arrow
返回

DAEMON: Dataset/Platform-Agnostic Explainable Malware Classification Using Multi-Stage Feature Mining

delete2021-01-01
delete9
delete
OA
AI
R
Ron Korine *
D
Danny Hendler
DOI:10.1109/ACCESS.2021.3082173delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Numerous metamorphic and polymorphic malicious variants are generated automatically on a daily basis. In order to do that, malware vendors employ mutation engines that transform the code of a malicious program while retaining its functionality, aiming to evade signature-based detection. These automatic processes have greatly increased the number of malware variants, deeming their fully-manual analysis impossible. Malware classification is the task of determining to which family a new malicious variant belongs. Variants of the same malware family show similar behavioral patterns. Thus, classifying newly discovered malicious programs and applications helps assess the risks they pose. Moreover, malware classification facilitates determining which of the newly discovered variants should undergo manual analysis by a security expert, in order to determine whether they belong to a new family (e.g., one whose members exploit a zero-day vulnerability) or are simply the result of a concept drift within a known malicious family. This motivated intense research in recent years on devising high-accuracy automatic tools for malware classification. In this work, we present DAEMON-a novel dataset-agnostic malware classifier. A key property of DAEMON is that the type of features it uses and the manner in which they are mined facilitate understanding the distinctive behavior of malware families, making its classification decisions explainable. We've optimized DAEMON using a large-scale dataset of x86 binaries, belonging to a mix of several malware families targeting computers running Windows. We then re-trained it and applied it, without any algorithmic change, feature re-engineering or parameter tuning, to two other large-scale datasets of malicious Android applications consisting of numerous malware families. DAEMON obtained highly accurate classification results on all datasets, establishing that it is not only dataset-agnostic but also platform-agnostic. We analyze DAEMON's classification models and provide numerous examples demonstrating how the features it uses facilitate explainability.
Keyword:
Malware
Static analysis
Feature extraction
Smart phones
Manuals
Heuristic algorithms
Tuning
Malware classification
malware families
server-side polymorphism
static analysis
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Access 封面图
IEEE Access
IF:
3.6
论文数:
9.8W
被引数:
29.4W

机构

B
ben-gurion university of the negev
学者数:
8.4K
论文数: 5.1K
被引数: 1
引用论文

引用论文

Steel-Reinforced Concrete Structures
err
IF0
err2017-11-06
err0
PREAI
errMohamed Abdallah El-Reedy
err分享
err收藏
Malware Dynamic Analysis Evasion Techniques: A Survey恶意软件动态分析规避技术综述
err2019-11-14
err90
PREAI
errAfianian, Amir; Niksefat, Salman; Sadeghiyan, Babak; Baptiste, David
err分享
err收藏
Anxiety Status of Female Chinese Ph.D. Candidates and Its Association with Sports
err2022-06-27
err0
errOAAI
errYupeng Mao; Yongsheng Zhu; Changjun Jia; Fengxin Sun; Song Chen; Bing Liu
err分享
err收藏
HSP70 is required for the proper assembly of pericentriolar material and function of mitotic centrosomes
err2019-05-10
err0
errOAAI
errChieh-Ting Fang; Hsiao-Hui Kuo; Shao-Chun Hsu; Ling-Huei Yih
err分享
err收藏
学者 查看更多内容