HPCMalHunter: Behavioral Malware Detection using Hardware Performance Counters and Singular Value Decomposition

被引:0
|
作者
Bahador, Mohammad Bagher [1 ]
Abadi, Mahdi [1 ]
Tajoddin, Asghar [1 ]
机构
[1] Tarbiat Modarcs Univ, Fac Elect & Comp Engn, Tehran, Iran
关键词
behavioral malware detection; hardware-level detection; real-time detection; hardware performance counter; singular value decomposition;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Malicious programs, also known as malware, often use code obfuscation techniques to make static analysis more difficult and to evade signature-based detection. To resolve this problem, various behavioral detection techniques have been proposed that focus on the run-time behaviors of programs in order to dynamically detect malicious ones. Most of these techniques describe the run-time behavior of a program on the basis of its data flow and/or its system call traces. Recent work in behavioral malware detection has shown promise in using hardware performance counters (HPCs), which are a set of special-purpose registers built into modern processors providing detailed information about hardware and software events. In this paper, we pursue this line of research by presenting HPCMalHunter, a novel approach for real-time behavioral malware detection. HPCMalHunter uses HPCs to collect a set of event vectors from the beginning of a program's execution. It also uses the singular value decomposition (SVD) to reduce these event vectors and generate a behavioral vector for the program. By applying support vector machines (SVMs) to the feature vectors of different programs, it is able to identify malicious programs in real-time. Our results of experiments show that HPCMalHunter can detect malicious programs at the beginning of their execution with a high detection rate and a low false alarm rate.
引用
收藏
页码:703 / 708
页数:6
相关论文
共 50 条
  • [1] On the Performance of Malware Detection Classifiers Using Hardware Performance Counters
    Zeraatkar, Alireza Abolhasani
    Kamran, Parnian Shabani
    Kaur, Inderpreet
    Ramu, Nagabindu
    Sheaves, Tyler
    Al-Asaad, Hussain
    2024 INTERNATIONAL CONFERENCE ON SMART APPLICATIONS, COMMUNICATIONS AND NETWORKING, SMARTNETS-2024, 2024,
  • [2] Time Series-based Malware Detection using Hardware Performance Counters
    Kuruvila, Abraham Peedikayil
    Karmakar, Sayar
    Basu, Kanad
    2021 IEEE INTERNATIONAL SYMPOSIUM ON HARDWARE ORIENTED SECURITY AND TRUST (HOST), 2021, : 102 - 112
  • [3] Intelligent Malware Detection based on Hardware Performance Counters: A Comprehensive Survey
    Sayadi, Hossein
    He, Zhangying
    Makrani, Hosein Mohammadi
    Homayoun, Houman
    2024 25TH INTERNATIONAL SYMPOSIUM ON QUALITY ELECTRONIC DESIGN, ISQED 2024, 2024,
  • [4] A Theoretical Study of Hardware Performance Counters-Based Malware Detection
    Basu, Kanad
    Krishnamurthy, Prashanth
    Khorrami, Farshad
    Karri, Ramesh
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 : 512 - 525
  • [5] Hardware Implementation of Singular Value Decomposition
    Majumder S.
    Shaw A.K.
    Sarkar S.K.
    Journal of The Institution of Engineers (India): Series B, 2016, 97 (2) : 227 - 231
  • [6] Hardware Performance Counters Can Detect Malware: Myth or Fact?
    Zhou, Boyou
    Gupta, Anmol
    Jahanshahi, Rasoul
    Egele, Manuel
    Joshi, Ajay
    PROCEEDINGS OF THE 2018 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIACCS'18), 2018, : 457 - 468
  • [7] A Cautionary Tale About Detecting Malware Using Hardware Performance Counters and Machine Learning
    Zhou, Boyou
    Gupta, Anmol
    Jahanshahi, Rasoul
    Egele, Manuel
    Joshi, Ajay
    IEEE DESIGN & TEST, 2021, 38 (03) : 39 - 50
  • [8] A Cautionary Tale about Detecting Malware Using Hardware Performance Counters and Machine Learning
    Zhou, Boyou
    Gupta, Anmol
    Jahanshahi, Rasoul
    Egele, Manuel
    Joshi, Ajay
    IEEE Design and Test, 2021, 38 (03): : 39 - 50
  • [9] High-performance Hardware Architecture for Tensor Singular Value Decomposition
    Deng, Chunhua
    Yin, Miao
    Liu, Xiao-Yang
    Wang, Xiaodong
    Yuan, Bo
    2019 IEEE/ACM INTERNATIONAL CONFERENCE ON COMPUTER-AIDED DESIGN (ICCAD), 2019,
  • [10] Automated malware identification method using image descriptors and singular value decomposition
    Tuncer, Turker
    Ertam, Fatih
    Dogan, Sengul
    MULTIMEDIA TOOLS AND APPLICATIONS, 2021, 80 (07) : 10881 - 10900