Hardware-Based Malware Detection Using Low-Level Architectural Features

被引:63
|
作者
Ozsoy, Meltem [1 ]
Khasawneh, Khaled N. [2 ]
Donovick, Caleb [3 ]
Gorelik, Iakov [3 ]
Abu-Ghazaleh, Nael [2 ]
Ponomarev, Dmitry [3 ]
机构
[1] Intel Corp, Secur & Privacy Lab, Hillsboro, OR 97124 USA
[2] Univ Calif Riverside, CSE & ECE Dept, Riverside, CA 92521 USA
[3] SUNY Binghamton, CS Dept, Binghamton, NY 13902 USA
基金
美国国家科学基金会;
关键词
Malware detection; architecture; security; low-level features;
D O I
10.1109/TC.2016.2540634
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security exploits and ensuant malware pose an increasing challenge to computing systems as the variety and complexity of attacks continue to increase. In response, software-based malware detection tools have grown in complexity, thus making it computationally difficult to use them to protect systems in real-time. Therefore, software detectors are applied selectively and at a low frequency, creating opportunities for malware to remain undetected. In this paper, we propose Malware-Aware Processors ( MAP)processors augmented with a hardware-based online malware detector to serve as the first line of defense to differentiate malware from legitimate programs. The output of this detector helps the system prioritize how to apply more expensive software-based solutions. The always-on nature of MAP detector helps protect against intermittently operating malware. We explore the use of different features for classification and study both logistic regression and neural networks. We show that the detectors can achieve excellent performance, with little hardware overhead. We integrate the MAP implementation with an open-source x86-compatible core, synthesizing the resulting design to run on an FPGA.
引用
收藏
页码:3332 / 3344
页数:13
相关论文
共 50 条
  • [1] A Survey on Hardware-Based Malware Detection Approaches
    Chenet, Cristiano Pegoraro
    Savino, Alessandro
    Di Carlo, Stefano
    IEEE ACCESS, 2024, 12 : 54115 - 54128
  • [2] Hardware-based Workload Forensics and Malware Detection in Microprocessors
    Zhou, Liwei
    Makris, Yiorgos
    2016 17TH INTERNATIONAL WORKSHOP ON MICROPROCESSOR AND SOC TEST AND VERIFICATION (MTV), 2016, : 45 - 50
  • [3] Runtime Malware Detection using hardware features
    Sanjith, S.
    Sivaraman, E.
    Honnavalli, Prasad B.
    2019 10TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2019,
  • [4] Multinomial malware classification via low-level features
    Banin, Sergii
    Dyrkolbotn, Geir Olav
    DIGITAL INVESTIGATION, 2018, 26 : S107 - S117
  • [5] Real-Time Hardware-Based Malware and Micro-Architectural Attack Detection Utilizing CMOS Reservoir Computing
    Chandrasekaran, Sanjeev Tannirkulam
    Kuruvila, Abraham Peedikayil
    Basu, Kanad
    Sanyal, Arindam
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS II-EXPRESS BRIEFS, 2022, 69 (02) : 349 - 353
  • [6] A Saliency Detection Model Using Low-Level Features Based on Wavelet Transform
    Imamoglu, Nevrez
    Lin, Weisi
    Fang, Yuming
    IEEE TRANSACTIONS ON MULTIMEDIA, 2013, 15 (01) : 96 - 105
  • [7] Violence detection in surveillance video using low-level features
    Zhou, Peipei
    Ding, Qinghai
    Luo, Haibo
    Hou, Xinglin
    PLOS ONE, 2018, 13 (10):
  • [8] Image orientation detection using low-level features and faces
    Ciocca, Gianluigi
    Cusano, Claudio
    Schettini, Raimondo
    DIGITAL PHOTOGRAPHY VI, 2010, 7537
  • [9] Quantifying and Improving the Efficiency of Hardware-based Mobile Malware Detectors
    Kazdagli, Mikhail
    Reddi, Vijay Janapa
    Tiwari, Mohit
    2016 49TH ANNUAL IEEE/ACM INTERNATIONAL SYMPOSIUM ON MICROARCHITECTURE (MICRO), 2016,
  • [10] Defending Hardware-Based Malware Detectors Against Adversarial Attacks
    Kuruvila, Abraham Peedikayil
    Kundu, Shamik
    Basu, Kanad
    IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2021, 40 (09) : 1727 - 1739