MalPro: Learning on Process-Aware Behaviors for Malware Detection

被引:4
|
作者
Chen, Xiaohui [1 ,2 ]
Tong, Ying [3 ]
Du, Chunlai [4 ]
Liu, Yongji [1 ]
Ding, Zhenquan [1 ]
Ran, Qingyun [3 ]
Zhang, Yi [3 ]
Cui, Lei [1 ]
Hao, Zhiyu [1 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
[3] Jiangsu Prov Publ Secur Dept, Nanjing, Peoples R China
[4] North China Univ Technol, Sch Informat Sci & Technol, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
malware detection; API sequence; run-time argument; process graph; process-aware behavior; deep learning;
D O I
10.1109/ISCC55528.2022.9913030
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Malware continuously evolve and become more and more sophisticated. Learning on execution behavior is proven to be effective for malware detection. In this paper, we present MalPro, a DNN based malware detection approach that performs learning on process-aware behaviors for Windows programs. It first employs logistic regression-based weighting method to assess the sensitivity of an API to malicious behavior, and weights the API following run-time arguments with varying degrees of sensitivities. Then, it constructs the process graph of inter-process interactions from which a set of attributes are extracted, for characterizing the relationship of various processes in term of invoke actions. Finally, it feeds the weighted API sequences and the process graph attributes into the DNN for training a binary classifier to detect malware. Moreover, we have implemented and evaluated MalPro on two datasets. The results demonstrate that our method outperforms naive models, verifying the effectiveness of MalPro.
引用
收藏
页数:7
相关论文
共 50 条
  • [1] Toward Detecting Malware Based on Process-Aware Behaviors
    Du C.
    Tong Y.
    Chen X.
    Liu Y.
    Ding Z.
    Xu H.
    Ran Q.
    Zhang Y.
    Meng L.
    Cui L.
    Hao Z.
    [J]. Security and Communication Networks, 2023, 2023
  • [2] Process-Aware Intrusion Detection in MQTT Networks
    Empl, Philip
    Boehm, Fabian
    Pernul, Guenther
    [J]. PROCEEDINGS OF THE FOURTEENTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY, CODASPY 2024, 2024, : 91 - 102
  • [3] Scenarios for Process-Aware Insider Attack Detection in Manufacturing
    Macak, Martin
    Vaclavek, Radek
    Kusnirakova, Dasa
    Matulevicius, Raimundas
    Buhnova, Barbora
    [J]. PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, ARES 2022, 2022,
  • [4] MalPro: A Learning-based Malware Propagation and Containment Modeling
    Valizadeh, Saeed
    van Dijk, Marten
    [J]. CCSW'19: PROCEEDINGS OF THE 2019 ACM SIGSAC CONFERENCE ON CLOUD COMPUTING SECURITY WORKSHOP, 2019, : 45 - 56
  • [5] Optimization of Process-Aware Attack Detection for Industrial Control Systems Security
    Sicard, Franck
    Hotellier, Estelle
    Perez-Olivares, Javier Soto
    Zamai, Eric
    [J]. 2020 25TH IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION (ETFA), 2020, : 889 - 896
  • [6] Explainable AI for Process-Aware Attack Detection in Industrial Control Systems
    Kenmogne, Lea Astrid
    Mocanu, Stephane
    [J]. 2024 IEEE 10TH INTERNATIONAL CONFERENCE ON NETWORK SOFTWARIZATION, NETSOFT 2024, 2024, : 363 - 368
  • [7] Bayesian Learning Model Predictive Control for Process-Aware Source Seeking
    Li, Yingke
    Liu, Tianyi
    Zhou, Enlu
    Zhang, Fumin
    [J]. IEEE CONTROL SYSTEMS LETTERS, 2022, 6 : 692 - 697
  • [8] Architecture and prototype implementation for process-aware intrusion detection in electrical grids
    Flosbach, Robert
    Chromik, Justyna Joanna
    Remke, Anne
    [J]. 2019 IEEE 38TH INTERNATIONAL SYMPOSIUM ON RELIABLE DISTRIBUTED SYSTEMS (SRDS 2019), 2019, : 42 - 51
  • [9] Development of a Process-Aware Instructor-Aware Multi-Tabletop Collaborative Learning Environment
    Porouhan, Parham
    Premchaiswadi, Wichian
    [J]. 2016 14TH INTERNATIONAL CONFERENCE ON ICT AND KNOWLEDGE ENGINEERING (ICT&KE), 2016, : 62 - 70
  • [10] PACAs: Process-Aware Conversational Agents
    Lins, Luis Fernando
    Melo, Glaucia
    Oliveira, Toacy
    Alencar, Paulo
    Cowan, Donald
    [J]. BUSINESS PROCESS MANAGEMENT WORKSHOPS, BPM 2021, 2022, 436 : 312 - 318