Malware is definitely one of the greatest threats to modern computer systems. A successful attack can have catastrophic financial consequences for companies and government institutions. To remain under the radar, attackers practically always use some code obfuscation method. The techniques utilized are becoming increasingly sophisticated and are no longer limited to compression or encryption. The newest trend is to apply solutions based on Artificial Intelligence algorithms. In this paper, we investigate to what extent such techniques can be used to obfuscate malicious code. To this aim, sample implementations of malicious programs that use neural networks to obfuscate their code are presented and analyzed. Additionally, potential countermeasures for such threats are proposed. The obtained results prove that NN enhanced malware is an issue for the existing detection systems. Moreover, the introduced dedicated detection approach is effective, however, the attacker can still adapt and avoid disclosure.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Assessing the Threat of Neural Network Enhanced Obfuscation in Malware

  • Adrian Brodzik,
  • Wojciech Mazurczyk

摘要

Malware is definitely one of the greatest threats to modern computer systems. A successful attack can have catastrophic financial consequences for companies and government institutions. To remain under the radar, attackers practically always use some code obfuscation method. The techniques utilized are becoming increasingly sophisticated and are no longer limited to compression or encryption. The newest trend is to apply solutions based on Artificial Intelligence algorithms. In this paper, we investigate to what extent such techniques can be used to obfuscate malicious code. To this aim, sample implementations of malicious programs that use neural networks to obfuscate their code are presented and analyzed. Additionally, potential countermeasures for such threats are proposed. The obtained results prove that NN enhanced malware is an issue for the existing detection systems. Moreover, the introduced dedicated detection approach is effective, however, the attacker can still adapt and avoid disclosure.