For many years, executable packing has been used for a variety of applications, including software protection but also malware obfuscation. Even today, this evasion technique remains an open issue, particularly in malware analysis. Numerous studies have proposed static detection techniques based on various algorithms and features, taking advantage of machine learning to build increasingly powerful models. These studies have focused in particular on supervised learning, but unsupervised learning remains relatively unexploited yet. Furthermore, most studies related to adversarial learning focused on attacks in the feature space while those targeting features identified as significant in supervised models are still rather limited. Such features may be still manipulated from the problem space for causing misclassification. The objective of this study is to apply alterations on packed samples based on realistic modifications and visualize their effect using unsupervised learning. To this end, the Packing Box experimental toolkit is used to build a dataset, train models, apply alterations, retrain models and then highlight the consequences of these alterations on the trained models.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Highlighting the Impact of Packed Executable Alterations with Unsupervised Learning

  • Alexandre D’Hondt,
  • Charles Henry Bertrand Van Ouytsel,
  • Axel Legay

摘要

For many years, executable packing has been used for a variety of applications, including software protection but also malware obfuscation. Even today, this evasion technique remains an open issue, particularly in malware analysis. Numerous studies have proposed static detection techniques based on various algorithms and features, taking advantage of machine learning to build increasingly powerful models. These studies have focused in particular on supervised learning, but unsupervised learning remains relatively unexploited yet. Furthermore, most studies related to adversarial learning focused on attacks in the feature space while those targeting features identified as significant in supervised models are still rather limited. Such features may be still manipulated from the problem space for causing misclassification. The objective of this study is to apply alterations on packed samples based on realistic modifications and visualize their effect using unsupervised learning. To this end, the Packing Box experimental toolkit is used to build a dataset, train models, apply alterations, retrain models and then highlight the consequences of these alterations on the trained models.