An Adversarial Robust Behavior Sequence Anomaly Detection Approach Based on Critical Behavior Unit Learning

被引:4
|
作者
Zhan, Dongyang [1 ]
Tan, Kai [1 ]
Ye, Lin [1 ]
Yu, Xiangzhan [1 ]
Zhang, Hongli [1 ]
He, Zheng [2 ]
机构
[1] Harbin Inst Technol, Sch Cyberspace Sci, Harbin 150001, Heilongjiang, Peoples R China
[2] Heilongjiang Meteorol Bur, Harbin 150001, Heilongjiang, Peoples R China
基金
黑龙江省自然科学基金; 中国国家自然科学基金; 国家重点研发计划;
关键词
Adversarial attacks; anomaly detection; deep learning; behavior unit extraction; malware detection; MALWARE DETECTION;
D O I
10.1109/TC.2023.3292001
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Sequential deep learning models (e.g., RNN and LSTM) can learn the sequence features of software behaviors, such as API or syscall sequences. However, recent studies have shown that these deep learning-based approaches are vulnerable to adversarial samples. Attackers can use adversarial samples to change the sequential characteristics of behavior sequences and mislead malware classifiers. In this paper, an adversarial robustness anomaly detection method based on the analysis of behavior units is proposed to overcome this problem. We extract related behaviors that usually perform a behavior intention as a behavior unit, which contains the representative semantic information of local behaviors and can be used to improve the robustness of behavior analysis. By learning the overall semantics of each behavior unit and the contextual relationships among behavior units based on a multilevel deep learning model, our approach can mitigate perturbation attacks that target local and large-scale behaviors. In addition, our approach can be applied to both low-level and high-level behavior logs (e.g., API and syscall logs). The experimental results show that our approach outperforms all the compared methods, which indicates that our approach has better performance against obfuscation attacks.
引用
收藏
页码:3286 / 3299
页数:14
相关论文
共 50 条
  • [21] A Graph Embedding Approach to User Behavior Anomaly Detection
    Modell, Alexander
    Larson, Jonathan
    Turcotte, Melissa
    Bertiger, Anna
    2021 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2021, : 2650 - 2655
  • [22] Anomaly behavior detection analysis in video surveillance: a critical review
    Roka, Sanjay
    Diwakar, Manoj
    Singh, Prabhishek
    Singh, Pragya
    JOURNAL OF ELECTRONIC IMAGING, 2023, 32 (04)
  • [23] Robust Anomaly Detection Using Reconstructive Adversarial Network
    Nie, Lihai
    Zhao, Laiping
    Li, Keqiu
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (02): : 1899 - 1912
  • [24] Robust Anomaly Detection in Images Using Adversarial Autoencoders
    Beggel, Laura
    Pfeiffer, Michael
    Bischl, Bernd
    MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES, ECML PKDD 2019, PT I, 2020, 11906 : 206 - 222
  • [25] Robust anomaly detection via adversarial counterfactual generation
    Liguori, Angelica
    Ritacco, Ettore
    Pisani, Francesco Sergio
    Manco, Giuseppe
    KNOWLEDGE AND INFORMATION SYSTEMS, 2024, 66 (12) : 7437 - 7468
  • [26] Pattern Anomaly Detection based on Sequence-to-Sequence Regularity Learning
    Cheng, Yuzhen
    LI, Min
    TEHNICKI VJESNIK-TECHNICAL GAZETTE, 2023, 30 (04): : 1112 - 1117
  • [27] Unsupervised Adversarial Learning of Anomaly Detection in the Wild
    Berg, Amanda
    Felsberg, Michael
    Ahlberg, Jorgen
    ECAI 2020: 24TH EUROPEAN CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2020, 325 : 1002 - 1008
  • [28] Stream Learning and Anomaly-based Intrusion Detection in the Adversarial Settings
    Viegas, Eduardo
    Santin, Altair
    Abreu, Vilmar
    Oliveira, Luiz S.
    2017 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (ISCC), 2017, : 773 - 778
  • [29] Multimodal Adversarial Learning Based Unsupervised Time Series Anomaly Detection
    Huang X.
    Zhang F.
    Fan H.
    Xi L.
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2021, 58 (08): : 1655 - 1667
  • [30] Traffic Anomaly Detection Based on Robust Principal Component Analysis Using Periodic Traffic Behavior
    Matsuda, Takahiro
    Morita, Tatsuya
    Kudo, Takanori
    Takine, Tetsuya
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2017, E100B (05) : 749 - 761