A multiview learning method for malware threat hunting: windows, IoT and android as case studies

被引:0
|
作者
Hamid Darabian
Ali Dehghantanha
Sattar Hashemi
Mohammad Taheri
Amin Azmoodeh
Sajad Homayoun
Kim-Kwang Raymond Choo
Reza M. Parizi
机构
[1] Shiraz University,Department of Computer Science and Engineering
[2] University of Guelph,Cyber Science Lab, School of Computer Science
[3] Shiraz University of Technology,IT and Computer Engineering Faculty
[4] The University of Texas at San Antonio,Department of Information Systems and Cyber Security and Department of Electrical and Computer Engineering
[5] Kennesaw State University,Department of Software Engineering and Game Development
来源
World Wide Web | 2020年 / 23卷
关键词
Malware; Threat hunting; Malware detection; Multi-view learning; Maximum margin; View weighting;
D O I
暂无
中图分类号
学科分类号
摘要
Malware remains a threat to our cyberspace and increasingly digitalized society. Current malware hunting techniques employ a variety of features, such as OpCodes, ByteCodes, and API calls, to distinguish malware from goodware. However, existing malware hunting approaches generally focus on a single particular view, such as using dynamic information or opcodes only. While single-view malware hunting systems may provide lean and optimized basis for detecting a specific type of malware, their performance can be significantly limited when dealing with other types of malware; thus, making it trivial for an advanced attacker to develop malware that simply obfuscates features monitored by a single-view malware detection system. To address these limitations, we propose a multi-view learning method that uses multiple views including OpCodes, ByteCodes, header information, permission, attacker’s intent and API call to hunt malicious programs. Our system automatically assigns weights to different views to optimize detection in different environment. Using experiments conducted on various Windows, Android and Internet of Things (IoT) platforms, we demonstrate that our method offers high accuracy with a low false positive rate on these case study platforms. Moreover, we also investigate the robustness of detection against weak views (features with low power of discrimination). The proposed method is the first malware threat hunting method that can be applied to different platforms, at the time of this research, and it is considerably difficult for attackers to evade detection (since it requires attackers to obfuscate multiple different views).
引用
下载
收藏
页码:1241 / 1260
页数:19
相关论文
共 48 条
  • [1] A multiview learning method for malware threat hunting: windows, IoT and android as case studies
    Darabian, Hamid
    Dehghantanha, Ali
    Hashemi, Sattar
    Taheri, Mohammad
    Azmoodeh, Amin
    Homayoun, Sajad
    Choo, Kim-Kwang Raymond
    Parizi, Reza M.
    WORLD WIDE WEB-INTERNET AND WEB INFORMATION SYSTEMS, 2020, 23 (02): : 1241 - 1260
  • [2] IoT Malware Threat Hunting Method Based on Improved Transformer
    Li, Yaping
    Li, Yuancheng
    International Journal of Network Security, 2023, 25 (02) : 267 - 276
  • [3] A Survey on Cross-Architectural IoT Malware Threat Hunting
    Raju, Anandharaju Durai
    Abualhaol, Ibrahim Y.
    Giagone, Ronnie Salvador
    Zhou, Yang
    Huang, Shengqiang
    IEEE ACCESS, 2021, 9 : 91686 - 91709
  • [4] Cryptojacking Malware Hunting: A Method Based on Ensemble Learning of Hierarchical Threat Intelligence Feature
    Zheng R.
    Wang Q.-Y.
    Lin Z.-P.
    Jing R.-Q.
    Jiang Z.-W.
    Fu J.-M.
    Wang S.-W.
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2022, 50 (11): : 2707 - 2715
  • [5] Malware Detection in Android IoT Systems Using Deep Learning
    Waqar, Muhammad
    Fareed, Sabeeh
    Kim, Ajung
    Malik, Saif Ur Rehman
    Imran, Muhammad
    Yaseen, Muhammad Usman
    CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 74 (02): : 4399 - 4415
  • [6] A Multikernel and Metaheuristic Feature Selection Approach for IoT Malware Threat Hunting in the Edge Layer
    Haddadpajouh, Hamed
    Mohtadi, Alireza
    Dehghantanaha, Ali
    Karimipour, Hadis
    Lin, Xiaodong
    Choo, Kim-Kwang Raymond
    IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (06) : 4540 - 4547
  • [7] Detecting Advanced Persistent Threat Malware Using Machine Learning-Based Threat Hunting
    Lin, Tien-Chih
    Guo, Cheng-Chung
    Yang, Chu -Sing
    PROCEEDINGS OF THE 18TH EUROPEAN CONFERENCE ON CYBER WARFARE AND SECURITY (ECCWS 2019), 2019, : 760 - 768
  • [8] A Deep Learning Method for Obfuscated Android Malware Detection
    Dasiah, Nitin Benjamin
    Gain, Ritu
    Sabarisrinivas, V.
    Sitara, K.
    Communications in Computer and Information Science, 2024, 2128 CCIS : 149 - 164
  • [9] Evading Machine-Learning-Based Android Malware Detector for IoT Devices
    Renjith, G.
    Vinod, P.
    Aji, S.
    IEEE SYSTEMS JOURNAL, 2023, 17 (02): : 2745 - 2755
  • [10] A Method for Windows Malware Detection Based on Deep Learning
    Xiang Huang
    Li Ma
    Wenyin Yang
    Yong Zhong
    Journal of Signal Processing Systems, 2021, 93 : 265 - 273