DAEMON: Dataset-Agnostic Explainable Malware Classification Using Multi-Stage Feature Mining

08/04/2020
by   Ron Korine, et al.
0

Numerous metamorphic and polymorphic malicious variants are generated automatically on a daily basis by mutation engines that transform the code of a malicious program while retaining its functionality, in order to evade signature-based detection. These automatic processes have greatly increased the number of malware variants, deeming their fully-manual analysis impossible. Malware classification is the task of determining to which family a new malicious variant belongs. Variants of the same malware family show similar behavioral patterns. Thus, classifying newly discovered variants helps assess the risks they pose and determine which of them should undergo manual analysis by a security expert. This motivated intense research in recent years of how to devise high-accuracy automatic tools for malware classification. In this paper, we present DAEMON - a novel dataset-agnostic and even platform-agnostic malware classifier. We've optimized DAEMON using a large-scale dataset of x86 binaries, belonging to a mix of several malware families targeting computers running Windows. We then applied it, without any algorithmic change, features re-engineering or parameter tuning, to two other large-scale datasets of malicious Android applications of numerous malware families. DAEMON obtained top-notch classification results on all datasets, making it the first provably dataset-agnostic malware classifier to date. An important byproduct of the type of features used by DAEMON and the manner in which they are mined is that its classification results are explainable.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/11/2021

FamDroid: Learning-Based Android Malware Family Classification Using Static Analysis

Android is currently the most extensively used smartphone platform in th...
research
11/13/2015

Novel Feature Extraction, Selection and Fusion for Effective Malware Family Classification

Modern malware is designed with mutation characteristics, namely polymor...
research
09/22/2018

DeepOrigin: End-to-End Deep Learning for Detection of New Malware Families

In this paper, we present a novel method of differentiating known from p...
research
08/28/2022

Shedding Light on the Targeted Victim Profiles of Malicious Downloaders

Malware affects millions of users worldwide, impacting the daily lives o...
research
02/17/2020

Tools and Techniques for Malware Detection and Analysis

One of the major and serious threats that the Internet faces today is th...
research
09/19/2020

Optimizing Away JavaScript Obfuscation

JavaScript is a popular attack vector for releasing malicious payloads o...
research
06/23/2021

MG-DVD: A Real-time Framework for Malware Variant Detection Based on Dynamic Heterogeneous Graph Learning

Detecting the newly emerging malware variants in real time is crucial fo...

Please sign up or login with your details

Forgot password? Click here to reset