Automated, Reliable Zero-Day Malware Detection Based on Autoencoding Architecture

被引:12
|
作者
Kim, Chiho [1 ]
Chang, Sang-Yoon [2 ]
Kim, Jonghyun [3 ]
Lee, Dongeun [1 ]
Kim, Jinoh [1 ]
机构
[1] Texas A&M Univ, Dept Comp Sci, Commerce, TX 75428 USA
[2] Univ Colorado, Dept Comp Sci, Colorado Springs, CO 80918 USA
[3] Elect Telecommun Res Inst, Cybersecur Res Div, Daejeon 34129, South Korea
关键词
Zero-day detection; malware detection; evasion attacks; adversarial attacks; autoencoder; one-class classification; semi-supervised learning; ATTACKS;
D O I
10.1109/TNSM.2023.3251282
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
While a body of studies has been carried out for malware detection with its significance, they are often limited to known malware patterns due to the reliance on signature-based or supervised learning approaches. The semi-supervised learning approach would be an option for identifying previously unseen patterns (i.e., zero-day detection); however, our preliminary study reveals critical limitations from existing methods, including (i) the profiling-based approach using an autoencoder can provide better detection but is sensitive to the threshold setting, and (ii) one-class (OC) classification does not require a manual threshold discovery but may be limited with low detection rates. In this paper, we present a new detection method incorporating the concept of autoencoding and OC classification, designed to benefit from strong abstraction by neural networks (using an autoencoder) and the removal of the complex threshold selection (using an OC classifier). For this combined architecture, a challenge is concurrent training of the autoencoder and the OC classifier, which may cause an ill-suited learner due to no reference to malware instances. To this end, we introduce a new model selection method that discovers well-optimized models from a variety of combinations. The experimental results performed with public malware datasets (Meraz'18 and Drebin) show the effectiveness of our presented methods with up to 97.1% accuracy, comparable to the supervised learning-based detection. We also examine the impact of evading attacks using adversarial attack tools, the result of which shows resilience to malware variants with over 99% detection rates.
引用
收藏
页码:3900 / 3914
页数:15
相关论文
共 50 条
  • [21] An Adaptive Real-Time Architecture for Zero-Day Threat Detection
    Pastana Lobato, Antonio Gonzalez
    Lopez, Martin Andreoni
    Sanz, Igor Jochem
    Cardenas, Alvaro A.
    Duarte, Otto Carlos M. B.
    Pujolle, Guy
    2018 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2018,
  • [22] Adversarial Variational Modality Reconstruction and Regularization for Zero-Day Malware Variants Similarity Detection
    Molloy, Christopher
    Banks, Jeremy
    Ding, Steven H. H.
    Charland, Philippe
    Walenstein, Andrew
    Li, Litao
    2022 IEEE INTERNATIONAL CONFERENCE ON DATA MINING (ICDM), 2022, : 1131 - 1136
  • [23] IoTZeroJar: Towards a Honeypot Architecture for Detection of Zero-Day Attacks in IoT
    Ellouh, Mahmoud
    Ghaleb, Mustafa
    Felemban, Muhamad
    Proceedings - 2022 14th IEEE International Conference on Computational Intelligence and Communication Networks, CICN 2022, 2022, : 765 - 771
  • [24] An Architecture of Unknown Attack Detection System against Zero-day Worm
    Kim, Ikkyun
    Kim, Daewon
    Kim, Byoungkoo
    Choi, Yangseo
    Yoon, Seongyong
    Oh, Jintae
    Jang, Jongsoo
    PROCEEDINGS OF THE 8TH WSEAS INTERNATIONAL CONFERENCE ON APPLIED COMPUTER SCIENCE (ACS'08): RECENT ADVANCES ON APPLIED COMPUTER SCIENCE, 2008, : 205 - +
  • [25] Efficient detection of zero-day Android Malware using Normalized Bernoulli Naive Bayes
    Sayfullina, Luiza
    Eirola, Emil
    Komashinsky, Dmitry
    Palumbo, Paolo
    Miche, Yoan
    Lendasse, Amaury
    Karhunen, Juha
    2015 IEEE TRUSTCOM/BIGDATASE/ISPA, VOL 1, 2015, : 198 - 205
  • [26] Detection of Zero-day Attacks on IoT
    Reardon, Shay
    Hssayeni, Murtadha D.
    Mahgoub, Imadeldin
    2024 INTERNATIONAL CONFERENCE ON SMART APPLICATIONS, COMMUNICATIONS AND NETWORKING, SMARTNETS-2024, 2024,
  • [27] Mitigation and Detection of Zero-Day Vulnerabilities
    Sebastian Guisao, Juan
    Toro Rendon, Juan Carlos
    CUADERNO ACTIVA, 2014, (06): : 63 - 67
  • [28] Image-Based Zero-Day Malware Detection in IoMT Devices: A Hybrid AI-Enabled Method
    He, Zhangying
    Sayadi, Hossein
    2023 24TH INTERNATIONAL SYMPOSIUM ON QUALITY ELECTRONIC DESIGN, ISQED, 2023, : 82 - 89
  • [29] When Machine Learning Meets Hardware Cybersecurity: Delving into Accurate Zero-Day Malware Detection
    He, Zhangying
    Miari, Tahereh
    Makrani, Hosein Mohammadi
    Aliasgari, Mehrdad
    Homayoun, Houman
    Sayadi, Hossein
    PROCEEDINGS OF THE 2021 TWENTY SECOND INTERNATIONAL SYMPOSIUM ON QUALITY ELECTRONIC DESIGN (ISQED 2021), 2021, : 85 - 90
  • [30] A zero-day resistant malware detection method for securing Cloud using SVM and Sandboxing Techniques
    Kumar, Saket
    Singh, Chandra Bhim Bhan
    PROCEEDINGS OF THE 2018 SECOND INTERNATIONAL CONFERENCE ON INVENTIVE COMMUNICATION AND COMPUTATIONAL TECHNOLOGIES (ICICCT), 2018, : 1397 - 1402