研究生: 蔡尚洲
Shang-Chou Tsai
論文名稱: 一個透過重新排序系統階層執行流程的新穎物聯網惡意軟體分類器
A Novel IoT Malware Classifier Based on Reordering System-Level Execution Flow
指導教授: 鄭欣明
Shin-Ming Cheng
口試委員: 黃俊穎
Chun-Ying Huang
Shun-Wen Hsiao
Chia-Mei Chen
學位類別: 碩士
系所名稱: 電資學院 - 資訊工程系
Department of Computer Science and Information Engineering
論文出版年: 2022
畢業學年度: 110
語文別: 中文
論文頁數: 46
中文關鍵詞: 物聯網惡意軟體系統呼叫串列機器學習動態分析
外文關鍵詞: IoT malware, System call sequence, Machine learning, Dynamic analysis
描述的完整性連帶提高模型準確度。我們使用 84K 筆惡意軟體的資料集
在隨機森林上達到 98.7%,模型驗證時間和準確度都優於過往基於系統呼

In a modern society with rapid technological progress, the requirements
for performance and integration of devices are increasing every year. Terminal devices and Internet of Things(IoT) technologies are gradually becoming more and more important. However, the architecture of personal
computers and IoT devices is too different, so anti-virus software cannot be
directly applied on IoT architecture. Due to the above reasons, many information security vulnerabilities exist in the open networks of IoT devices.
For this reason, it is necessary to analyze and find the security vulnerabilities in the operation of IoT. In dynamic analysis, malware execution flows
extracted from sandboxes can be directly observed to detect malware attack behaviors. Although dynamic analysis can ignore malware obfuscation techniques at the binary level, malware creates multiple processes to
complete malicious attacks. The malicious behavior may masked by the
interleaved execution flow resulting in increased noise after feature transformation, which makes the analysis more difficult. In this paper, we propose a new classification framework for dynamic analysis by reordering
the execution process, i.e., System Call Name Sequence. Reordering has
two parts: splitting and fusion. Splitting can effectively reduce the noise
after feature transition. Fusion can improve the descriptive completeness of
the malicious behavior feature vector and the model accuracy. We conduct
experiments using 84K malware data set to verify the effectiveness of the
proposed method. The results show that the accuracy of malware classification reaches 98.7% on Random Forest, and the model verification time
and accuracy are better than the previous classification method based on
system call name sequence.

