A Multi-Dimensional Deep Learning Framework for IoT Malware Classification and Family Attribution

被引:44
|
作者
Dib, Mirabelle [1 ]
Torabi, Sadegh [1 ]
Bou-Harb, Elias [2 ]
Assi, Chadi [1 ]
机构
[1] Concordia Inst Informat Syst Engn, Cyber Secur Res Ctr, Montreal, PQ H3G 1M8, Canada
[2] Univ Texas San Antonio, Cyber Ctr Secur & Analyt, San Antonio, TX 78249 USA
来源
IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT | 2021年 / 18卷 / 02期
基金
加拿大自然科学与工程研究理事会; 美国国家科学基金会;
关键词
Malware; Feature extraction; Internet of Things; Deep learning; Labeling; Security; Tsunami; IoT malware classification; deep learning; multimodal learning; feature fusion; static malware analysis;
D O I
10.1109/TNSM.2021.3075315
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The emergence of Internet of Things malware, which leverages exploited IoT devices to perform large-scale cyber attacks (e.g., Mirai botnet), is considered as a major threat to the Internet ecosystem. To mitigate such threat, there is an utmost need for effective IoT malware classification and family attribution, which provide essential steps towards initiating attack mitigation/prevention countermeasures. In this paper, motivated by the lack of sophisticated malware obfuscation in the implementation of IoT malware, we utilize features extracted from strings- and image-based representations of the executable binaries to propose a novel multi-dimensional classification approach using Deep Learning (DL) architectures. To this end, we analyze more than 70,000 recently detected IoT malware samples. Our in-depth experiments with four prominent IoT malware families highlight the significant accuracy of the approach (99.78%), which outperforms conventional single-level classifiers. Additionally, we utilize our IoT-tailored approach for labeling newly detected "unknown" malware samples, which were mainly attributed to a few predominant families. Finally, this work contributes to the security of future networks (e.g., 5G) through the implementation of effective tools/techniques for timely IoT malware classification, and attack mitigation.
引用
收藏
页码:1165 / 1177
页数:13
相关论文
共 50 条
  • [21] A multi-view feature fusion approach for effective malware classification using Deep Learning
    Chaganti, Rajasekhar
    Ravi, Vinayakumar
    Pham, Tuan D.
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2023, 72
  • [22] Towards an interpretable deep learning model for mobile malware detection and family identification
    Iadarola, Giacomo
    Martinelli, Fabio
    Mercaldo, Francesco
    Santone, Antonella
    COMPUTERS & SECURITY, 2021, 105
  • [23] Multi-Dimensional Fusion Deep Learning for Side Channel Analysis
    Deng, Tuo
    Wang, Huanyu
    He, Dalin
    Xiong, Naixue
    Liang, Wei
    Wang, Junnian
    ELECTRONICS, 2023, 12 (23)
  • [24] A trusted and collaborative framework for deep learning in IoT
    Zhang, Qingyang
    Zhong, Hong
    Shi, Weisong
    Liu, Lu
    COMPUTER NETWORKS, 2021, 193
  • [25] IoT Malware Network Traffic Classification using Visual Representation and Deep Learning
    Bendiab, Gueltoum
    Shiaeles, Stavros
    Alruban, Abdulrahman
    Kolokotronis, Nicholas
    PROCEEDINGS OF THE 2020 6TH IEEE CONFERENCE ON NETWORK SOFTWARIZATION (NETSOFT 2020): BRIDGING THE GAP BETWEEN AI AND NETWORK SOFTWARIZATION, 2020, : 444 - 449
  • [26] Classification of Methamorphic Malware with Deep Learning(LSTM)
    Yaz, Ahmet Faruk
    Catak, Ferhat Ozgur
    Gul, Ensar
    2019 27TH SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2019,
  • [27] Malware Classification Using Deep Learning Methods
    Cakir, Bugra
    Dogdu, Erdogan
    ACMSE '18: PROCEEDINGS OF THE ACMSE 2018 CONFERENCE, 2018,
  • [28] A Deep Learning Cache Framework for Privacy Security on Heterogeneous IoT Networks
    Li, Jian
    Feng, Meng
    Li, Shuai
    IEEE ACCESS, 2024, 12 : 93261 - 93269
  • [29] Advanced hybrid malware identification framework for the Internet of Medical Things, driven by deep learning
    Safeer, Ehtesham
    Tahir, Sidra
    Nawaz, Asif
    Humayun, Mamoona
    Shaheen, Momina
    Khan, Maqbool
    SECURITY AND PRIVACY, 2025, 8 (01):
  • [30] A new deep boosted CNN and ensemble learning based IoT malware detection
    Khan, Saddam Hussain
    Alahmadi, Tahani Jaser
    Ullah, Wasi
    Iqbal, Javed
    Rahim, Azizur
    Alkahtani, Hend Khalid
    Alghamdi, Wajdi
    Almagrabi, Alaa Omran
    COMPUTERS & SECURITY, 2023, 133