研究打包对机器学习杀毒系统的影响,发现现有方法在面对打包恶意软件时表现显著下降。
Assessing the Impact of Packing on Machine Learning-Based Malware Detection and Classification Systems
- 对比多种打包技术对静态机器学习模型性能的影响
- 发现打包导致检测准确率普遍下降,尤其影响可视化特征提取
- 提醒安全团队需提前应对恶意软件作者的打包策略
恶意软件的泛滥,尤其是通过打包技术隐藏代码,给静态分析和基于签名的检测方法带来了巨大挑战。打包会干扰原始可执行文件中特征和签名的提取。为应对日益增多的真实世界恶意软件,研究人员和反病毒公司开始利用机器学习取得良好效果。然而,关于打包对基于机器学习的静态恶意软件检测与分类系统的影响,目前知之甚少。本文填补这一空白,深入研究打包对静态机器学习模型在恶意软件检测与分类中的性能影响,特别关注使用可视化技术的模型。我们对多种打包技术进行了全面分析,揭示了当前静态检测系统的局限性,并强调必须主动应对恶意软件作者不断演进的攻击手段。
原文摘要 · Abstract (English)
The proliferation of malware, particularly through the use of packing, presents a significant challenge to static analysis and signature-based malware detection techniques. The application of packing to the original executable code renders extracting meaningful features and signatures challenging. To deal with the increasing amount of malware in the wild, researchers and anti-malware companies started harnessing machine learning capabilities with very promising results. However, little is known about the effects of packing on static machine learning-based malware detection and classification systems. This work addresses this gap by investigating the impact of packing on the performance of static machine learning-based models used for malware detection and classification, with a particular focus on those using visualisation techniques. To this end, we present a comprehensive analysis of various packing techniques and their effects on the performance of machine learning-based detectors and classifiers. Our findings highlight the limitations of current static detection and classification systems and underscore the need to be proactive to effectively counteract the evolving tactics of malware authors.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。