Li, Deqiang
    Cui, Shicheng
    Li, Yun
    Xu, Jia
    Xiao, Fu
    Xu, Shouhuai
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (02) : 920 - 936
  • [45] Semantics-based transaction processing for real-time databases: The case of automated stock trading
    Konana, P
    Ram, S
    INFORMS JOURNAL ON COMPUTING, 1999, 11 (03) : 299 - 315
  • [46] MalBuster: Scalable, Real-Time, and Concept Drift-Adaptive Malware Detection for Smart Environments
    Wang, Jingwen
    Li, Peilong
    Weitkamp, Ethan
    Satani, Yusuke
    Omundsen, Adam
    2024 IEEE 21ST CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE, CCNC, 2024, : 352 - 355
  • [47] Run-time malware detection based on IRP
    Zhang F.-Y.
    Qi D.-Y.
    Hu J.-L.
    Huanan Ligong Daxue Xuebao/Journal of South China University of Technology (Natural Science), 2011, 39 (02): : 113 - 117
  • [48] A Real-Time Hybrid Approach to Combat In-Browser Cryptojacking Malware
    Khan Abbasi, Muhammad Haris
    Ullah, Subhan
    Ahmad, Tahir
    Buriro, Attaullah
    APPLIED SCIENCES-BASEL, 2023, 13 (04):
  • [49] SpyDroid: A Framework for Employing Multiple Real-Time Malware Detectors on Android
    Iqbal, Shahrear
    Zulkernine, Mohammad
    PROCEEDINGS OF THE 2018 13TH INTERNATIONAL CONFERENCE ON MALICIOUS AND UNWANTED SOFTWARE (MALWARE 2018), 2018, : 33 - 40
  • [50] Real-Time Hardware-Based Malware and Micro-Architectural Attack Detection Utilizing CMOS Reservoir Computing
    Chandrasekaran, Sanjeev Tannirkulam
    Kuruvila, Abraham Peedikayil
    Basu, Kanad
    Sanyal, Arindam
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS II-EXPRESS BRIEFS, 2022, 69 (02) : 349 - 353