Attacking Malware Detection using Adversarial Machine Learning
Utkarsh Verma, Yonghong Huang, Carl Woodward, Craig Schmugar, Prashanth Palasamudram Ramagopal, Celeste Fralick · 2022
Machine Learning has been successfully used for many different cyber threat classification tasks including malware detection and distinguishing between malicious and nonmalicious programs. In cybersecurity, we have an adversary who is working to make the detection technologies fail. Although artificial neural networks perform very well on these cyber threat classification tasks, they are also vulnerable to adversarial examples. An adversarial example is a sample that has modifications made to it so that the neural networks misclassify it. Many techniques have been proposed, both for crafting adversarial examples and for hardening neural networks against them. However, most previous work has been done in the computer vision domain especially with images. We explain the challenges and findings of using Adversarial Machine Learning (AML) for attacking a Portable Executable (PE) Malware Classification System. We demonstrate how a Black-Box attack can be made against a PE Malware Classification System using AML Intelligence and evaluate popular defense techniques and their effectiveness in the malware domain.