XMD: An Expansive Hardware-telemetry based Malware Detector to enhance Endpoint Detection

06/24/2022
by   Harshit Kumar, et al.
0

Hardware-based Malware Detectors (HMDs) have shown promise in detecting malicious workloads. However, the current HMDs focus solely on the CPU core of a System-on-Chip (SoC) and, therefore, do not exploit the full potential of the hardware telemetry. In this paper, we propose XMD, an HMD that operates on an expansive set of telemetry channels extracted from the different subsystems of SoC. Key innovations in XMD are guided by analytical theorems that leverage the concept of manifold hypothesis. XMD exploits the thread-level profiling power of the CPU-core telemetry, and the global profiling power of non-core telemetry channels, to achieve significantly better detection performance and concept drift robustness than currently used Hardware Performance Counter (HPC) based detectors. We train and evaluate XMD using hardware telemetries collected from 904 benign applications and 1205 malware samples. XMD improves over currently used HPC-based detectors by 32.91 67.57 performance of 86.54 detection rate of 80 Anti-Virus(AV) on VirusTotal, on the same set of malware samples.

READ FULL TEXT

page 10

page 11

page 20

research
03/21/2021

Towards Improving the Trustworthiness of Hardware based Malware Detector using Online Uncertainty Estimation

Hardware-based Malware Detectors (HMDs) using Machine Learning (ML) mode...
research
05/07/2020

Defending Hardware-based Malware Detectors against Adversarial Attacks

In the era of Internet of Things (IoT), Malware has been proliferating e...
research
12/08/2022

PKDGA: A Partial Knowledge-based Domain Generation Algorithm for Botnets

Domain generation algorithms (DGAs) can be categorized into three types:...
research
05/17/2022

A two-steps approach to improve the performance of Android malware detectors

The popularity of Android OS has made it an appealing target to malware ...
research
08/09/2022

Robust Machine Learning for Malware Detection over Time

The presence and persistence of Android malware is an on-going threat th...
research
03/01/2018

The Shape of Alerts: Detecting Malware Using Distributed Detectors by Robustly Amplifying Transient Correlations

We introduce a new malware detector - Shape-GD - that aggregates per-mac...
research
01/05/2022

Comprehensive Efficiency Analysis of Machine Learning Algorithms for Developing Hardware-Based Cybersecurity Countermeasures

Modern computing systems have led cyber adversaries to create more sophi...

Please sign up or login with your details

Forgot password? Click here to reset