DRLDO: A novel DRL based De-ObfuscationSystem for Defense against Metamorphic Malware

02/01/2021
by   Mohit Sewak, et al.
3

In this paper, we propose a novel mechanism to normalize metamorphic and obfuscated malware down at the opcode level and hence create an advanced metamorphic malware de-obfuscation and defense system. We name this system DRLDO, for Deep Reinforcement Learning based De-Obfuscator. With the inclusion of the DRLDO as a sub-component, an existing Intrusion Detection System could be augmented with defensive capabilities against 'zero-day' attacks from obfuscated and metamorphic variants of existing malware. This gains importance, not only because there exists no system to date that uses advanced DRL to intelligently and automatically normalize obfuscation down even to the opcode level, but also because the DRLDO system does not mandate any changes to the existing IDS. The DRLDO system does not even mandate the IDS' classifier to be retrained with any new dataset containing obfuscated samples. Hence DRLDO could be easily retrofitted into any existing IDS deployment. We designed, developed, and conducted experiments on the system to evaluate the same against multiple-simultaneous attacks from obfuscations generated from malware samples from a standardized dataset that contains multiple generations of malware. Experimental results prove that DRLDO was able to successfully make the otherwise un-detectable obfuscated variants of the malware detectable by an existing pre-trained malware classifier. The detection probability was raised well above the cut-off mark to 0.6 for the classifier to detect the obfuscated malware unambiguously. Further, the de-obfuscated variants generated by DRLDO achieved a very high correlation (of 0.99) with the base malware. This observation validates that the DRLDO system is actually learning to de-obfuscate and not exploiting a trivial trick.

READ FULL TEXT

page 6

page 17

page 18

research
10/16/2020

DOOM: A Novel Adversarial-DRL-Based Op-Code Level Metamorphic Malware Obfuscator for the Enhancement of IDS

We designed and developed DOOM (Adversarial-DRL based Opcode level Obfus...
research
09/23/2021

ADVERSARIALuscator: An Adversarial-DRL Based Obfuscator and Metamorphic Malware SwarmGenerator

Advanced metamorphic malware and ransomware, by using obfuscation, could...
research
09/12/2021

DRo: A data-scarce mechanism to revolutionize the performance of Deep Learning based Security Systems

Supervised Deep Learning requires plenty of labeled data to converge, an...
research
12/16/2022

WebAssembly Diversification for Malware Evasion

WebAssembly is a binary format that has become an essential component of...
research
11/19/2019

Volenti non fit injuria: Ransomware and its Victims

With the recent growth in the number of malicious activities on the inte...
research
02/25/2019

An Intrusion Using Malware and DDNS

This whitepaper captures the details of the technical alert numbered TA1...
research
10/26/2021

Task-Aware Meta Learning-based Siamese Neural Network for Classifying Obfuscated Malware

Malware authors apply different obfuscation techniques on the generic fe...

Please sign up or login with your details

Forgot password? Click here to reset