Monotonic-HMDs: Exploiting Monotonic Features to Defend Against Evasive Malware
Md Shohidul Islam, Behnam Omidi, Khaled N. Khasawneh · 2021
Machine learning-based hardware malware detectors (HMDs) offer a potential game-changing advantage in defending systems against malware. However, HMDs suffer from adversarial attacks; they can be effectively reverse-engineered and subsequently be evaded, allowing malware to hide from detection. Adversarial evasion attacks requires adding benign features to the program execution to be able to evade detection. Against these attacks, in this paper, we propose Monotonic-HMDs, which are HMDs built using monotonic features to defend against adversarial evasion attacks. Specifically, Monotonic-HMDs are build using monotonic malicious features only. Thus, Monotonic-HMDs ensures that an adversary cannot evade the detection by simply adding benign features to the malware programs since they are not used in the Monotonic-HMD model. In addition, adding malicious features will only increase the probability of detecting the input program as malware. Our experimental results demonstrate that Monotonic-HMDs offer effective defense against adversarial attacks without sacrificing significant detection accuracy, which can be interpreted as a cost for security in classifying malware. Importantly, our results shows that for evasive malware that can completely evade current HMDs, the proposed Monotonic-HMDs achieve 83% detection accuracy and maintain this accuracy even under more aggressive attacks. Moreover, Monotonic-HMDs reduce the inference time, i.e., time to perform one detection, by 61.11%. Furthermore, the hardware implementation results of the Monotonic-HMDs shows that Monotonic-HMDs offers area and power consumption savings compared to current HMDs.