arrow
返回

MinCloud: Trusted and transferable MinHash-based framework for unknown malware detection for Linux cloud environments

delete2024-12-01
delete0
PRE
AI
A
Aviad Cohen
T
Tom Landman
C
Chen Bery
N
Nir Nissim *
DOI:10.1016/j.jisa.2024.103907delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Linux clouds have become an attractive target for cyber-attacks. However, existing detection solutions for Linux clouds have variety of limitations. Some of the solutions are untrusted, incapable of detecting unknown malware, or rely on a human expert to define the features. Other solutions are trusted but require a large amount of computational resources or have a limited ability to detect rootkits, fileless malware, or malware on a different server. In this study, we propose MinCloud, a trusted and transferable MinHash-based framework for unknown malware detection in Linux virtual servers that overcomes the limitations of existing solutions. In the first stage, we acquired volatile memory dumps from virtual servers by querying the hypervisor in a trusted manner and then analyzed them using the MinHash method. Finally, the MinHash characteristics are harnessed by applying machine learning classifiers to achieve precise malware detection. MinCloud was evaluated on widely used Linux virtual servers, various benign and malicious applications, and 23,000 volatile memory dumps, each representing different behaviors of the examined servers and the executed applications over time. MinCloud's evaluation shows it can (1) detect unknown malware, (2) classify unknown malware according to its malware category, (3) detect fileless attacks and rootkit malware, and (4) provide accurately transfer detection between different Linux servers. MinCloud outperformed state-of-the-art trusted detection methods and commonly used antiviruses.
Keyword:
Cloud
Linux
Machine learning
Malware
MinHash
Virtualization
Volatile memory forensics

期刊

Journal of Information Security and Applications 封面图
Journal of Information Security and Applications
IF:
3.7
论文数:
2.0K
被引数:
4.9K

机构

B
ben-gurion university of the negev
学者数:
8.4K
论文数: 5.1K
被引数: 1
引用论文

引用论文

err分享
err收藏
err分享
err收藏
Improving condition severity classification with an efficient active learning based framework
err2016-06-01
err21
errOAAI
errNissim, Nir; Boland, Mary Regina; Tatonetti, Nicholas P.; Elovici, Yuval; Hripcsak, George; Shahar, Yuval; Moskovitch, Robert
err分享
err收藏
The crystal and molecular structure of UO2(NO3)2[Ph2P(O)CH2C(O)Ph]2 and its role in the solvent extraction of the uranyl ion
err1989-01-01
err0
PREAI
errRyszard Babecki; Andrew W.G. Platt; John C. Tebby; John Fawcett; David R. Russell; Robert Little
err分享
err收藏
Understanding the Relationship between Human Behavior and Susceptibility to Cyber Attacks: A Data-Driven Approach
err2017-03-22
err32
PREAI
errOvelgonne, Michael; Dumitras, Tudor; Prakash, B. Aditya; Subrahmanian, V. S.; Wang, Benjamin
err分享
err收藏
学者 查看更多内容