The rise of metamorphic malware has sparked research interest in its dangerous attacks on information assets and computer networks. Sophos’s recent threat report reveals that 94% of malware targeting organizations are either metamorphic or polymorphic, highlighting the need for more research into these complex malicious categories of malware. Metamorphic malware alters its code with each execution, making detection challenging for traditional antivirus software. This paper employs a multi-objective evolutionary algorithm (MO-EA) in an adversarial learning setting to generate a large archive of evasive malware mutants serving as training data in detecting metamorphic malware. The experimental results show that MO-EA, when tested on malware stealing personal information, generated an archive of evasive malware mutants that evaded 60% to 73% of 63 detection engines. Compared to other approaches that employ a single-objective EA and quality-diversity EA, MO-EA offers a wider range of evasive mutants and thus a more robust archive that can serve as training data for machine learning models in detecting metamorphic malware.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Multi-Objective Evolutionary Algorithm for Automatic Generation of Adversarial Metamorphic Malware

  • Kehinde O. Babaagba,
  • Jordan Wylie,
  • Mayowa Ayodele,
  • Zhiyuan Tan

摘要

The rise of metamorphic malware has sparked research interest in its dangerous attacks on information assets and computer networks. Sophos’s recent threat report reveals that 94% of malware targeting organizations are either metamorphic or polymorphic, highlighting the need for more research into these complex malicious categories of malware. Metamorphic malware alters its code with each execution, making detection challenging for traditional antivirus software. This paper employs a multi-objective evolutionary algorithm (MO-EA) in an adversarial learning setting to generate a large archive of evasive malware mutants serving as training data in detecting metamorphic malware. The experimental results show that MO-EA, when tested on malware stealing personal information, generated an archive of evasive malware mutants that evaded 60% to 73% of 63 detection engines. Compared to other approaches that employ a single-objective EA and quality-diversity EA, MO-EA offers a wider range of evasive mutants and thus a more robust archive that can serve as training data for machine learning models in detecting metamorphic malware.