ADVERSARIALuscator: An Adversarial-DRL Based Obfuscator and Metamorphic Malware SwarmGenerator

09/23/2021
by   Mohit Sewak, et al.
0

Advanced metamorphic malware and ransomware, by using obfuscation, could alter their internal structure with every attack. If such malware could intrude even into any of the IoT networks, then even if the original malware instance gets detected, by that time it can still infect the entire network. It is challenging to obtain training data for such evasive malware. Therefore, in this paper, we present ADVERSARIALuscator, a novel system that uses specialized Adversarial-DRL to obfuscate malware at the opcode level and create multiple metamorphic instances of the same. To the best of our knowledge, ADVERSARIALuscator is the first-ever system that adopts the Markov Decision Process-based approach to convert and find a solution to the problem of creating individual obfuscations at the opcode level. This is important as the machine language level is the least at which functionality could be preserved so as to mimic an actual attack effectively. ADVERSARIALuscator is also the first-ever system to use efficient continuous action control capable of deep reinforcement learning agents like the Proximal Policy Optimization in the area of cyber security. Experimental results indicate that ADVERSARIALuscator could raise the metamorphic probability of a corpus of malware by >0.45. Additionally, more than 33 ADVERSARIALuscator were able to evade the most potent IDS. If such malware could intrude even into any of the IoT networks, then even if the original malware instance gets detected, by that time it can still infect the entire network. Hence ADVERSARIALuscator could be used to generate data representative of a swarm of very potent and coordinated AI-based metamorphic malware attacks. The so generated data and simulations could be used to bolster the defenses of an IDS against an actual AI-based metamorphic attack from advanced malware and ransomware.

READ FULL TEXT

page 11

page 16

page 22

research
10/16/2020

DOOM: A Novel Adversarial-DRL-Based Op-Code Level Metamorphic Malware Obfuscator for the Enhancement of IDS

We designed and developed DOOM (Adversarial-DRL based Opcode level Obfus...
research
02/01/2021

DRLDO: A novel DRL based De-ObfuscationSystem for Defense against Metamorphic Malware

In this paper, we propose a novel mechanism to normalize metamorphic and...
research
04/28/2020

SGX-SSD: A Policy-based Versioning SSD with Intel SGX

This paper demonstrates that SSDs, which perform device-level versioning...
research
12/09/2022

A Bayesian Model Combination-based approach to Active Malware Analysis

Active Malware Analysis involves modeling malware behavior by executing ...
research
10/12/2022

The State-of-the-Art in AI-Based Malware Detection Techniques: A Review

Artificial Intelligence techniques have evolved rapidly in recent years,...
research
11/05/2018

Malware Epidemics Effects in a Lanchester Conflict Model

For developing a better comprehension of the consequences of cyber-attac...
research
08/10/2023

Analysis of the LockBit 3.0 and its infiltration into Advanced's infrastructure crippling NHS services

The LockBit 3.0 ransomware variant is arguably the most threatening of m...

Please sign up or login with your details

Forgot password? Click here to reset