Anomaly based malware threat detection on Linux Systems

Jayanthi Ramamoorthy, Narasimha Shashidhar, Bing Zhou · 2023

There has been a steady increase in malware targeting Linux-based systems. With the proliferation of embedded IoT devices and cloud architectures that use Linux or Unix-based Operating Systems, this trend is expected to grow. Most modern Linux distributions include a configurable and queryable userspace component for security auditing with auditd (audit daemon) subsystem. In a multi-user, enterprise environment, these audit events are typically collected in a centralized repository as a source for threat detection and Incident response. Attack techniques used by malicious programs such as process injection and memory corruption are commonly seen in fileless malware, insider threats, and zero day attacks. Such attacks are difficult to detect through traditional signature-based methods since there are no known, discernible indicators of compromise. This study proposes a novel method of using Linux process overlay (execve) audit logs to identify threats from malicious executable and shellcode, with Machine Learning. Our study proposes a methodology that uses a Sparse Autoencoder Deep Learning model to effectively detect these security threats as anomalies, with an accuracy of over 95 percent. We suggest this approach as a feasible enterprise solution to identify Linux malware and detect security threat anomalies by leveraging native Linux audit logging capabilities.

Read the paper · More papers on PaperTik