Skip to main content

Research Repository

Advanced Search

A multilabel fuzzy relevance clustering system for malware attack attribution in the edge layer of cyber-physical networks

Alaeiyan, M; Dehghantanha, A; Dargahi, T; Conti, M; Parsa, S

A multilabel fuzzy relevance clustering system for malware attack attribution in the edge layer of cyber-physical networks Thumbnail


Authors

M Alaeiyan

A Dehghantanha

T Dargahi

M Conti

S Parsa



Abstract

The rapid increase in the number of malicious programs has made malware forensics a daunting task and caused users’ systems to become in danger. Timely identification of malware characteristics including its origin and the malware sample family would significantly limit the potential damage of malware. This is a more profound risk in Cyber-Physical Systems (CPSs), where a malware attack may cause significant physical damage to the infrastructure. Due to limited on-device available memory and processing power in CPS devices, most of the efforts for protecting CPS networks are focused on the edge layer, where the majority of security mechanisms are deployed.

Since the majority of advanced and sophisticated malware programs are combining features from different families, these malicious programs are not similar enough to any existing malware family and easily evade binary classifier detection. Therefore, in this article, we propose a novel multilabel fuzzy clustering system for malware attack attribution. Our system is deployed on the edge layer to provide insight into applicable malware threats to the CPS network. We leverage static analysis by utilizing Opcode frequencies as the feature space to classify malware families.

We observed that a multilabel classifier does not classify a part of samples. We named this problem the instance coverage problem. To overcome this problem, we developed an ensemble-based multilabel fuzzy classification method to suggest the relevance of a malware instance to the stricken families. This classifier identified samples of VirusShare, RansomwareTracker, and BIG2015 with an accuracy of 94.66%, 94.26%, and 97.56%, respectively.

Citation

Alaeiyan, M., Dehghantanha, A., Dargahi, T., Conti, M., & Parsa, S. (2020). A multilabel fuzzy relevance clustering system for malware attack attribution in the edge layer of cyber-physical networks. ACM transactions on cyber-physical systems, 4(3), 1-22. https://doi.org/10.1145/3351881

Journal Article Type Article
Acceptance Date Jul 1, 2019
Online Publication Date Mar 12, 2020
Publication Date Mar 12, 2020
Deposit Date Apr 7, 2020
Publicly Available Date Apr 7, 2020
Journal ACM Transactions on Cyber-Physical Systems
Print ISSN 2378-962X
Electronic ISSN 2378-9638
Publisher Association for Computing Machinery (ACM)
Volume 4
Issue 3
Pages 1-22
DOI https://doi.org/10.1145/3351881
Publisher URL https://doi.org/10.1145/3351881
Related Public URLs https://dl-acm-org.salford.idm.oclc.org/journal/tcps

Files

A multilabel fuzzy relevance clustering system for malware attack attribution in the edge layer of cyber-physical networks-ACCEPTED VERSION.pdf (1.7 Mb)
PDF




Downloadable Citations