A Multi-Dimensional Deep Learning Framework for IoT Malware Classification and Family Attribution

被引:44
|
作者
Dib, Mirabelle [1 ]
Torabi, Sadegh [1 ]
Bou-Harb, Elias [2 ]
Assi, Chadi [1 ]
机构
[1] Concordia Inst Informat Syst Engn, Cyber Secur Res Ctr, Montreal, PQ H3G 1M8, Canada
[2] Univ Texas San Antonio, Cyber Ctr Secur & Analyt, San Antonio, TX 78249 USA
基金
美国国家科学基金会; 加拿大自然科学与工程研究理事会;
关键词
Malware; Feature extraction; Internet of Things; Deep learning; Labeling; Security; Tsunami; IoT malware classification; deep learning; multimodal learning; feature fusion; static malware analysis;
D O I
10.1109/TNSM.2021.3075315
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The emergence of Internet of Things malware, which leverages exploited IoT devices to perform large-scale cyber attacks (e.g., Mirai botnet), is considered as a major threat to the Internet ecosystem. To mitigate such threat, there is an utmost need for effective IoT malware classification and family attribution, which provide essential steps towards initiating attack mitigation/prevention countermeasures. In this paper, motivated by the lack of sophisticated malware obfuscation in the implementation of IoT malware, we utilize features extracted from strings- and image-based representations of the executable binaries to propose a novel multi-dimensional classification approach using Deep Learning (DL) architectures. To this end, we analyze more than 70,000 recently detected IoT malware samples. Our in-depth experiments with four prominent IoT malware families highlight the significant accuracy of the approach (99.78%), which outperforms conventional single-level classifiers. Additionally, we utilize our IoT-tailored approach for labeling newly detected "unknown" malware samples, which were mainly attributed to a few predominant families. Finally, this work contributes to the security of future networks (e.g., 5G) through the implementation of effective tools/techniques for timely IoT malware classification, and attack mitigation.
引用
收藏
页码:1165 / 1177
页数:13
相关论文
共 50 条
  • [1] A Deep Learning Framework for Malware Classification
    Kalash, Mahmoud
    Rochan, Mrigank
    Mohammed, Noman
    Bruce, Neil
    Wang, Yang
    Iqbal, Farkhund
    INTERNATIONAL JOURNAL OF DIGITAL CRIME AND FORENSICS, 2020, 12 (01) : 90 - 108
  • [2] Deep Learning-Based Multi-classification for Malware Detection in IoT
    Wang, Zhiqiang
    Liu, Qian
    Wang, Zhuoyue
    Chi, Yaping
    JOURNAL OF CIRCUITS SYSTEMS AND COMPUTERS, 2022, 31 (17)
  • [3] Deep Learning Framework and Visualization for Malware Classification
    Akarsh, S.
    Simran, K.
    Poornachandran, Prabaharan
    Menon, Vijay Krishna
    Soman, K. P.
    2019 5TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING & COMMUNICATION SYSTEMS (ICACCS), 2019, : 1059 - 1063
  • [4] Attribution Classification Method of APT Malware in IoT Using Machine Learning Techniques
    Li, Shudong
    Zhang, Qianqing
    Wu, Xiaobo
    Han, Weihong
    Tian, Zhihong
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [5] A Unified Deep Learning Framework for Multi-Modal Multi-Dimensional Data
    Xi, Pengcheng
    Goubran, Rafik
    Shu, Chang
    2019 IEEE INTERNATIONAL SYMPOSIUM ON MEDICAL MEASUREMENTS AND APPLICATIONS (MEMEA), 2019,
  • [6] HYDRA: A multimodal deep learning framework for malware classification
    Gibert, Daniel
    Mateu, Carles
    Planes, Jordi
    COMPUTERS & SECURITY, 2020, 95
  • [7] FedHGCDroid: An Adaptive Multi-Dimensional Federated Learning for Privacy-Preserving Android Malware Classification
    Jiang, Changnan
    Yin, Kanglong
    Xia, Chunhe
    Huang, Weidong
    ENTROPY, 2022, 24 (07)
  • [8] Efficient Deep Learning Network With Multi-Streams for Android Malware Family Classification
    Kim, Hyun-Il
    Kang, Moonyoung
    Cho, Seong-Je
    Choi, Sang-Il
    IEEE ACCESS, 2022, 10 : 5518 - 5532
  • [9] An Efficient Probabilistic Framework for Multi-Dimensional Classification
    Batal, Iyad
    Hong, Charmgil
    Hauskrecht, Milos
    PROCEEDINGS OF THE 22ND ACM INTERNATIONAL CONFERENCE ON INFORMATION & KNOWLEDGE MANAGEMENT (CIKM'13), 2013, : 2417 - 2422
  • [10] A multi-dimensional machine learning approach to predict advanced malware
    Bahtiyar, Serif
    Yaman, Mehmet Baris
    Altinigne, Can Yilmaz
    COMPUTER NETWORKS, 2019, 160 : 118 - 129