Robust Detection Model for Portable Execution Malware
Wanjia Zheng, Kazumasa Omote · 2021
With recent technological developments, it has become natural for personal computers and Internet of Things(IoT) devices, such as smartphones and tablets, to remain constantly connected to the Internet. Malicious attackers are known to abuse malware to achieve their nefarious purposes, necessitating the implementation of defense systems as protection. Methods such as machine learning-based techniques, which have been utilized with great success in various fields such as image recognition and processing, and voice recognition, are used to prevent cyberattacks caused by malware. However, several adversarial attack methods have been proposed in recent years to induce malfunctions in machine learning-based models. In this study, we focus on malware detection field and treat the aforementioned issue from the perspectives of both attackers and defenders; subsequently, we propose a novel adversarial attack method, named IMAGE_RESOURCE attack, and a robust malware detection model, respectively, using dimension reduction and machine learning techniques. The robustness of the proposed model is evaluated using portable execution (PE) surface information obtained from the FFRI Dataset 2018. During robustness evaluation, distances (e.g., Euclidean distance) between the malware and benign files are measured, and the effectiveness of IMAGE_RESOURCE attack is estimated. Thus, we establish the effectiveness and superiority of the proposed model in terms of detection accuracy and robustness.