Being Single Has Benefits. Instance Poisoning to Deceive Malware Classifiers

10/30/2020
by   Tzvika Shapira, et al.
0

The performance of a machine learning-based malware classifier depends on the large and updated training set used to induce its model. In order to maintain an up-to-date training set, there is a need to continuously collect benign and malicious files from a wide range of sources, providing an exploitable target to attackers. In this study, we show how an attacker can launch a sophisticated and efficient poisoning attack targeting the dataset used to train a malware classifier. The attacker's ultimate goal is to ensure that the model induced by the poisoned dataset will be unable to detect the attacker's malware yet capable of detecting other malware. As opposed to other poisoning attacks in the malware detection domain, our attack does not focus on malware families but rather on specific malware instances that contain an implanted trigger, reducing the detection rate from 99.23 poisoning. We evaluate our attack on the EMBER dataset with a state-of-the-art classifier and malware samples from VirusTotal for end-to-end validation of our work. We propose a comprehensive detection approach that could serve as a future sophisticated defense against this newly discovered severe threat.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
12/12/2022

Machine Learning for Detecting Malware in PE Files

The increasing number of sophisticated malware poses a major cybersecuri...
research
11/22/2021

A Comparison of State-of-the-Art Techniques for Generating Adversarial Malware Binaries

We consider the problem of generating adversarial malware by a cyber-att...
research
05/07/2020

Defending Hardware-based Malware Detectors against Adversarial Attacks

In the era of Internet of Things (IoT), Malware has been proliferating e...
research
04/06/2019

On Training Robust PDF Malware Classifiers

Although state-of-the-art PDF malware classifiers can be trained with al...
research
08/28/2020

A Network-Assisted Approach for Ransomware Detection

Ransomware is a kind of malware using cryptographic mechanisms to preven...
research
03/02/2020

Exploring Backdoor Poisoning Attacks Against Malware Classifiers

Current training pipelines for machine learning (ML) based malware class...
research
05/23/2019

Characterizing Certain DNS DDoS Attacks

This paper details data science research in the area of Cyber Threat Int...

Please sign up or login with your details

Forgot password? Click here to reset