arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

基于硬件性能计数器的恶意软件检测分类器性能研究

On the Performance of Malware Detection Classifiers Using Hardware Performance Counters

Alireza Abolhasani Zeraatkar, Parnian Shabani Kamran, Inderpreet Kaur, Nagabindu Ramu, Tyler Sheaves, Hussain Al-Asaad

arXiv 2608.02671首次发表:更新:

发表机构

University of California; ECE Department(加利福尼亚大学; 电子与计算机工程系)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究提出用硬件性能计数器(HPC)结合机器学习分类器进行运行时恶意软件检测,采用集成学习技术减少所需HPC数量,实验表明其性能优于或匹配更多HPC的标准检测器,提升了处理器效率。

AI 中文摘要

利用硬件性能计数器(Hardware Performance Counters,HPC)进行恶意软件检测,作为杀毒软件的补充,已成为提升计算系统安全性的有前景方案。基于硬件的恶意软件检测器(Hardware-based Malware Detectors,HMD)采用机器学习(Machine Learning,ML)分类器检测恶意应用模式,ML分类器的输入是称为HPC的低级性能特征,即运行时从处理器收集的与硬件相关的活动数据,用于刻画应用的低级微架构行为。本文提出利用HPC和ML分类器进行恶意软件检测,并强调运行时恶意软件检测的有效性。我们采用集成学习技术提升HMD的性能,减少所需微架构事件的数量;由于处理器每个周期仅能测量2至8个事件,该技术无需多次运行应用,从而提升了处理器效率。我们使用18种机器学习模型及两种集成学习方法评估恶意软件检测性能,共构建144种不同配置。实验结果表明,采用集成技术的基于2个HPC的集成学习恶意软件检测,性能比使用8个HPC的标准分类器最高提升10%;在仅需4个HPC的情况下,其性能与使用16个HPC的标准ML检测器相当,可实现有效的运行时恶意软件检测。

英文摘要

Malware detection using Hardware Performance Counters (HPC) has emerged as a promising solution to improve the security of computing systems as a complement to antivirus software. Hardware-based malware detectors (HMD) use Machine Learning (ML) classifiers to detect malicious application patterns. The inputs to ML classifiers are low-level performance features known as HPCs, hardware-related activity data collected from a processor at run time to profile the low-level microarchitectural behavior of an application. This paper proposes malware detection using HPCs and machine learning classifiers and highlights the effectiveness of malware detection at run-time. We use ensemble learning techniques to improve the performance of the hardware-based malware detectors, which reduces the number of necessary micro-architectural events. This improves the processor's efficiency by eliminating the need to run an application several times since a processor can measure only 2 to 8 events at a cycle. We use 18 machine-learning models along with two ensemble learning methods to evaluate the malware detection performance, creating a total of 144 different configurations. The experimental results show that the ensemble learning-based malware detection with 2 HPCs using the ensemble technique outperforms standard classifiers with 8 HPCs by up to 10%. It also matches the performance of standard ML-based detectors that use 16 HPCs while requiring only 4 HPCs, thereby enabling effective run-time malware detection.

Journal ref2024 International Conference on Smart Applications, Communications and Networking (SmartNets), IEEE, 2024

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑