Antivirus Applied to IoT Malware Detection based on Runtime Behaviors

Nowadays, the Internet of Things (IoT) has a significant impact on people’s lives, reaching hundreds of billions of Internet-connected devices. Due to the popularity of smart devices, the number of tech-driven cyber attacks has increased in recent years. The constant emergence of new malware aimed a...

Full description

Bibliographic Details
Main Authors: SILVA, S.H. M. T., LIMA, S.M.L., PINHEIRO, R.P., LIMA, R. D. T., ABREU, L. M. S., FERNANDES, S. M. M.
Format: Article
Language:English
Published: Faculdade Salesiana Maria Auxiliadora 2022-06-01
Series:Sistemas de Informação
Subjects:
Online Access:http://www.fsma.edu.br/si/edicao29/Download_FSMA_SI_2022_1_Principal_3.html
_version_ 1797860734557749248
author SILVA, S.H. M. T.
LIMA, S.M.L.
PINHEIRO, R.P.
LIMA, R. D. T.
ABREU, L. M. S.
FERNANDES, S. M. M.
author_facet SILVA, S.H. M. T.
LIMA, S.M.L.
PINHEIRO, R.P.
LIMA, R. D. T.
ABREU, L. M. S.
FERNANDES, S. M. M.
author_sort SILVA, S.H. M. T.
collection DOAJ
description Nowadays, the Internet of Things (IoT) has a significant impact on people’s lives, reaching hundreds of billions of Internet-connected devices. Due to the popularity of smart devices, the number of tech-driven cyber attacks has increased in recent years. The constant emergence of new malware aimed at IoT, such as the botnet, the use of complex obfuscation and evasion techniques, and often the availability of large resources for its development, makes him the biggest cyber villain in IoT scenarios today. The present work creates an Antivirus for Dynamic Malware Analysis based on Artificial Neural Networks, equipped with statistical learning and Artificial Intelligence, specialized in malware detection from 32-bit IoT architectures of the Advanced RISC Machine (ARM) type. Under different starting conditions and learning functions, our antivirus architectures are investigated to maximize their accuracy. The absence or limitation in the detection of malicious software by commercial antivirus can be provided by a smart antivirus. Instead of models based on blacklists or heuristics, our antivirus allows the detection of malware on embedded Linux systems in a preventive and non-reactive way like Clamav’s modus operandi and other traditional antiviruses.
first_indexed 2024-04-09T21:51:11Z
format Article
id doaj.art-1bbc782ea77e4c11b12d21188b0de03a
institution Directory Open Access Journal
issn 1983-5604
language English
last_indexed 2024-04-09T21:51:11Z
publishDate 2022-06-01
publisher Faculdade Salesiana Maria Auxiliadora
record_format Article
series Sistemas de Informação
spelling doaj.art-1bbc782ea77e4c11b12d21188b0de03a2023-03-24T17:29:20ZengFaculdade Salesiana Maria AuxiliadoraSistemas de Informação1983-56042022-06-011292544Antivirus Applied to IoT Malware Detection based on Runtime BehaviorsSILVA, S.H. M. T.0LIMA, S.M.L.1PINHEIRO, R.P.2LIMA, R. D. T.3ABREU, L. M. S.4FERNANDES, S. M. M.5UPEUFPEUPEUPEUFPEUPENowadays, the Internet of Things (IoT) has a significant impact on people’s lives, reaching hundreds of billions of Internet-connected devices. Due to the popularity of smart devices, the number of tech-driven cyber attacks has increased in recent years. The constant emergence of new malware aimed at IoT, such as the botnet, the use of complex obfuscation and evasion techniques, and often the availability of large resources for its development, makes him the biggest cyber villain in IoT scenarios today. The present work creates an Antivirus for Dynamic Malware Analysis based on Artificial Neural Networks, equipped with statistical learning and Artificial Intelligence, specialized in malware detection from 32-bit IoT architectures of the Advanced RISC Machine (ARM) type. Under different starting conditions and learning functions, our antivirus architectures are investigated to maximize their accuracy. The absence or limitation in the detection of malicious software by commercial antivirus can be provided by a smart antivirus. Instead of models based on blacklists or heuristics, our antivirus allows the detection of malware on embedded Linux systems in a preventive and non-reactive way like Clamav’s modus operandi and other traditional antiviruses.http://www.fsma.edu.br/si/edicao29/Download_FSMA_SI_2022_1_Principal_3.htmlantivirusmalwareiotarm elf filesdynamic runtime behaviorsartificial neural networkcomputer forensics
spellingShingle SILVA, S.H. M. T.
LIMA, S.M.L.
PINHEIRO, R.P.
LIMA, R. D. T.
ABREU, L. M. S.
FERNANDES, S. M. M.
Antivirus Applied to IoT Malware Detection based on Runtime Behaviors
Sistemas de Informação
antivirus
malware
iot
arm elf files
dynamic runtime behaviors
artificial neural network
computer forensics
title Antivirus Applied to IoT Malware Detection based on Runtime Behaviors
title_full Antivirus Applied to IoT Malware Detection based on Runtime Behaviors
title_fullStr Antivirus Applied to IoT Malware Detection based on Runtime Behaviors
title_full_unstemmed Antivirus Applied to IoT Malware Detection based on Runtime Behaviors
title_short Antivirus Applied to IoT Malware Detection based on Runtime Behaviors
title_sort antivirus applied to iot malware detection based on runtime behaviors
topic antivirus
malware
iot
arm elf files
dynamic runtime behaviors
artificial neural network
computer forensics
url http://www.fsma.edu.br/si/edicao29/Download_FSMA_SI_2022_1_Principal_3.html
work_keys_str_mv AT silvashmt antivirusappliedtoiotmalwaredetectionbasedonruntimebehaviors
AT limasml antivirusappliedtoiotmalwaredetectionbasedonruntimebehaviors
AT pinheirorp antivirusappliedtoiotmalwaredetectionbasedonruntimebehaviors
AT limardt antivirusappliedtoiotmalwaredetectionbasedonruntimebehaviors
AT abreulms antivirusappliedtoiotmalwaredetectionbasedonruntimebehaviors
AT fernandessmm antivirusappliedtoiotmalwaredetectionbasedonruntimebehaviors