HPCMalHunter: Behavioral Malware Detection using Hardware Performance Counters and Singular Value Decomposition

被引:0
|
作者
Bahador, Mohammad Bagher [1 ]
Abadi, Mahdi [1 ]
Tajoddin, Asghar [1 ]
机构
[1] Tarbiat Modarcs Univ, Fac Elect & Comp Engn, Tehran, Iran
关键词
behavioral malware detection; hardware-level detection; real-time detection; hardware performance counter; singular value decomposition;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Malicious programs, also known as malware, often use code obfuscation techniques to make static analysis more difficult and to evade signature-based detection. To resolve this problem, various behavioral detection techniques have been proposed that focus on the run-time behaviors of programs in order to dynamically detect malicious ones. Most of these techniques describe the run-time behavior of a program on the basis of its data flow and/or its system call traces. Recent work in behavioral malware detection has shown promise in using hardware performance counters (HPCs), which are a set of special-purpose registers built into modern processors providing detailed information about hardware and software events. In this paper, we pursue this line of research by presenting HPCMalHunter, a novel approach for real-time behavioral malware detection. HPCMalHunter uses HPCs to collect a set of event vectors from the beginning of a program's execution. It also uses the singular value decomposition (SVD) to reduce these event vectors and generate a behavioral vector for the program. By applying support vector machines (SVMs) to the feature vectors of different programs, it is able to identify malicious programs in real-time. Our results of experiments show that HPCMalHunter can detect malicious programs at the beginning of their execution with a high detection rate and a low false alarm rate.
引用
收藏
页码:703 / 708
页数:6
相关论文
共 50 条
  • [11] Automated malware identification method using image descriptors and singular value decomposition
    Turker Tuncer
    Fatih Ertam
    Sengul Dogan
    Multimedia Tools and Applications, 2021, 80 : 10881 - 10900
  • [12] Community detection in graphs using singular value decomposition
    Sarkar, Somwrita
    Dong, Andy
    PHYSICAL REVIEW E, 2011, 83 (04)
  • [13] Image Splicing Detection Using Singular Value Decomposition
    Moghaddasi, Zahra
    Jalab, Hamid A.
    Noor, Rafidah Md
    PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON INTERNET OF THINGS, DATA AND CLOUD COMPUTING (ICC 2017), 2017,
  • [14] Community detection in graphs using singular value decomposition
    Sarkar, Somwrita
    Dong, Andy
    Physical Review E - Statistical, Nonlinear, and Soft Matter Physics, 2011, 83 (04):
  • [15] Malicious Firmware Detection with Hardware Performance Counters
    Wang, Xueyang
    Konstantinou, Charalambos
    Maniatakos, Michail
    Karri, Ramesh
    Lee, Serena
    Robison, Patricia
    Stergiou, Paul
    Kim, Steve
    IEEE TRANSACTIONS ON MULTI-SCALE COMPUTING SYSTEMS, 2016, 2 (03): : 160 - 173
  • [16] Hardware Performance Counters based Runtime Anomaly Detection using SVM
    Bin Abbas, Muhamed Fauzi
    Kadiyala, Sai Praveen
    Prakash, Alok
    Srikanthan, Thambipillai
    Aung, Yan Lin
    2017 TRON SYMPOSIUM (TRONSHOW), 2017,
  • [17] On the Detection of Kernel-Level Rootkits Using Hardware Performance Counters
    Singh, Baljit
    Evtyushkin, Dmitry
    Elwell, Jesse
    Riley, Ryan
    Cervesato, Iliana
    PROCEEDINGS OF THE 2017 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIA CCS'17), 2017, : 483 - 493
  • [18] Run-Time Hardware Trojan Detection Using Performance Counters
    Elnaggar, Rana
    Chakrabarty, Krishnendu
    Tahoori, Mehdi B.
    2017 IEEE INTERNATIONAL TEST CONFERENCE (ITC), 2017,
  • [19] HiPeR - Early Detection of a Ransomware Attack using Hardware Performance Counters
    Anand, P. Mohan
    Charan, P. V. Sai
    Shukla, Sandeep K.
    DIGITAL THREATS: RESEARCH AND PRACTICE, 2023, 4 (03):
  • [20] DeCrypto Pro: Deep Learning Based Cryptomining Malware Detection Using Performance Counters
    Mani, Ganapathy
    Pasumarti, Vikram
    Bhargava, Bharat
    Vora, Faisal Tariq
    MacDonald, James
    King, Justin
    Kobes, Jason
    2020 IEEE INTERNATIONAL CONFERENCE ON AUTONOMIC COMPUTING AND SELF-ORGANIZING SYSTEMS (ACSOS 2020), 2020, : 109 - 118