Deep Neural Network and Transfer Learning for Accurate Hardware-Based Zero-Day Malware Detection

被引:12
作者
He, Zhangying [1 ]
Rezaei, Amin [1 ]
Homayoun, Houman [2 ]
Sayadi, Hossein [1 ]
机构
[1] Calif State Univ, Long Beach, CA 90032 USA
[2] Univ Calif Davis, Davis, CA 95616 USA
来源
PROCEEDINGS OF THE 32ND GREAT LAKES SYMPOSIUM ON VLSI 2022, GLSVLSI 2022 | 2022年
关键词
Deep Learning; Hardware-Based Malware Detection; Machine Learning; Transfer Learning; Zero-Day Attack;
D O I
10.1145/3526241.3530326
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In recent years, security researchers have shifted their attentions to the underlying processors' architecture and proposed Hardware-Based Malware Detection (HMD) countermeasures to address inefficiencies of software-based detection methods. HMD techniques apply standard Machine Learning (ML) algorithms to the processors' low-level events collected from Hardware Performance Counter (HPC) registers. However, despite obtaining promising results for detecting known malware, the challenge of accurate zero-day (unknown) malware detection has remained an unresolved problem in existing HPC-based countermeasures. Our comprehensive analysis shows that standard ML classifiers are not effective in recognizing zero-day malware traces using HPC events. In response, we propose Deep-HMD, a two-stage intelligent and flexible approach based on deep neural network and transfer learning, for accurate zero-day malware detection based on image-based hardware events. The experimental results indicate that our proposed solution outperforms existing ML-based methods by achieving a 97% detection rate (F-Measure and Area Under the Curve) for detecting zero-day malware signatures at run-time using the top 4 hardware events with a minimal false positive rate and no hardware redesign overhead.
引用
收藏
页码:27 / 32
页数:6
相关论文
共 50 条
[31]   Comparative Evaluation of AI-Based Techniques for Zero-Day Attacks Detection [J].
Ali, Shamshair ;
Rehman, Saif Ur ;
Imran, Azhar ;
Adeem, Ghazif ;
Iqbal, Zafar ;
Kim, Ki-Il .
ELECTRONICS, 2022, 11 (23)
[32]   A zero-day resistant malware detection method for securing Cloud using SVM and Sandboxing Techniques [J].
Kumar, Saket ;
Singh, Chandra Bhim Bhan .
PROCEEDINGS OF THE 2018 SECOND INTERNATIONAL CONFERENCE ON INVENTIVE COMMUNICATION AND COMPUTATIONAL TECHNOLOGIES (ICICCT), 2018, :1397-1402
[33]   A novel deep learning-based approach for malware detection [J].
Shaukat, Kamran ;
Luo, Suhuai ;
Varadharajan, Vijay .
ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2023, 122
[34]   Using network traffic analysis deep learning based Android malware detection [J].
Utku A. .
Journal of the Faculty of Engineering and Architecture of Gazi University, 2022, 37 (04) :1823-1838
[35]   Advanced Machine Learning Approaches for Zero-Day Attack Detection: A Review [J].
El Husseini, Fatema ;
Noura, Hassan ;
Salman, Ola ;
Chehab, Ali .
2024 8TH CYBER SECURITY IN NETWORKING CONFERENCE, CSNET, 2024, :297-304
[36]   A review of Machine Learning-based zero-day attack detection: Challenges and future directions [J].
Guo, Yang .
COMPUTER COMMUNICATIONS, 2023, 198 :175-185
[37]   Image Splicing Detection based on Deep Convolutional Neural Network and Transfer Learning [J].
Das, Debjit ;
Naskar, Ruchira .
2022 IEEE 19TH INDIA COUNCIL INTERNATIONAL CONFERENCE, INDICON, 2022,
[38]   Mobile Malware Detection Using Deep Neural Network [J].
Bulut, Irfan ;
Yavuz, A. Gokhan .
2017 25TH SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2017,
[39]   Deep Learning and Zero-Day Traffic Classification: Lessons Learned From a Commercial-Grade Dataset [J].
Yang, Lixuan ;
Finamore, Alessandro ;
Jun, Feng ;
Rossi, Dario .
IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (04) :4103-4118
[40]   An investigation of a deep learning based malware detection system [J].
Sewak, Mohit ;
Sahay, Sanjay K. ;
Rathore, Hemant .
13TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2018), 2019,