HPCMalHunter: Behavioral Malware Detection using Hardware Performance Counters and Singular Value Decomposition

被引:0
|
作者
Bahador, Mohammad Bagher [1 ]
Abadi, Mahdi [1 ]
Tajoddin, Asghar [1 ]
机构
[1] Tarbiat Modarcs Univ, Fac Elect & Comp Engn, Tehran, Iran
关键词
behavioral malware detection; hardware-level detection; real-time detection; hardware performance counter; singular value decomposition;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Malicious programs, also known as malware, often use code obfuscation techniques to make static analysis more difficult and to evade signature-based detection. To resolve this problem, various behavioral detection techniques have been proposed that focus on the run-time behaviors of programs in order to dynamically detect malicious ones. Most of these techniques describe the run-time behavior of a program on the basis of its data flow and/or its system call traces. Recent work in behavioral malware detection has shown promise in using hardware performance counters (HPCs), which are a set of special-purpose registers built into modern processors providing detailed information about hardware and software events. In this paper, we pursue this line of research by presenting HPCMalHunter, a novel approach for real-time behavioral malware detection. HPCMalHunter uses HPCs to collect a set of event vectors from the beginning of a program's execution. It also uses the singular value decomposition (SVD) to reduce these event vectors and generate a behavioral vector for the program. By applying support vector machines (SVMs) to the feature vectors of different programs, it is able to identify malicious programs in real-time. Our results of experiments show that HPCMalHunter can detect malicious programs at the beginning of their execution with a high detection rate and a low false alarm rate.
引用
收藏
页码:703 / 708
页数:6
相关论文
共 50 条
  • [31] Early Detection of System-Level Anomalous Behaviour using Hardware Performance Counters
    Woo, Lai Leng
    Zwolinski, Mark
    Halak, Basel
    PROCEEDINGS OF THE 2018 DESIGN, AUTOMATION & TEST IN EUROPE CONFERENCE & EXHIBITION (DATE), 2018, : 485 - 490
  • [32] Digital Video Watermarking Using Motion Detection and Singular Value Decomposition
    Sinha, Sanjana
    Pramanick, Swarnali
    Jagatramka, Ankul
    Bardhan, Prajnat
    Kole, Dipak K.
    Chakraborty, Aruna
    Communications in Computer and Information Science, 2011, 205 M4D : 229 - 238
  • [33] Image Forgery Detection Using Singular Value Decomposition with Some Attacks
    Rathore, Neeraj Kumar
    Jain, Neelesh Kumar
    Shukla, Prashant Kumar
    Rawat, UmaShankar
    Dubey, Rachana
    NATIONAL ACADEMY SCIENCE LETTERS-INDIA, 2021, 44 (04): : 331 - 338
  • [34] Image Forgery Detection Using Singular Value Decomposition with Some Attacks
    Neeraj Kumar Rathore
    Neelesh Kumar Jain
    Prashant Kumar Shukla
    UmaShankar Rawat
    Rachana Dubey
    National Academy Science Letters, 2021, 44 : 331 - 338
  • [35] Digital Video Watermarking Using Motion Detection and Singular Value Decomposition
    Sinha, Sanjana
    Pramanick, Swarnali
    Jagatramka, Ankul
    Bardhan, Prajnat
    Kole, Dipak K.
    Chakraborty, Aruna
    ADVANCES IN DIGITAL IMAGE PROCESSING AND INFORMATION TECHNOLOGY, 2011, 205 : 229 - 238
  • [36] Detecting Spectre Attacks Using Hardware Performance Counters
    Li, Congmiao
    Gaudiot, Jean-Luc
    IEEE TRANSACTIONS ON COMPUTERS, 2022, 71 (06) : 1320 - 1331
  • [37] Using singular value decomposition to improve a Genetic Algorithm's performance
    Martin, JG
    Rasheed, K
    CEC: 2003 CONGRESS ON EVOLUTIONARY COMPUTATION, VOLS 1-4, PROCEEDINGS, 2003, : 1612 - 1617
  • [38] Early Detection of Ransomware Activity based on Hardware Performance Counters
    Anand, P. Mohan
    Charan, P. V. Sai
    Shukla, Sandeep K.
    PROCEEDINGS OF 2023 AUSTRALIAN COMPUTER SCIENCE WEEK, ACSW 2023, 2023, : 10 - 17
  • [39] Plagiarism detection based on Singular Value Decomposition
    Ceska, Zdenek
    ADVANCES IN NATURAL LANGUAGE PROCESSING, PROCEEDINGS, 2008, 5221 : 108 - 119
  • [40] Detection of Resampling Based on Singular Value Decomposition
    Wang, Ran
    Ping, Xijian
    PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON IMAGE AND GRAPHICS (ICIG 2009), 2009, : 879 - 884