Hardware-Based Malware Detection Using Low-Level Architectural Features

被引:63
|
作者
Ozsoy, Meltem [1 ]
Khasawneh, Khaled N. [2 ]
Donovick, Caleb [3 ]
Gorelik, Iakov [3 ]
Abu-Ghazaleh, Nael [2 ]
Ponomarev, Dmitry [3 ]
机构
[1] Intel Corp, Secur & Privacy Lab, Hillsboro, OR 97124 USA
[2] Univ Calif Riverside, CSE & ECE Dept, Riverside, CA 92521 USA
[3] SUNY Binghamton, CS Dept, Binghamton, NY 13902 USA
基金
美国国家科学基金会;
关键词
Malware detection; architecture; security; low-level features;
D O I
10.1109/TC.2016.2540634
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security exploits and ensuant malware pose an increasing challenge to computing systems as the variety and complexity of attacks continue to increase. In response, software-based malware detection tools have grown in complexity, thus making it computationally difficult to use them to protect systems in real-time. Therefore, software detectors are applied selectively and at a low frequency, creating opportunities for malware to remain undetected. In this paper, we propose Malware-Aware Processors ( MAP)processors augmented with a hardware-based online malware detector to serve as the first line of defense to differentiate malware from legitimate programs. The output of this detector helps the system prioritize how to apply more expensive software-based solutions. The always-on nature of MAP detector helps protect against intermittently operating malware. We explore the use of different features for classification and study both logistic regression and neural networks. We show that the detectors can achieve excellent performance, with little hardware overhead. We integrate the MAP implementation with an open-source x86-compatible core, synthesizing the resulting design to run on an FPGA.
引用
收藏
页码:3332 / 3344
页数:13
相关论文
共 50 条
  • [21] Combination of high-level features with low-level features for detection of pedestrian
    Takarli, Fariba
    Aghagolzadeh, Ali
    Seyedarabi, Hadi
    SIGNAL IMAGE AND VIDEO PROCESSING, 2016, 10 (01) : 93 - 101
  • [22] Combination of high-level features with low-level features for detection of pedestrian
    Fariba Takarli
    Ali Aghagolzadeh
    Hadi Seyedarabi
    Signal, Image and Video Processing, 2016, 10 : 93 - 101
  • [23] Deep Neural Network and Transfer Learning for Accurate Hardware-Based Zero-Day Malware Detection
    He, Zhangying
    Rezaei, Amin
    Homayoun, Houman
    Sayadi, Hossein
    PROCEEDINGS OF THE 32ND GREAT LAKES SYMPOSIUM ON VLSI 2022, GLSVLSI 2022, 2022, : 27 - 32
  • [24] Ensemble Learning for Effective Run-Time Hardware-Based Malware Detection: A Comprehensive Analysis and Classification
    Sayadi, Hossein
    Patel, Nisarg
    Manoj, Sai P. D.
    Sasan, Avesta
    Rafatirad, Setareh
    Homayoun, Houman
    2018 55TH ACM/ESDA/IEEE DESIGN AUTOMATION CONFERENCE (DAC), 2018,
  • [25] Low-Level Image Features for Stamps Detection and Classification
    Forczmanski, Pawel
    Markiewicz, Andrzej
    PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON COMPUTER RECOGNITION SYSTEMS CORES 2013, 2013, 226 : 383 - 392
  • [26] Image Saliency Detection with Low-Level Features Enhancement
    Zhao, Ting
    Wu, Xiangqian
    PATTERN RECOGNITION AND COMPUTER VISION (PRCV 2018), PT I, 2018, 11256 : 408 - 419
  • [27] Multiple Lane Boundary Detection Using A Combination of Low-Level Image Features
    Li, Yingmao
    Iqbal, Asif
    Gans, Nicholas R.
    2014 IEEE 17TH INTERNATIONAL CONFERENCE ON INTELLIGENT TRANSPORTATION SYSTEMS (ITSC), 2014, : 1682 - 1687
  • [28] Fast and effective pedestrian detection based on low-level visual features combination
    Qaid, Tawfik M. A.
    Loukil, Abdelhamid
    El Boudadi, Lahouari Kaddour
    Mohammed, Adam A. Q.
    JOURNAL OF ELECTRONIC IMAGING, 2022, 31 (04)
  • [29] Change Detection Based on Low-Level to High-Level Features Integration With Limited Samples
    Wang, Xin
    Du, Peijun
    Chen, Dongmei
    Liu, Sicong
    Zhang, Wei
    Li, Erzhu
    IEEE JOURNAL OF SELECTED TOPICS IN APPLIED EARTH OBSERVATIONS AND REMOTE SENSING, 2020, 13 : 6260 - 6276
  • [30] Detecting Data Exploits Using Low-level Hardware Information
    Liu, Chen
    Yang, Zhiliu
    Blasingame, Zander
    Torres, Gildo
    Bruska, James
    PROCEEDINGS OF THE FIRST WORKSHOP ON RADICAL AND EXPERIENTIAL SECURITY (RESEC'18), 2018, : 41 - 47