arrow
Return

Practical evasion attack against neural network-based macro-malware detection method

delete2024-11-26
delete0
delete
OA
AI
M
Mamoru Mimura *
K
Kazuyuki Kurashina
DOI:10.1007/s10586-024-04825-5delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
In recent years, various methods have been proposed to detect unknown malware using machine learning models. These models extract features from malware and classify them as benign or malicious. However, there have been reports of evasion attacks against machine learning-based malware detectors. Previous research has focused on these evasion attacks, particularly against models that detect Visual Basics for Applications (VBA) malware using natural language processing models such as Bag of Words (BoW) and Latent Semantic Indexing (LSI). However, these models rely on word frequency as a feature, overlooking the context, and their evaluation involved an equal number of benign and malicious samples, leaving their effectiveness in real-world scenarios unverified. To address these limitations, our study introduces a tokenizer that preserves word order during token conversion. We evaluated its accuracy using an imbalanced dataset and employed models such as recurrent neural networks (RNNs) and long short-term memory (LSTM) networks to understand the context of words. Its detection rate for malicious malware exceeds 0.8, indicating sufficient performance. Moreover, by incorporating words found only in benign samples as arguments in non-functional operations, we managed to reduce the evasion attack detection rate to as low as 0.89. Ultimately, we confirmed that the detection rate of malicious samples remained consistent in real-world conditions, demonstrating the effectiveness of our approach.
Keywords:
Evasion attack
Macro malware
Natural language processing
Deep neural network

Journal

C
Cluster Computing-The Journal of Networks Software Tools and Applications
IF:
4.1
Papers:
5.1K
Citations:
7.5K

Organization

N
national defense academy - japan
Scholars:
595
Papers: 620
Citations: 0
Cited Papers

Cited Papers

A Comprehensive Review on Malware Detection Approaches
err2020-01-01
err263
errOAAI
errAslan, Omer; Samet, Refik
errShare
errSave
Tandem silylformylation–allyl(crotyl)silylation: a new approach to polyketide synthesis
err2003-11-01
err0
PREAI
errMichael J. Zacuto; Steven J. O'Malley; James L. Leighton
errShare
errSave
The cluster approach to exchange coupling in diamminecopper(II) carbonate, Cu(NH3)2CO3
err2002-05-01
err0
PREAI
errAnthony K. Gregson; Robert R. Weller; William E. Hatfield
errShare
errSave
Invoice #31415 attached: Automated analysis of malicious Microsoft Office documents
err2022-03-01
err17
errOAAI
errKoutsokostas, Vasilios; Lykousas, Nikolaos; Apostolopoulos, Theodoros; Orazi, Gabriele; Ghosal, Amrita; Casino, Fran; Conti, Mauro; Patsakis, Constantinos
errShare
errSave
researcher View more