Task-Aware Meta Learning-based Siamese Neural Network for Classifying Obfuscated Malware

10/26/2021
by   Jinting Zhu, et al.
0

Malware authors apply different obfuscation techniques on the generic feature of malware (i.e., unique malware signature) to create new variants to avoid detection. Existing Siamese Neural Network (SNN) based malware detection methods fail to correctly classify different malware families when similar generic features are shared across multiple malware variants resulting in high false-positive rates. To address this issue, we propose a novel Task-Aware Meta Learning-based Siamese Neural Network resilient against obfuscated malware while able to detect malware trained with one or a few training samples. Using entropy features of each malware signature alongside image features as task inputs, our task-aware meta leaner generates the parameters for the feature layers to more accurately adjust the feature embedding for different malware families. In addition, our model utilizes meta-learning with the extracted features of a pre-trained network (e.g., VGG-16) to avoid the bias typically associated with a model trained with a limited number of training samples. Our proposed approach is highly effective in recognizing unique malware signatures, thus correctly classifying malware samples that belong to the same malware family even in the presence of obfuscation technique applied to malware. Our experimental results, validated with N-way on N-shot learning, show that our model is highly effective in classification accuracy exceeding the rate>91 compared to other similar methods.

READ FULL TEXT
research
12/01/2021

A Few-Shot Meta-Learning based Siamese Neural Network using Entropy Features for Ransomware Classification

Ransomware defense solutions that can quickly detect and classify differ...
research
11/21/2017

DeepSign: Deep Learning for Automatic Malware Signature Generation and Classification

This paper presents a novel deep learning based method for automatic mal...
research
07/21/2022

A Ransomware Triage Approach using a Task Memory based on Meta-Transfer Learning Framework

Solutions for rapid prioritization of different ransomware have been rai...
research
01/26/2021

Malware Detection Using Frequency Domain-Based Image Visualization and Deep Learning

We propose a novel method to detect and visualize malware through image ...
research
11/08/2021

OMD: Orthogonal Malware Detection Using Audio, Image, and Static Features

With the growing number of malware and cyber attacks, there is a need fo...
research
02/01/2021

DRLDO: A novel DRL based De-ObfuscationSystem for Defense against Metamorphic Malware

In this paper, we propose a novel mechanism to normalize metamorphic and...
research
05/02/2023

MDENet: Multi-modal Dual-embedding Networks for Malware Open-set Recognition

Malware open-set recognition (MOSR) aims at jointly classifying malware ...

Please sign up or login with your details

Forgot password? Click here to reset