• DocumentCode
    1950160
  • Title

    Malware-aware processors: A framework for efficient online malware detection

  • Author

    Ozsoy, Meltem ; Donovick, Caleb ; Gorelik, Iakov ; Abu-Ghazaleh, Nael ; Ponomarev, Dmitry

  • Author_Institution
    State Univ. of New York at Binghamton, Binghamton, NY, USA
  • fYear
    2015
  • fDate
    7-11 Feb. 2015
  • Firstpage
    651
  • Lastpage
    661
  • Abstract
    Security exploits and ensuant malware pose an increasing challenge to computing systems as the variety and complexity of attacks continue to increase. In response, software-based malware detection tools have grown in complexity, thus making it computationally difficult to use them to protect systems in real-time. Therefore, software detectors are applied selectively and at a low frequency, creating opportunities for malware to remain undetected. In this paper, we propose Malware-Aware Processors (MAP) - processors augmented with an online hardware-based detector to serve as the first line of defense to differentiate malware from legitimate programs. The output of this detector helps the system prioritize how to apply more expensive software-based solutions. The always-on nature of MAP detector helps protect against intermittently operating malware. Our work improves on the state of the art in the following ways: (1) We define and explore the use of sub-semantic features for online detection of malware. (2) We explore hardware implementations and show that simple classifiers appropriate for such implementations can effectively classify malware. We also study different classifiers, develop implementation optimizations, and explore complexity to performance trade-offs. (3) We propose a two-level detection framework where the hardware classifier prioritizes the work of a more accurate but more expensive software defense mechanism. (4) We integrate the MAP implementation with an open-source x86-compatible core, synthesizing the resulting design to run on an FPGA.
  • Keywords
    field programmable gate arrays; invasive software; microprocessor chips; FPGA; malware-aware processor; online hardware-based detector; online malware detection; open-source x86-compatible core; software defense mechanism; software-based malware detection tool; subsemantic feature; Complexity theory; Detectors; Feature extraction; Hardware; Malware; Program processors;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    High Performance Computer Architecture (HPCA), 2015 IEEE 21st International Symposium on
  • Conference_Location
    Burlingame, CA
  • Type

    conf

  • DOI
    10.1109/HPCA.2015.7056070
  • Filename
    7056070