Early Stage Malware Prediction Using Recurrent Neural Networks
arXiv:1708.03513 · doi:10.1016/j.cose.2018.05.010
Abstract
Static malware analysis is well-suited to endpoint anti-virus systems as it can be conducted quickly by examining the features of an executable piece of code and matching it to previously observed malicious code. However, static code analysis can be vulnerable to code obfuscation techniques. Behavioural data collected during file execution is more difficult to obfuscate, but takes a relatively long time to capture - typically up to 5 minutes, meaning the malicious payload has likely already been delivered by the time it is detected. In this paper we investigate the possibility of predicting whether or not an executable is malicious based on a short snapshot of behavioural data. We find that an ensemble of recurrent neural networks are able to predict whether an executable is malicious or benign within the first 5 seconds of execution with 94% accuracy. This is the first time general types of malicious file have been predicted to be malicious during execution rather than using a complete activity log file post-execution, and enables cyber security endpoint protection to be advanced to use behavioural data for blocking malicious payloads rather than detecting them post-execution and having to repair the damage.
References in corpus (4)
- Empirical Evaluation of Gated Recurrent Neural Networks on Sequence Modeling
- A Comparison of Static, Dynamic, and Hybrid Analysis for Malware Detection
- Generic Black-Box End-to-End Attack Against State of the Art API Call Based Malware Classifiers
- Virtual Machine Introspection Based Malware Behavior Profiling and Family Grouping
Cited by in corpus (14)
- A Few-Shot Meta-Learning based Siamese Neural Network using Entropy Features for Ransomware Classification
- Redundancy Coefficient Gradual Up-weighting-based Mutual Information Feature Selection Technique for Crypto-ransomware Early Detection
- An Intrusion Detection System based on Deep Belief Networks
- Adversarial Attacks on Time-Series Intrusion Detection for Industrial Control Systems
- FedMUP: Federated Learning driven Malicious User Prediction Model for Secure Data Distribution in Cloud Environments
- MalPhase: Fine-Grained Malware Detection Using Network Flow Data
- MAIDS: Malicious Agent Identification-based Data Security Model for Cloud Environments
- Towards interpreting ML-based automated malware detection models: a survey
- Malware Detection Using Frequency Domain-Based Image Visualization and Deep Learning
- Quantized Non-Volatile Nanomagnetic Synapse based Autoencoder for Efficient Unsupervised Network Anomaly Detection
- Android Malware Clustering using Community Detection on Android Packages Similarity Network
- When deep learning meets security
- ANDRUSPEX : Leveraging Graph Representation Learning to Predict Harmful App Installations on Mobile Devices
- The First Step Towards Modeling Unbreakable Malware