TrustSign: Trusted Malware Signature Generation in Private Clouds Using Deep Feature Transfer Learning

被引:0
|
作者
Nahmias, Daniel [1 ,2 ]
Cohen, Aviad [1 ,2 ]
Nissim, Nir [1 ,3 ]
Elovici, Yuval [1 ,2 ]
机构
[1] Ben Gurion Univ Negev, Cyber Secur Res Ctr, Malware Lab, Beer Sheva, Israel
[2] Ben Gurion Univ Negev, Dept Software & Informat Syst Engn, Beer Sheva, Israel
[3] Ben Gurion Univ Negev, Dept Ind Engn & Management, Beer Sheva, Israel
来源
2019 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN) | 2019年
关键词
Deep Learning; Transfer Learning; Convolutional Neural Networks; Malware; Cryptojacking; Automatic Signature Generation; CONDITION SEVERITY CLASSIFICATION; METHODOLOGY;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This paper presents TrustSign, a novel, trusted automatic malware signature generation method based on high-level deep features transferred from a VGG-19 neural network model pre-trained on the ImageNet dataset. While traditional automatic malware signature generation techniques rely on static or dynamic analysis of the malware's executable, our method overcomes the limitations associated with these techniques by producing signatures based on the presence of the malicious process in the volatile memory. Signatures generated using TrustSign well represent the real malware behavior during runtime. By leveraging the cloud's virtualization technology, TrustSign analyzes the malicious process in a trusted manner, since the malware is unaware and cannot interfere with the inspection procedure. Additionally, by removing the dependency on the malware's executable, our method is capable of signing fileless malware. Thus, we focus our research on in-browser cryptojacking attacks, which current antivirus solutions have difficulty to detect. However, TrustSign is not limited to cryptojacking attacks, as our evaluation included various ransomware samples. TrustSign's signature generation process does not require feature engineering or any additional model training, and it is done in a completely unsupervised manner, obviating the need for a human expert. Therefore, our method has the advantage of dramatically reducing signature generation and distribution time. The results of our experimental evaluation demonstrate TrustSign's ability to generate signatures invariant to the process state over time. By using the signatures generated by TrustSign as input for various supervised classifiers, we achieved 99.5% classification accuracy.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] Deep feature transfer learning for trusted and automated malware signature generation in private cloud environments
    Nahmias, Daniel
    Cohen, Aviad
    Nissim, Nir
    Elovici, Yuval
    NEURAL NETWORKS, 2020, 124 : 243 - 257
  • [2] DeepSign: Deep Learning for Automatic Malware Signature Generation and Classification
    David, Omid E.
    Netanyahu, Nathan S.
    2015 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2015,
  • [3] A Deep Learning Approach to Android Malware Feature Learning and Detection
    Su, Xin
    Zhang, Dafang
    Li, Wenjia
    Zhao, Kai
    2016 IEEE TRUSTCOM/BIGDATASE/ISPA, 2016, : 244 - 251
  • [4] DeepDroid: Feature Selection approach to detect Android malware using Deep Learning
    Mahindru, Arvind
    Sangal, A. L.
    PROCEEDINGS OF 2019 IEEE 10TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE (ICSESS 2019), 2019, : 16 - 19
  • [5] Malware Detection Using Deep Learning and Correlation-Based Feature Selection
    Alomari, Esraa Saleh
    Nuiaa, Riyadh Rahef
    Alyasseri, Zaid Abdi Alkareem
    Mohammed, Husam Jasim
    Sani, Nor Samsiah
    Esa, Mohd Isrul
    Musawi, Bashaer Abbuod
    SYMMETRY-BASEL, 2023, 15 (01):
  • [6] Feature Importance and Deep Learning for Android Malware Detection
    Talbi, A.
    Viens, A.
    Leroux, L-C
    Francois, M.
    Caillol, M.
    Nguyen, N.
    PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY (ICISSP), 2021, : 453 - 462
  • [7] Deep learning feature exploration for Android malware detection
    Zhang, Nan
    Tan, Yu-an
    Yang, Chen
    Li, Yuanzhang
    APPLIED SOFT COMPUTING, 2021, 102
  • [8] Malware Image Generation and Detection Method Using DCGANs and Transfer Learning
    Peppes, Nikolaos
    Alexakis, Theodoros
    Daskalakis, Emmanouil
    Demestichas, Konstantinos
    Adamopoulou, Evgenia
    IEEE ACCESS, 2023, 11 (105872-105884) : 105872 - 105884
  • [9] TransNet: Unseen Malware Variants Detection Using Deep Transfer Learning
    Rong, Candong
    Gou, Gaopeng
    Cui, Mingxin
    Xiong, Gang
    Li, Zhen
    Guo, Li
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS (SECURECOMM 2020), PT II, 2020, 336 : 84 - 101
  • [10] Malware Detection using Malware Image and Deep Learning
    Choi, Sunoh
    Jang, Sungwook
    Kim, Youngsoo
    Kim, Jonghyun
    2017 INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC), 2017, : 1193 - 1195