Enhanced Dynamic Analysis for Malware Detection With Gradient Attack

被引:0
|
作者
Yan, Pei [1 ,2 ]
Tan, Shunquan [3 ]
Wang, Miaohui [1 ,2 ]
Huang, Jiwu [4 ]
机构
[1] Shenzhen Key Lab Media Secur, Shenzhen 518000, Peoples R China
[2] Shenzhen Univ, Guangdong Key Lab Intelligent Informat Proc, Shenzhen 518060, Peoples R China
[3] Shenzhen City Polytech, Sch Informat & Commun Technol, Shenzhen 518116, Peoples R China
[4] Shenzhen MSU BIT Univ, Guangdong Lab Machine Percept & Intelligent Comp, Fac Comp, Shenzhen 518116, Peoples R China
关键词
Malware; Training; Noise; Feature extraction; Application programming interfaces; Perturbation methods; Backpropagation; Vocabulary; Vectors; Accuracy; Adversarial method; dynamic analysis; malware detection; network security;
D O I
10.1109/LSP.2024.3475354
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Malware detection is an effective way to prevent the intrusion of malware into computer systems, and the API-based dynamic analysis method can effectively detect obfuscated and packaged malware. However, existing methods still suffer from limited detection accuracy and weak generalization. To address this issue, this paper presents a gradient attack-based malware dynamic analysis method. Through exerting adversarial noise into the embedding layer, the malware detection model can learn more robust representations of API sequences during training, achieving broader coverage of sample representations. The strategy of normalizing attack noise and recovering attacked representation is designed, which controls the strength of the gradient attack within a reasonable range and prevents a negative impact on the model's detection performance. The proposed method can be applied to existing API-based malware detection models to enhance their detection performance, indicating the strong generality of the proposed method. Experimental results on two benchmark datasets (i.e., Aliyun and Catak) demonstrate the effectiveness of the proposed gradient attack method, which further improves the detection performance of the mainstream API-based models, with an average accuracy increase of 2.80% and 3.66% on these two datasets, respectively.
引用
收藏
页码:2825 / 2829
页数:5
相关论文
共 50 条
  • [31] Twitter-Enhanced Android Malware Detection
    DeLoach, Jordan
    Caragea, Doina
    2017 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2017, : 4648 - 4657
  • [32] Anatomy of a malware attack
    Netw. Secur., 1 (4-7):
  • [33] A New Malware Classification Approach Based on Malware Dynamic Analysis
    Fang, Ying
    Yu, Bo
    Tang, Yong
    Liu, Liu
    Lu, Zexin
    Wang, Yi
    Yang, Qiang
    INFORMATION SECURITY AND PRIVACY, ACISP 2017, PT II, 2017, 10343 : 173 - 189
  • [34] Dynamic Malware Attack in Energy-Constrained Mobile Wireless Networks
    Khouzani, M. H. R.
    Sarkar, Saswati
    2010 INFORMATION THEORY AND APPLICATIONS WORKSHOP (ITA), 2010, : 408 - 418
  • [35] Optimal feature configuration for dynamic malware detection
    Escudero Garcia, David
    DeCastro-Garcia, Noemi
    COMPUTERS & SECURITY, 2021, 105
  • [36] Runtime-based Behavior Dynamic Analysis System for Android Malware Detection
    Min, Luoxu
    Cao, Qinghua
    PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION APPLICATIONS (ICCIA 2012), 2012, : 233 - 236
  • [37] Impact of Code Obfuscation on Android Malware Detection based on Static and Dynamic Analysis
    Bacci, Alessandro
    Bartoli, Alberto
    Martinelli, Fabio
    Medvet, Eric
    Mercaldo, Francesco
    Visaggio, Corrado Aaron
    ICISSP: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2018, : 379 - 385
  • [38] A cost analysis of machine learning using dynamic runtime opcodes for malware detection
    Carlin, Domhnall
    O'Kane, Philip
    Sezer, Sakir
    COMPUTERS & SECURITY, 2019, 85 : 138 - 155
  • [39] Dynamic Malware Detection using API Similarity
    Alkhateeb, Ehab M.
    2017 IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION TECHNOLOGY (CIT), 2017, : 297 - 301
  • [40] AndroTaint: An Efficient Android Malware Detection Framework using Dynamic Taint Analysis
    Shankar, Venkatesh Gauri
    Somani, Gaurav
    Gaur, Manoj Singh
    Laxmi, Vijay
    Conti, Mauro
    2017 ISEA ASIA SECURITY AND PRIVACY CONFERENCE (ISEASP 2017), 2017, : 71 - 83