arrow
Return

On Deceiving Malware Classification with Section Injection

delete2023-01-16
delete2
delete
OA
AI
A
Adeilson Antonio da Silva
M
Maurício Pamplona Segundo *
DOI:10.3390/make5010009delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
We investigate how to modify executable files to deceive malware classification systems. This work's main contribution is a methodology to inject bytes across a malware file randomly and use it both as an attack to decrease classification accuracy but also as a defensive method, augmenting the data available for training. It respects the operating system file format to make sure the malware will still execute after our injection and will not change its behavior. We reproduced five state-of-the-art malware classification approaches to evaluate our injection scheme: one based on Global Image Descriptor (GIST) + K-Nearest-Neighbors (KNN), three Convolutional Neural Network (CNN) variations and one Gated CNN. We performed our experiments on a public dataset with 9339 malware samples from 25 different families. Our results show that a mere increase of 7% in the malware size causes an accuracy drop between 25% and 40% for malware family classification. They show that an automatic malware classification system may not be as trustworthy as initially reported in the literature. We also evaluate using modified malware alongside the original ones to increase networks robustness against the mentioned attacks. The results show that a combination of reordering malware sections and injecting random data can improve the overall performance of the classification. All the code is publicly available.
Keywords:
malware classification
adversarial examples
Deep Learning
Convolutional Neural Networks

Journal

M
Machine Learning and Knowledge Extraction
IF:
6
Papers:
841
Citations:
1.8K

Organization

State University System of Florida cover
State University System of Florida
Scholars:
12.8W
Papers: 10.9W
Citations: 130
U
university of south florida
Scholars:
1.5W
Papers: 1.2W
Citations: 9
Cited Papers

Cited Papers

errShare
errSave
A Method for Automatic Android Malware Detection Based on Static Analysis and Deep Learning
err2022-01-01
err24
errOAAI
errIbrahim, Mulhem; Issa, Bayan; Jasser, Muhammed Basheer
errShare
errSave
errShare
errSave
Effects of titanium and tantalum adhesion layers on the properties of sol-gel derived SrBi2Ta2O9 thin films
err2002-08-01
err0
PREAI
errChing-Chich Leu; Hung-Tao Lin; Chen-Ti Hu; Chao-Hsin Chien; Ming-Jui Yang; Ming-Che Yang; Tiao-Yuan Huang
errShare
errSave
researcher View more