Extended Abstract: Evading Packing Detection: Breaking Heuristic-Based Static Detectors

被引:0
|
作者
D'Hondt, Alexandre [1 ]
Van Ouytsel, Charles Henry Bertrand [1 ]
Legay, Axel [1 ]
机构
[1] Catholic Univ Louvain, Rue Archimede 1, Louvain La Neuve, Belgium
关键词
executable packing; packer detection; static analysis; adversarial examples; experimental toolkit; ENTROPY ANALYSIS;
D O I
10.1007/978-3-031-64171-8_9
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Nowadays, executable packing remains an open issue in its detection especially when it comes to static analysis. Packing is significantly used in malware to hide malicious code from detection systems. These last years, many studies about static packing detection addressed this problem with heuristics and machine learning, considering different ad hoc techniques, algorithms and feature sets but very few addressed it from the adversarial point of view, that is, how to fool heuristics by altering samples with targeted modifications. The objective of this work is to study to what extent it is easy to evade detection by open source static detectors that are commonly used by the community by applying alterations on packed samples, which require only slight adaptations of the related packers, resulting in evasion. An adversarial setting from the problem-space perspective is addressed by using realistic modifications of binary samples that target common significant features. For this purpose, alterations and datasets are composed and static detection is applied using the experimental toolkit Packing Box. Results of alterations are shown, in terms of information gain of features and accuracy of detection, on open source static packing detectors. Finally, their significant effects are highlighted and their effectiveness is evaluated.
引用
收藏
页码:174 / 183
页数:10
相关论文
共 40 条
  • [21] Big Data Driven Map Reduce Framework for Automated Flood Disaster Detection Based on Heuristic-Based Ensemble Learning
    Shatat, Abdallah Saleh Ali
    Akhtar, Md. Mobin
    Zamani, Abu Sarwar
    Dilshad, Sara
    Samdani, Faizan
    CYBERNETICS AND SYSTEMS, 2024, 55 (07) : 1757 - 1791
  • [22] A new design of epileptic seizure detection using hybrid heuristic-based weighted feature selection and ensemble learning
    Bhandari, Vedavati
    Huchaiah, Manjaiah Doddaghatta
    INTERNATIONAL JOURNAL OF INTELLIGENT ROBOTICS AND APPLICATIONS, 2022, 6 (04) : 668 - 693
  • [23] Balancing Privacy and Utility with Pattern Based Activity Detection Extended Abstract
    Carley, Cassandra
    PROCEEDINGS OF THE 2018 AAAI/ACM CONFERENCE ON AI, ETHICS, AND SOCIETY (AIES'18), 2018, : 360 - 361
  • [24] A new design of epileptic seizure detection using hybrid heuristic-based weighted feature selection and ensemble learning
    Vedavati Bhandari
    Manjaiah Doddaghatta Huchaiah
    International Journal of Intelligent Robotics and Applications, 2022, 6 : 668 - 693
  • [25] Semantics-Based Static Vulnerability Detection in Solidity Using Abstract Interpretation
    Kushwaha, Maitri
    Mukherjee, Arnab
    Pandey, Aishwarya
    Halder, Raju
    INFORMATION SYSTEMS SECURITY, ICISS 2024, 2025, 15416 : 265 - 285
  • [26] Achieving Multi-Attribute Superiority and Sybil Attack Detection in IoV: A Heuristic-Based Dynamic RSU Deployment Scheme
    Guo, Hongzhi
    Wu, Xinhan
    Yin, Zishuo
    Mao, Bomin
    Xun, Yijie
    Liu, Jiajia
    Chen, Wu
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2025, 26 (02) : 2734 - 2746
  • [27] A Novel Hybrid Approach for Intent Creation and Detection Using K-Means-Based Topic Clustering and Heuristic-Based Capsule Network
    Magoo, Chandni
    Singh, Manjeet
    INTERNATIONAL JOURNAL OF INFORMATION TECHNOLOGY & DECISION MAKING, 2023, 22 (06) : 1923 - 1960
  • [28] COMPARATIVE STUDY OF HEURISTIC-BASED SUPPORT VECTOR MACHINE AND NEURAL NETWORK FOR THERMOGRAM BREAST CANCER DETECTION WITH ENTROPY FEATURES
    Suryawanshi, Sonalee P.
    Dharmani, Bhaveshkumar C.
    BIOMEDICAL ENGINEERING-APPLICATIONS BASIS COMMUNICATIONS, 2023, 35 (02):
  • [29] Static Vulnerabilities Detection Based on Extended Vulnerability State Machine Model
    Liang, Bin
    NSWCTC 2009: INTERNATIONAL CONFERENCE ON NETWORKS SECURITY, WIRELESS COMMUNICATIONS AND TRUSTED COMPUTING, VOL 2, PROCEEDINGS, 2009, : 305 - 308
  • [30] Feature Grouping-based Outlier Detection upon Streaming Trajectories (Extended abstract)
    Mao, Jiali
    Wang, Tao
    Jin, Cheqing
    Zhou, Aoying
    2018 IEEE 34TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE), 2018, : 1745 - 1746