An Adversarial Robust Behavior Sequence Anomaly Detection Approach Based on Critical Behavior Unit Learning

被引:4
|
作者
Zhan, Dongyang [1 ]
Tan, Kai [1 ]
Ye, Lin [1 ]
Yu, Xiangzhan [1 ]
Zhang, Hongli [1 ]
He, Zheng [2 ]
机构
[1] Harbin Inst Technol, Sch Cyberspace Sci, Harbin 150001, Heilongjiang, Peoples R China
[2] Heilongjiang Meteorol Bur, Harbin 150001, Heilongjiang, Peoples R China
基金
黑龙江省自然科学基金; 中国国家自然科学基金; 国家重点研发计划;
关键词
Adversarial attacks; anomaly detection; deep learning; behavior unit extraction; malware detection; MALWARE DETECTION;
D O I
10.1109/TC.2023.3292001
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Sequential deep learning models (e.g., RNN and LSTM) can learn the sequence features of software behaviors, such as API or syscall sequences. However, recent studies have shown that these deep learning-based approaches are vulnerable to adversarial samples. Attackers can use adversarial samples to change the sequential characteristics of behavior sequences and mislead malware classifiers. In this paper, an adversarial robustness anomaly detection method based on the analysis of behavior units is proposed to overcome this problem. We extract related behaviors that usually perform a behavior intention as a behavior unit, which contains the representative semantic information of local behaviors and can be used to improve the robustness of behavior analysis. By learning the overall semantics of each behavior unit and the contextual relationships among behavior units based on a multilevel deep learning model, our approach can mitigate perturbation attacks that target local and large-scale behaviors. In addition, our approach can be applied to both low-level and high-level behavior logs (e.g., API and syscall logs). The experimental results show that our approach outperforms all the compared methods, which indicates that our approach has better performance against obfuscation attacks.
引用
收藏
页码:3286 / 3299
页数:14
相关论文
共 50 条
  • [1] Learning-Based Robust Anomaly Detection in the Presence of Adversarial Attacks
    Zhong, Chen
    Gursoy, M. Cenk
    Velipasalar, Senem
    2022 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2022, : 1206 - 1211
  • [2] Behavior Profiling for Robust Anomaly Detection
    Hsiao, Shun-Wen
    Sun, Yeali S.
    Chen, Meng Chang
    Zhang, Hui
    2010 IEEE INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND INFORMATION SECURITY (WCNIS), VOL 1, 2010, : 465 - +
  • [3] A User Behavior Anomaly Detection Approach based on Sequence Mining over Data Streams
    Zhou, Yong
    Wang, Yijie
    Ma, Xingkong
    2016 17TH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED COMPUTING, APPLICATIONS AND TECHNOLOGIES (PDCAT), 2016, : 376 - 381
  • [4] Contextual Sequence-Based User Behavior Anomaly Detection
    Gonzales, Omar
    Yang, Kwangsoo
    Huang, Shihong
    IEEE ACCESS, 2025, 13 : 35539 - 35554
  • [5] Robust Behavior Cloning with Adversarial Demonstration Detection
    Hussein, Mostafa
    Crowe, Brendan
    Clark-Turner, Madison
    Gesel, Paul
    Petrik, Marek
    Begum, Momotaz
    2021 IEEE/RSJ INTERNATIONAL CONFERENCE ON INTELLIGENT ROBOTS AND SYSTEMS (IROS), 2021, : 7858 - 7864
  • [6] A Martingale-based Approach for Flight Behavior Anomaly Detection
    Ho, Shen-Shyang
    Schofield, Matthew
    Sun, Bo
    Snouffer, Jason M.
    Kirschner, Jean R.
    2019 20TH INTERNATIONAL CONFERENCE ON MOBILE DATA MANAGEMENT (MDM 2019), 2019, : 43 - 52
  • [7] Robust Clustering and Anomaly Detection of User Electricity Consumption Behavior Based on Correntropy
    Zhang, Teng
    Qian, Xusheng
    Zhou, Yu
    Xu, Gaojun
    Wu, Ming
    IET GENERATION TRANSMISSION & DISTRIBUTION, 2025, 19 (01)
  • [8] PCA-Based Robust Anomaly Detection Using Periodic Traffic Behavior
    Kudo, Takanori
    Morita, Tatsuya
    Matsuda, Takahiro
    Takine, Tetsuya
    2013 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS WORKSHOPS (IEEE ICC), 2013, : 1330 - 1334
  • [9] Adversarial Discriminative Attention for Robust Anomaly Detection
    Kimura, Daiki
    Chaudhury, Subhajit
    Narita, Minori
    Munawar, Asim
    Tachibana, Ryuki
    2020 IEEE WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV), 2020, : 2161 - 2170
  • [10] Anomaly prediction of Internet behavior based on generative adversarial networks
    Wang, XiuQing
    An, Yang
    Hu, Qianwei
    PeerJ Computer Science, 2024, 10