arrow
返回

Leveraging malicious behavior traces from volatile memory using machine learning methods for trusted unknown malware detection in Linux cloud environments

delete2021-08-01
delete28
PRE
AI
N
Nir Nissim *
DOI:10.1016/j.knosys.2021.107095delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Most organizations today use cloud-computing environments and virtualization technology. Linux-based clouds are the most popular cloud environments among organizations, and thus have become the target of cyber-attacks launched by sophisticated malware. Existing malware detection solutions for Linux-based VMs are installed and operated on the VM itself and are considered untrusted since malware can detect, interfere with, and even evade them. Thus, Linux cloud-based environments remain exposed to various malware-based attacks. This paper presents the first trusted framework for detecting unknown malware in Linux VM cloud-environments. Our framework acquires volatile memory dumps from the inspected VM by querying the hypervisor in a trusted manner and overcoming malware's ability to detect the security mechanism and evade detection. Then, using machine-learning algorithms we leverage informative traces (our 171 proposed features) from different parts of the VM's volatile memory. The framework was evaluated in seven rigorous experiments, on a total of 21,800 volatile memory dumps taken from two widely used virtual servers (10,900 from each server) during the execution of a diverse yet representative collection of benign and malicious Linux applications. Notably, the results show that our proposed framework can accurately (with high TPRs and low FPRs): (a) detect unknown malware (b) detect new unknown malware from unseen malware categories, which is a critical ability for coping with new malware trends and phenomena; (c) categorize an unknown malware by its attack category; (d) detect unknown malware on an unknown virtual-server; and lastly (e) detect fileless malware, a critical capability demonstrating the ability to detect substantially different attack modus operandi. (C) 2021 Elsevier B.V. All rights reserved.
Keyword:
Cloud
Virtual machine
Volatile memory
Malware
Linux
Detection
Machine learning
Feature extraction
Volatility
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

K
Knowledge-Based Systems
IF:
7.6
论文数:
1.3W
被引数:
4.5W

机构

B
ben gurion university
学者数:
1.3W
论文数: 1.0W
被引数: 5
引用论文

引用论文

err分享
err收藏
Improving condition severity classification with an efficient active learning based framework
err2016-06-01
err21
errOAAI
errNissim, Nir; Boland, Mary Regina; Tatonetti, Nicholas P.; Elovici, Yuval; Hripcsak, George; Shahar, Yuval; Moskovitch, Robert
err分享
err收藏
Emerging Trends in Neuromodulation for Treatment of Drug-Resistant Epilepsy
err2022-03-21
err0
errOAAI
errMohamed Abouelleil; Nachiket Deshpande; Rushna Ali
err分享
err收藏
Robust Intelligent Malware Detection Using Deep Learning基于深度学习的强大智能恶意软件检测
err2019-01-01
err245
errOAAI
errVinayakumar, R.; Alazab, Mamoun; Soman, K. P.; Poornachandran, Prabaharan; Venkatraman, Sitalakshmi
err分享
err收藏
Marker lesion study of oral FGFR inhibitor BGJ398 in patients with FGFR3-altered intermediate-risk nonmuscle-invasive bladder cancer.
err2020-02-20
err0
PREAI
errEugene K. Cha; Gopa Iyer; Samuel Aaron Funt; Ashley Marie Regazzi; Jasmine Francis; M.H. Heinemann; Irina Ostrovnaya; Guido Dalbagni; Dean F. Bajorin; Bernard H. Bochner; Jonathan E. Rosenberg
err分享
err收藏
学者 查看更多内容