SNIFFER: A High-Accuracy Malware Detector for Enterprise-Based Systems

被引:0
|
作者
Chavis, Evan [1 ]
Davis, Harrison [1 ]
Hou, Yijun [1 ]
Hicks, Matthew [1 ]
Yitbarek, Salessawi Ferede [1 ]
Austin, Todd [1 ]
Bertacco, Valeria [1 ]
机构
[1] Univ Michigan, Comp Sci & Engn, Ann Arbor, MI 48109 USA
来源
2017 IEEE 2ND INTERNATIONAL VERIFICATION AND SECURITY WORKSHOP (IVSW) | 2017年
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In the continual battle between malware attacks and antivirus technologies, both sides strive to deploy their techniques at always lower layers in the software system stack. The goal is to monitor and control the software executing in the levels above their own deployment, to detect attacks or to defeat defenses. Recent antivirus solutions have gone even below the software, by enlisting hardware support. However, so far, they have only mimicked classic software techniques by monitoring software clues of an attack. As a result, malware can easily defeat them by employing metamorphic manifestation patterns. With this work, we propose a hardware-monitoring solution, SNIFFER, which tracks malware manifestations in system-level behavior, rather than code patterns, and it thus cannot be circumvented unless malware renounces its very nature, that is, to attack. SNIFFER leverages in-hardware feature monitoring, and uses machine learning to assess whether a system shows signs of an attack. Experiments with a virtual SNIFFER implementation, which supports 13 features and tests against five common network-based malicious behaviors, show that SNIFFER detects malware nearly 100% of the time, unless the malware aggressively throttle its attack. Our experiments also highlight the need for machine-learning classifiers employing a range of diverse system features, as many of the tested malware require multiple, seemingly disconnected, features for accurate detection.
引用
收藏
页码:70 / 75
页数:6
相关论文
共 50 条
  • [1] A High-accuracy Zero-crossing Based Edge Detector
    Xu, Huilin
    2015 8TH INTERNATIONAL CONGRESS ON IMAGE AND SIGNAL PROCESSING (CISP), 2015, : 319 - 324
  • [2] Towards a Novel Approach to High-accuracy Enterprise Search
    Guo, Shuman
    Wang, Lei
    Wang, Zhigang
    She, Nanfei
    Zhang, Hao
    Sun, Kewu
    PROCEEDINGS OF 2018 INTERNATIONAL CONFERENCE ON NETWORK INFRASTRUCTURE AND DIGITAL CONTENT (IEEE IC-NIDC), 2018, : 279 - 283
  • [3] High-accuracy radiance calibration system for ultraviolet detector
    Wang, Rui
    Song, Ke-Fei
    Guangxue Jingmi Gongcheng/Optics and Precision Engineering, 2009, 17 (03): : 469 - 474
  • [5] Detector-based calibration method for high-accuracy solar UV measurements
    Karha, P
    Visuri, R
    Leszczynski, K
    Manoochehri, F
    Jokela, K
    Ikonen, E
    PHOTOCHEMISTRY AND PHOTOBIOLOGY, 1996, 64 (02) : 340 - 343
  • [6] High-accuracy detector calibration for EUV metrology at PTB
    Scholze, F
    Brandt, G
    Müller, P
    Meyer, B
    Scholz, F
    Tümmler, J
    Vogel, K
    Ulm, G
    EMERGING LITHOGRAPHIC TECHNOLOGIES VI, PTS 1 AND 2, 2002, 4688 : 680 - 689
  • [7] High-accuracy X-ray detector calibration based on cryogenic radiometry
    Krumrey, M.
    Cibik, L.
    Mueller, P.
    SRI 2009: THE 10TH INTERNATIONAL CONFERENCE ON SYNCHROTRON RADIATION INSTRUMENTATION, 2010, 1234 : 826 - 829
  • [8] High-accuracy X-ray detector calibration at PTB
    Krumrey, M
    Scholze, F
    Ulm, G
    HIGH-ENERGY DETECTORS IN ASTRONOMY, 2004, 5501 : 277 - 285
  • [9] HIGH-ACCURACY SYNCHRONOUS DETECTOR WITH WIDE DYNAMIC RANGE.
    Kadzhar, Ch.O.
    Musaev, S.A.
    Salaev, E.Yu.
    Instruments and experimental techniques New York, 1982, 25 (5 pt 1): : 1155 - 1156
  • [10] HIGH-ACCURACY SYNCHRONOUS DETECTOR WITH WIDE DYNAMIC-RANGE
    KADZHAR, CO
    MUSAEV, SA
    SALAEV, EY
    INSTRUMENTS AND EXPERIMENTAL TECHNIQUES, 1982, 25 (05) : 1155 - 1156