Hardware-Based Malware Detection Using Low-Level Architectural Features

被引:64
作者
Ozsoy, Meltem [1 ]
Khasawneh, Khaled N. [2 ]
Donovick, Caleb [3 ]
Gorelik, Iakov [3 ]
Abu-Ghazaleh, Nael [2 ]
Ponomarev, Dmitry [3 ]
机构
[1] Intel Corp, Secur & Privacy Lab, Hillsboro, OR 97124 USA
[2] Univ Calif Riverside, CSE & ECE Dept, Riverside, CA 92521 USA
[3] SUNY Binghamton, CS Dept, Binghamton, NY 13902 USA
基金
美国国家科学基金会;
关键词
Malware detection; architecture; security; low-level features;
D O I
10.1109/TC.2016.2540634
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security exploits and ensuant malware pose an increasing challenge to computing systems as the variety and complexity of attacks continue to increase. In response, software-based malware detection tools have grown in complexity, thus making it computationally difficult to use them to protect systems in real-time. Therefore, software detectors are applied selectively and at a low frequency, creating opportunities for malware to remain undetected. In this paper, we propose Malware-Aware Processors ( MAP)processors augmented with a hardware-based online malware detector to serve as the first line of defense to differentiate malware from legitimate programs. The output of this detector helps the system prioritize how to apply more expensive software-based solutions. The always-on nature of MAP detector helps protect against intermittently operating malware. We explore the use of different features for classification and study both logistic regression and neural networks. We show that the detectors can achieve excellent performance, with little hardware overhead. We integrate the MAP implementation with an open-source x86-compatible core, synthesizing the resulting design to run on an FPGA.
引用
收藏
页码:3332 / 3344
页数:13
相关论文
共 50 条
  • [1] Multinomial malware classification via low-level features
    Banin, Sergii
    Dyrkolbotn, Geir Olav
    DIGITAL INVESTIGATION, 2018, 26 : S107 - S117
  • [2] Micro-architectural Features for Malware Detection
    Peng, Huicheng
    Wei, Jizeng
    Guo, Wei
    ADVANCED COMPUTER ARCHITECTURE, ACA 2016, 2016, 626 : 48 - 60
  • [3] Correlating High- and Low-Level Features: Increased Understanding of Malware Classification
    Banin, Sergii
    Dyrkolbotn, Geir Olav
    ADVANCES IN INFORMATION AND COMPUTER SECURITY, IWSEC 2019, 2019, 11689 : 149 - 167
  • [4] Ensemble Learning for Effective Run-Time Hardware-Based Malware Detection: A Comprehensive Analysis and Classification
    Sayadi, Hossein
    Patel, Nisarg
    Manoj, Sai P. D.
    Sasan, Avesta
    Rafatirad, Setareh
    Homayoun, Houman
    2018 55TH ACM/ESDA/IEEE DESIGN AUTOMATION CONFERENCE (DAC), 2018,
  • [5] Akoman: Hardware-Level Malware Detection Using Discrete Wavelet Transform
    Alizadeh, Niloofar S.
    Abadi, Mahdi
    2018 IEEE INTERNATIONAL CONFERENCE ON SMART COMPUTING (SMARTCOMP 2018), 2018, : 476 - 481
  • [6] The Design and Analysis of a Hardware-based Anomaly Detection Scheme
    Piao, JinLong
    Kim, Seong Baeg
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2012, 6 (02): : 367 - 372
  • [7] Fingerprint Liveness Detection From Single Image Using Low-Level Features and Shape Analysis
    Dubey, Rohit Kumar
    Goh, Jonathan
    Thing, Vrizlynn L. L.
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2016, 11 (07) : 1461 - 1475
  • [8] Saliency Detection Based on Low-Level and High-Level Features via Manifold-Space Ranking
    Li, Xiaoli
    Liu, Yunpeng
    Zhao, Huaici
    ELECTRONICS, 2023, 12 (02)
  • [9] Visualization and deep-learning-based malware variant detection using OpCode-level features
    Darem, Abdulbasit
    Abawajy, Jemal
    Makkar, Aaisha
    Alhashmi, Asma
    Alanazi, Sultan
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 125 : 314 - 323
  • [10] A Brain-inspired Approach for Malware Detection using Sub-semantic Hardware Features
    Parsa, Maryam
    Khasawneh, Khaled N.
    Alouani, Ihsen
    PROCEEDINGS OF THE GREAT LAKES SYMPOSIUM ON VLSI 2023, GLSVLSI 2023, 2023, : 139 - 142