A Comparison of State-of-the-Art Techniques for Generating Adversarial Malware Binaries
arXiv:2111.11487
Abstract
We consider the problem of generating adversarial malware by a cyber-attacker where the attacker's task is to strategically modify certain bytes within existing binary malware files, so that the modified files are able to evade a malware detector such as machine learning-based malware classifier. We have evaluated three recent adversarial malware generation techniques using binary malware samples drawn from a single, publicly available malware data set and compared their performances for evading a machine-learning based malware classifier called MalConv. Our results show that among the compared techniques, the most effective technique is the one that strategically modifies bytes in a binary's header. We conclude by discussing the lessons learned and future research directions on the topic of adversarial malware generation.
18 pages, 7 figures; summer project report from NREIP internship at Naval Research Laboratory
References in corpus (9)
- Generating Adversarial Malware Examples for Black-Box Attacks Based on GAN
- DeepSign: Deep Learning for Automatic Malware Signature Generation and Classification
- Learning to Evade Static PE Machine Learning Malware Models via Reinforcement Learning
- EMBER: An Open Dataset for Training Static PE Malware Machine Learning Models
- Deceiving End-to-End Deep Learning Malware Detectors using Adversarial Examples
- Malware Makeover: Breaking ML-based Static Analysis by Modifying Executable Bytes
- SOREL-20M: A Large Scale Benchmark Dataset for Malicious PE Detection
- Binary Black-box Evasion Attacks Against Deep Learning-based Static Malware Detectors with Adversarial Byte-Level Language Model
- Evading Malware Classifiers via Monte Carlo Mutant Feature Discovery