English

The Shape of Alerts: Detecting Malware Using Distributed Detectors by Robustly Amplifying Transient Correlations

Cryptography and Security 2018-03-05 v1

Abstract

We introduce a new malware detector - Shape-GD - that aggregates per-machine detectors into a robust global detector. Shape-GD is based on two insights: 1. Structural: actions such as visiting a website (waterhole attack) by nodes correlate well with malware spread, and create dynamic neighborhoods of nodes that were exposed to the same attack vector. However, neighborhood sizes vary unpredictably and require aggregating an unpredictable number of local detectors' outputs into a global alert. 2. Statistical: feature vectors corresponding to true and false positives of local detectors have markedly different conditional distributions - i.e. their shapes differ. The shape of neighborhoods can identify infected neighborhoods without having to estimate neighborhood sizes - on 5 years of Symantec detectors' logs, Shape-GD reduces false positives from ~1M down to ~110K and raises alerts 345 days (on average) before commercial anti-virus products; in a waterhole attack simulated using Yahoo web-service logs, Shape-GD detects infected machines when only ~100 of ~550K are compromised.

Keywords

Cite

@article{arxiv.1803.00883,
  title  = {The Shape of Alerts: Detecting Malware Using Distributed Detectors by Robustly Amplifying Transient Correlations},
  author = {Mikhail Kazdagli and Constantine Caramanis and Sanjay Shakkottai and Mohit Tiwari},
  journal= {arXiv preprint arXiv:1803.00883},
  year   = {2018}
}

Comments

arXiv admin note: substantial text overlap with arXiv:1708.01864

R2 v1 2026-06-23T00:39:31.724Z