Hardware-Based Malware Detection Using Low-Level Architectural Features

被引:63
|
作者
Ozsoy, Meltem [1 ]
Khasawneh, Khaled N. [2 ]
Donovick, Caleb [3 ]
Gorelik, Iakov [3 ]
Abu-Ghazaleh, Nael [2 ]
Ponomarev, Dmitry [3 ]
机构
[1] Intel Corp, Secur & Privacy Lab, Hillsboro, OR 97124 USA
[2] Univ Calif Riverside, CSE & ECE Dept, Riverside, CA 92521 USA
[3] SUNY Binghamton, CS Dept, Binghamton, NY 13902 USA
基金
美国国家科学基金会;
关键词
Malware detection; architecture; security; low-level features;
D O I
10.1109/TC.2016.2540634
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security exploits and ensuant malware pose an increasing challenge to computing systems as the variety and complexity of attacks continue to increase. In response, software-based malware detection tools have grown in complexity, thus making it computationally difficult to use them to protect systems in real-time. Therefore, software detectors are applied selectively and at a low frequency, creating opportunities for malware to remain undetected. In this paper, we propose Malware-Aware Processors ( MAP)processors augmented with a hardware-based online malware detector to serve as the first line of defense to differentiate malware from legitimate programs. The output of this detector helps the system prioritize how to apply more expensive software-based solutions. The always-on nature of MAP detector helps protect against intermittently operating malware. We explore the use of different features for classification and study both logistic regression and neural networks. We show that the detectors can achieve excellent performance, with little hardware overhead. We integrate the MAP implementation with an open-source x86-compatible core, synthesizing the resulting design to run on an FPGA.
引用
收藏
页码:3332 / 3344
页数:13
相关论文
共 50 条
  • [41] A film classifier based on low-level visual features
    Huang, Hui-Yu
    Shih, Weir-Sheng
    Hsu, Wen-Hsing
    2007 IEEE NINTH WORKSHOP ON MULTIMEDIA SIGNAL PROCESSING, 2007, : 465 - +
  • [42] Using low-level architectural features for configuration infosec in a general-purpose self-configurable system
    Macias, Nicholas J.
    Athanas, Peter M.
    International Journal of u- and e- Service, Science and Technology, 2009, 2 (04) : 17 - 28
  • [43] Using Existing Hardware Services for Malware Detection
    Kompalli, Sarat
    2014 IEEE SECURITY AND PRIVACY WORKSHOPS (SPW 2014), 2014, : 204 - 208
  • [44] SCARF: Detecting Side-Channel Attacks at Real-time using Low-level Hardware Features
    Wang, Han
    Sayadi, Hossein
    Rafatirad, Setareh
    Sasan, Avesta
    Homayoun, Houman
    2020 26TH IEEE INTERNATIONAL SYMPOSIUM ON ON-LINE TESTING AND ROBUST SYSTEM DESIGN (IOLTS 2020), 2020,
  • [45] Hardware-Based Hopfield Neuromorphic Computing for Fall Detection
    Yu, Zheqi
    Zahid, Adnan
    Ansari, Shuja
    Abbas, Hasan
    Abdulghani, Amir M.
    Heidari, Hadi
    Imran, Muhammad A.
    Abbasi, Qammer H.
    SENSORS, 2020, 20 (24) : 1 - 16
  • [46] The Design and Analysis of a Hardware-based Anomaly Detection Scheme
    Piao, JinLong
    Kim, Seong Baeg
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2012, 6 (02): : 367 - 372
  • [47] On a graphics hardware-based vortex detection and visualization system
    S. Stegmaier
    T. Ertl
    Journal of Visualization, 2005, 8 : 153 - 160
  • [48] Hardware-based Detection of Malicious Firmware Modification in Microgrids
    Srivastava, Amisha
    Thakur, Sneha
    Kuruvila, Abraham Peedikayil
    Balsara, Poras T.
    Basu, Kanad
    PROCEEDINGS OF THE 37TH INTERNATIONAL CONFERENCE ON VLSI DESIGN, VLSID 2024 AND 23RD INTERNATIONAL CONFERENCE ON EMBEDDED SYSTEMS, ES 2024, 2024, : 186 - 191
  • [49] A New Curriculum for Hardware-Based Network Intrusion Detection
    Lo, Dan
    Wang, Andy
    North, Sarah
    North, Max
    PROCEEDINGS OF THE 49TH ANNUAL ASSOCIATION FOR COMPUTING MACHINERY SOUTHEAST CONFERENCE (ACMSE '11), 2011, : 318 - 319
  • [50] An efficient hardware-based design for network intrusion detection
    Department of Electronics Engineering, Ching Yun University, Chungli 320, Taiwan
    WSEAS Trans. Electron., 2007, 3 (49-55):