Study of infostealers using Graph Neural Networks

Álvaro Bustos-Tabernero, Daniel López-Sánchez, Angélica González Arrieta, Paulo Nováis · Logic Journal of IGPL · 2024

Abstract Cybersecurity technology has the ability to detect malware through a variety of methods, such as signature recognition, logical rules or the identification of known malware stored in a database or public source. However, threat actors continuously try to create new variants of existing malware by obfuscating or altering parts of the code to evade detection by antivirus engines. Infostealers are one of the most common malicious programs aimed at obtaining personal or banking information from an infected system and exfiltrating it. In addition, they are the precursors of potentially high-security incidents because attackers gain a entry into companies’ internal systems and may even access them with administrator permissions. This article demonstrates how a feature vector can be obtained from the assembly code of a Windows binary and how a a Graph Neural Network can be used to determine, with ninety percent accuracy, whether it is an infostealer.

Read the paper · More papers on PaperTik