MultiEvasion: Evasion Attacks Against Multiple Malware Detectors

被引:0
|
作者
Liu, Hao [1 ]
Sun, Wenhai [2 ]
Niu, Nan [1 ]
Wang, Boyang [1 ]
机构
[1] Univ Cincinnati, Cincinnati, OH 45221 USA
[2] Purdue Univ, W Lafayette, IN 47907 USA
基金
美国国家科学基金会;
关键词
D O I
10.1109/CNS56114.2022.9947227
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
End-to-end malware detection analyzes raw bytes of programs with deep neural networks. It is considered as a new promising approach to simplify feature selection in static analysis but still provide accurate detection. Unfortunately, recent studies show that evasion attacks can modify raw bytes of malware and force a well-trained detector to predict the crafted malware as benign. In this paper, we propose a new evasion attack and validate the vulnerability of end-to-end malware detection in the context of multiple detectors, where our evasion attack MultiEvasion can defeat two (or even three) classifiers simultaneously without affecting functionalities of malware. This raises emerging concerns to end-to-end malware detection as running multiple classifiers was considered as one of the major countermeasures against evasion attacks. Specifically, our experimental results over real-world datasets show that our proposed attack can achieve 99.5% evasion rate against two classifiers and 18.3% evasion rate against three classifiers. Our findings suggest that the security of end-to-end malware detection need to be carefully examined before being applied in the real world.
引用
收藏
页码:10 / 18
页数:9
相关论文
共 50 条
  • [41] Securing Malware Cognitive Systems against Adversarial Attacks
    Ti, Yuede
    Bowman, Benjamin
    Huang, H. Howie
    2019 IEEE INTERNATIONAL CONFERENCE ON COGNITIVE COMPUTING (IEEE ICCC 2019), 2019, : 1 - 9
  • [42] An Efficient Recovery and Survival Scheme against Malware Attacks
    Sun, Xianjun
    Lin, Chuang
    Jiang, Yixin
    Liu, Weidong
    Chu, Xiaowen
    2010 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS - ICC 2010, 2010,
  • [43] Stronger Targeted Poisoning Attacks Against Malware Detection
    Narisada, Shintaro
    Sasaki, Shoichiro
    Hidano, Seira
    Uchibayashi, Toshihiro
    Suganuma, Takuo
    Hiji, Masahiro
    Kiyomoto, Shinsaku
    CRYPTOLOGY AND NETWORK SECURITY, CANS 2020, 2020, 12579 : 65 - 84
  • [44] Towards a Practical Defense Against Adversarial Attacks on Deep Learning-Based Malware Detectors via Randomized Smoothing
    Gibert, Daniel
    Zizzo, Giulio
    Le, Quan
    COMPUTER SECURITY. ESORICS 2023 INTERNATIONAL WORKSHOPS, CPS4CIP, PT II, 2024, 14399 : 683 - 699
  • [45] When a Tree Falls: Using Diversity in Ensemble Classifiers to Identify Evasion in Malware Detectors
    Smutz, Charles
    Stavrou, Angelos
    23RD ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2016), 2016,
  • [46] Are Malware Detection Classifiers Adversarially Vulnerable to Actor-Critic based Evasion Attacks?
    Rathore, Hemant
    Sharma, Sujay C.
    Sahay, Sanjay K.
    Sewak, Mohit
    EAI ENDORSED TRANSACTIONS ON SCALABLE INFORMATION SYSTEMS, 2022, 10 (01):
  • [47] Quantifying the Impact of Adversarial Evasion Attacks on Machine Learning Based Android Malware Classifiers
    Abaid, Zainab
    Kaafar, Mohamed Ali
    Jha, Sanjay
    2017 IEEE 16TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2017, : 375 - 384
  • [48] Single-Shot Black-Box Adversarial Attacks Against Malware Detectors: A Causal Language Model Approach
    Hu, James Lee
    Ebrahimi, Mohammadreza
    Chen, Hsinchun
    2021 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS (ISI), 2021, : 7 - 12
  • [49] A Hybrid Approach to Defend against Adversarial Evasion Attacks
    Jung, Kuchul
    Woo, Jongseok
    Mukhopadhyay, Saibal
    2024 IEEE 67TH INTERNATIONAL MIDWEST SYMPOSIUM ON CIRCUITS AND SYSTEMS, MWSCAS 2024, 2024, : 919 - 922
  • [50] Malware Analysis by Combining Multiple Detectors and Observation Windows
    Ficco, Massimo
    IEEE TRANSACTIONS ON COMPUTERS, 2022, 71 (06) : 1276 - 1290