HPCMalHunter: Behavioral Malware Detection using Hardware Performance Counters and Singular Value Decomposition

被引:0
|
作者
Bahador, Mohammad Bagher [1 ]
Abadi, Mahdi [1 ]
Tajoddin, Asghar [1 ]
机构
[1] Tarbiat Modarcs Univ, Fac Elect & Comp Engn, Tehran, Iran
关键词
behavioral malware detection; hardware-level detection; real-time detection; hardware performance counter; singular value decomposition;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Malicious programs, also known as malware, often use code obfuscation techniques to make static analysis more difficult and to evade signature-based detection. To resolve this problem, various behavioral detection techniques have been proposed that focus on the run-time behaviors of programs in order to dynamically detect malicious ones. Most of these techniques describe the run-time behavior of a program on the basis of its data flow and/or its system call traces. Recent work in behavioral malware detection has shown promise in using hardware performance counters (HPCs), which are a set of special-purpose registers built into modern processors providing detailed information about hardware and software events. In this paper, we pursue this line of research by presenting HPCMalHunter, a novel approach for real-time behavioral malware detection. HPCMalHunter uses HPCs to collect a set of event vectors from the beginning of a program's execution. It also uses the singular value decomposition (SVD) to reduce these event vectors and generate a behavioral vector for the program. By applying support vector machines (SVMs) to the feature vectors of different programs, it is able to identify malicious programs in real-time. Our results of experiments show that HPCMalHunter can detect malicious programs at the beginning of their execution with a high detection rate and a low false alarm rate.
引用
收藏
页码:703 / 708
页数:6
相关论文
共 50 条
  • [21] Automatic Logo Detection and Extraction using Singular Value Decomposition
    Dixit, Umesh D.
    Shirdhonkar, M. S.
    2016 INTERNATIONAL CONFERENCE ON COMMUNICATION AND SIGNAL PROCESSING (ICCSP), VOL. 1, 2016, : 787 - 790
  • [22] Video shot boundary detection using singular value decomposition
    Cerneková, Z
    Kotropoulos, C
    Pitas, I
    DIGITAL MEDIA: PROCESSING MULTIMEDIA INTERACTIVE SERVICES, 2003, : 53 - 58
  • [23] Wavelet based corner detection using singular value decomposition
    Quddus, A
    Gabbouj, M
    2000 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING, PROCEEDINGS, VOLS I-VI, 2000, : 2227 - 2230
  • [24] Demand-Driven Software Race Detection using Hardware Performance Counters
    Greathouse, Joseph L.
    Ma, Zhiqiang
    Frank, Matthew I.
    Peri, Ramesh
    Austin, Todd
    ISCA 2011: PROCEEDINGS OF THE 38TH ANNUAL INTERNATIONAL SYMPOSIUM ON COMPUTER ARCHITECTURE, 2011, : 165 - 176
  • [25] Singular value decomposition and metamorphic detection
    Jidigam, Ranjith Kumar
    Austin, Thomas H.
    Stamp, Mark
    JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2015, 11 (04) : 203 - 216
  • [26] Hardware Performance Counters for Embedded Software Anomaly Detection
    Ott, Karl
    Mahapatra, Rabi
    2018 16TH IEEE INT CONF ON DEPENDABLE, AUTONOM AND SECURE COMP, 16TH IEEE INT CONF ON PERVAS INTELLIGENCE AND COMP, 4TH IEEE INT CONF ON BIG DATA INTELLIGENCE AND COMP, 3RD IEEE CYBER SCI AND TECHNOL CONGRESS (DASC/PICOM/DATACOM/CYBERSCITECH), 2018, : 528 - 535
  • [27] Using Existing Hardware Services for Malware Detection
    Kompalli, Sarat
    2014 IEEE SECURITY AND PRIVACY WORKSHOPS (SPW 2014), 2014, : 204 - 208
  • [28] Runtime Malware Detection using hardware features
    Sanjith, S.
    Sivaraman, E.
    Honnavalli, Prasad B.
    2019 10TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2019,
  • [29] Fight Hardware with Hardware: Systemwide Detection and Mitigation of Side-channel Attacks Using Performance Counters
    Carna, Stefano
    Ferracci, Serena
    Quaglia, Francesco
    Pellegrini, Alessandro
    DIGITAL THREATS: RESEARCH AND PRACTICE, 2023, 4 (01):
  • [30] REDUCED-COMPLEXITY SINGULAR VALUE DECOMPOSITION FOR TUCKER DECOMPOSITION: ALGORITHM AND HARDWARE
    Hu, Xiaofeng
    Deng, Chunhua
    Yuan, Bo
    2020 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING, 2020, : 1793 - 1797