Opening book details…
Can I read Learning to Evade Static PE Machine Learning Malware Models via Reinforcement Learning on EtoBox?
Learning to Evade Static PE Machine Learning Malware Models via Reinforcement Learning by Anderson, Hyrum S.; Kharkar, Anant; Filar, Bobby; Evans, David; Roth, Phil is a scholarly article available to read on EtoBox.
What is Learning to Evade Static PE Machine Learning Malware Models via Reinforcement Learning about?
Machine learning is a popular approach to signatureless malware detection because it can generalize to never-before-seen malware families and polymorphic strains. This has resulted in its practical use for either primary detection engines or for supplementary heuristic detection by anti-malware vendors. Recent work in adversarial machine learning has shown that deep learning models are susceptible to gradient-based attacks, whereas non-differentiable models that report a score can be attacked by genetic algorithms that aim to systematically reduce the score. We propose a more general framework based on reinforcement learning (RL) for attacking static portable executable (PE) anti-malware engines. The general framework does not require a differentiable model nor does it require the engine to produce a score. Instead, an RL agent is equipped with a set of functionality-preserving operations that it may perform on the PE file. Through a series of games played against the anti-malware engine, it learns which sequences of operations are likely to result in evading the detector for any given malware sample. This enables completely black-box attacks against static PE anti-malware, and pro
- Author
- Anderson, Hyrum S.; Kharkar, Anant; Filar, Bobby; Evans, David; Roth, Phil
- Published
- 2018
- Language
- EN
More by Anderson, Hyrum S.; Kharkar, Anant; Filar, Bobby; Evans, David; Roth, Phil
Browse all works by Anderson, Hyrum S.; Kharkar, Anant; Filar, Bobby; Evans, David; Roth, Phil