IoT malware classification based on reinterpreted function-call graphs. Issue 125 (February 2023)
- Record Type:
- Journal Article
- Title:
- IoT malware classification based on reinterpreted function-call graphs. Issue 125 (February 2023)
- Main Title:
- IoT malware classification based on reinterpreted function-call graphs
- Authors:
- Wu, Chia-Yi
Ban, Tao
Cheng, Shin-Ming
Takahashi, Takeshi
Inoue, Daisuke - Abstract:
- Abstract: Various malware and cyberattacks have arisen along with the proliferation of IoT devices. The evolving malware targeting IoT devices calls forth effective and efficient solutions to protect vulnerable IoT devices from being compromised. In this paper, we investigate the feasibility of a state-of-the-art graph embedding method, g r a p h 2 v e c, for performing family classification for IoT malware, with promising results reported. To further improve the generalization performance of the classifiers based on g r a p h 2 v e c -extracted features, we propose two new mechanisms to improve the quality of feature representation. First, we unify user-defined function calls by reinterpreting the opcode sequences therein to better capture the semantics of the function-call relationship in malware binaries. Then, we integrate literal information into the g r a p h 2 v e c embedding of the function call graph to achieve better discriminant ability. To prove the effectiveness of the proposed scheme, we carried out performance comparison on a large-scale dataset containing more than 108K malware binaries collected from seven CPU architectures. The accuracy rates obtained by five widely adopted classifiers on malware family classification are improved by 2%, on average, by adopting the two proposed mechanisms. Specifically, when combined with the proposed approach, the support vector machine classifier obtained an accuracy rate of 98.88% on malware family classification,Abstract: Various malware and cyberattacks have arisen along with the proliferation of IoT devices. The evolving malware targeting IoT devices calls forth effective and efficient solutions to protect vulnerable IoT devices from being compromised. In this paper, we investigate the feasibility of a state-of-the-art graph embedding method, g r a p h 2 v e c, for performing family classification for IoT malware, with promising results reported. To further improve the generalization performance of the classifiers based on g r a p h 2 v e c -extracted features, we propose two new mechanisms to improve the quality of feature representation. First, we unify user-defined function calls by reinterpreting the opcode sequences therein to better capture the semantics of the function-call relationship in malware binaries. Then, we integrate literal information into the g r a p h 2 v e c embedding of the function call graph to achieve better discriminant ability. To prove the effectiveness of the proposed scheme, we carried out performance comparison on a large-scale dataset containing more than 108K malware binaries collected from seven CPU architectures. The accuracy rates obtained by five widely adopted classifiers on malware family classification are improved by 2%, on average, by adopting the two proposed mechanisms. Specifically, when combined with the proposed approach, the support vector machine classifier obtained an accuracy rate of 98.88% on malware family classification, outperforming known function-call-graph (FCG)-based methods and previous work on static malware analysis. … (more)
- Is Part Of:
- Computers & security. Issue 125(2023)
- Journal:
- Computers & security
- Issue:
- Issue 125(2023)
- Issue Display:
- Volume 125, Issue 125 (2023)
- Year:
- 2023
- Volume:
- 125
- Issue:
- 125
- Issue Sort Value:
- 2023-0125-0125-0000
- Page Start:
- Page End:
- Publication Date:
- 2023-02
- Subjects:
- Cybersecurity -- IoT malware analysis -- Machine learning -- Static analysis -- Graph embedding
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2022.103060 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 24838.xml