A Multi-Dimensional Deep Learning Framework for IoT Malware Classification and Family Attribution

被引:44
|
作者
Dib, Mirabelle [1 ]
Torabi, Sadegh [1 ]
Bou-Harb, Elias [2 ]
Assi, Chadi [1 ]
机构
[1] Concordia Inst Informat Syst Engn, Cyber Secur Res Ctr, Montreal, PQ H3G 1M8, Canada
[2] Univ Texas San Antonio, Cyber Ctr Secur & Analyt, San Antonio, TX 78249 USA
来源
IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT | 2021年 / 18卷 / 02期
基金
加拿大自然科学与工程研究理事会; 美国国家科学基金会;
关键词
Malware; Feature extraction; Internet of Things; Deep learning; Labeling; Security; Tsunami; IoT malware classification; deep learning; multimodal learning; feature fusion; static malware analysis;
D O I
10.1109/TNSM.2021.3075315
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The emergence of Internet of Things malware, which leverages exploited IoT devices to perform large-scale cyber attacks (e.g., Mirai botnet), is considered as a major threat to the Internet ecosystem. To mitigate such threat, there is an utmost need for effective IoT malware classification and family attribution, which provide essential steps towards initiating attack mitigation/prevention countermeasures. In this paper, motivated by the lack of sophisticated malware obfuscation in the implementation of IoT malware, we utilize features extracted from strings- and image-based representations of the executable binaries to propose a novel multi-dimensional classification approach using Deep Learning (DL) architectures. To this end, we analyze more than 70,000 recently detected IoT malware samples. Our in-depth experiments with four prominent IoT malware families highlight the significant accuracy of the approach (99.78%), which outperforms conventional single-level classifiers. Additionally, we utilize our IoT-tailored approach for labeling newly detected "unknown" malware samples, which were mainly attributed to a few predominant families. Finally, this work contributes to the security of future networks (e.g., 5G) through the implementation of effective tools/techniques for timely IoT malware classification, and attack mitigation.
引用
收藏
页码:1165 / 1177
页数:13
相关论文
共 50 条
  • [1] HYDRA: A multimodal deep learning framework for malware classification
    Gibert, Daniel
    Mateu, Carles
    Planes, Jordi
    COMPUTERS & SECURITY, 2020, 95
  • [2] Deep Learning-Based Multi-classification for Malware Detection in IoT
    Wang, Zhiqiang
    Liu, Qian
    Wang, Zhuoyue
    Chi, Yaping
    JOURNAL OF CIRCUITS SYSTEMS AND COMPUTERS, 2022, 31 (17)
  • [3] Deep Learning Framework and Visualization for Malware Classification
    Akarsh, S.
    Simran, K.
    Poornachandran, Prabaharan
    Menon, Vijay Krishna
    Soman, K. P.
    2019 5TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING & COMMUNICATION SYSTEMS (ICACCS), 2019, : 1059 - 1063
  • [4] A New Malware Classification Framework Based on Deep Learning Algorithms
    Aslan, Omer
    Yilmaz, Abdullah Asim
    IEEE ACCESS, 2021, 9 : 87936 - 87951
  • [5] A Deep Learning Framework for Malware Classification
    Kalash, Mahmoud
    Rochan, Mrigank
    Mohammed, Noman
    Bruce, Neil
    Wang, Yang
    Iqbal, Farkhund
    INTERNATIONAL JOURNAL OF DIGITAL CRIME AND FORENSICS, 2020, 12 (01) : 90 - 108
  • [6] MTS-IoT: A Robust Encrypted IoT Traffic Classification via Multi-dimensional Time Series
    Gao, Tianye
    Qi, Wang
    Liu, Kehong
    Li, Shengbao
    Ge, Ruihai
    Zan, Tianning
    PROCEEDINGS OF THE 2024 27 TH INTERNATIONAL CONFERENCE ON COMPUTER SUPPORTED COOPERATIVE WORK IN DESIGN, CSCWD 2024, 2024, : 323 - 328
  • [7] DATA AUGMENTATION IN TRAINING DEEP LEARNING MODELS FOR MALWARE FAMILY CLASSIFICATION
    Ding Yuxin
    Wang Guangbin
    Ma Yubin
    Ding Haoxuan
    PROCEEDINGS OF 2021 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS (ICMLC), 2021, : 102 - 107
  • [8] Deep Hashing for Malware Family Classification and New Malware Identification
    Zhang, Yunchun
    Liao, Zikun
    Zhang, Ning
    Min, Shaohui
    Wang, Qi
    Quek, Tony Q. S.
    Zhao, Mingxiong
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (16): : 26837 - 26851
  • [9] Internet-Wide Analysis, Characterization, and Family Attribution of IoT Malware: A Comprehensive Longitudinal Study
    Torabi, Sadegh
    Klisura, Dorde
    Khoury, Joseph
    Bou-Harb, Elias
    Assi, Chadi
    Debbabi, Mourad
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2025, 22 (02) : 1703 - 1716
  • [10] RMDNet-Deep Learning Paradigms for Effective Malware Detection and Classification
    Puneeth, S.
    Lal, Shyam
    Pratap Singh, Mahendra
    Raghavendra, B. S.
    IEEE ACCESS, 2024, 12 : 82622 - 82635