ReinforSec: an automatic generator of synthetic malware samples and denial-of-service attacks through reinforcement learning
In recent years, cybersecurity has been strengthened through the adoption of processes, mechanisms and rapid sources of indicators of compromise in critical areas. Among the most latent challenges are the detection, classification and eradication of malware and Denial of Service Cyber-Attacks (DoS)....
| Autores: | , , , , , , , , |
|---|---|
| Tipo de recurso: | artículo |
| Fecha de publicación: | 2023 |
| País: | España |
| Institución: | Universidad Complutense de Madrid (UCM) |
| Repositorio: | Docta Complutense |
| Idioma: | inglés |
| OAI Identifier: | oai:docta.ucm.es:20.500.14352/103659 |
| Acceso en línea: | https://hdl.handle.net/20.500.14352/103659 |
| Access Level: | acceso abierto |
| Palabra clave: | 004.8 004.056 Malware Denial of service Reinforcement learning Synthetic sampling Cybersecurity Machine learning Cybersecurity datasets Artificial intelligence Q learning Seguridad informática Inteligencia artificial (Informática) 1203.04 Inteligencia Artificial 1203.17 Informática |
| id |
ES_9bac93e5f3bc83dbce9e256bb9be5e60 |
|---|---|
| oai_identifier_str |
oai:docta.ucm.es:20.500.14352/103659 |
| network_acronym_str |
ES |
| network_name_str |
España |
| repository_id_str |
|
| spelling |
ReinforSec: an automatic generator of synthetic malware samples and denial-of-service attacks through reinforcement learningHernandez Suarez, AldoSanchez Perez, GabrielToscano Medina, Linda K.Perez Meana, HectorOlivares Mercado, JesusPortillo Portillo, JoseBenitez Garcia, GibranSandoval Orozco, Ana LucilaGarcía Villalba, Luis Javier004.8004.056MalwareDenial of serviceReinforcement learningSynthetic samplingCybersecurityMachine learningCybersecurity datasetsArtificial intelligenceQ learningSeguridad informáticaInteligencia artificial (Informática)1203.04 Inteligencia Artificial1203.17 InformáticaIn recent years, cybersecurity has been strengthened through the adoption of processes, mechanisms and rapid sources of indicators of compromise in critical areas. Among the most latent challenges are the detection, classification and eradication of malware and Denial of Service Cyber-Attacks (DoS). The literature has presented different ways to obtain and evaluate malware- and DoS-cyber-attack-related instances, either from a technical point of view or by offering ready-to-use datasets. However, acquiring fresh, up-to-date samples requires an arduous process of exploration, sandbox configuration and mass storage, which may ultimately result in an unbalanced or under-represented set. Synthetic sample generation has shown that the cost associated with setting up controlled environments and time spent on sample evaluation can be reduced. Nevertheless, the process is performed when the observations already belong to a characterized set, totally detached from a real environment. In order to solve the aforementioned, this work proposes a methodology for the generation of synthetic samples of malicious Portable Executable binaries and DoS cyber-attacks. The task is performed via a Reinforcement Learning engine, which learns from a baseline of different malware families and DoS cyber-attack network properties, resulting in new, mutated and highly functional samples. Experimental results demonstrate the high adaptability of the outputs as new input datasets for different Machine Learning algorithms.MDPIUniversidad Complutense de Madrid20232023-01-0120232023-01-01journal articlehttp://purl.org/coar/resource_type/c_6501VoRhttp://purl.org/coar/version/c_970fb48d4fbd8a85info:eu-repo/semantics/articleapplication/pdfhttps://hdl.handle.net/20.500.14352/103659reponame:Docta Complutenseinstname:Universidad Complutense de Madrid (UCM)InglésengEuropean Commission http://dx.doi.org/10.13039/501100000780 Horizon Europe Framework Programme 101070303open accesshttp://purl.org/coar/access_right/c_abf2Attribution 4.0 Internationalhttp://creativecommons.org/licenses/by/4.0/info:eu-repo/semantics/openAccessoai:docta.ucm.es:20.500.14352/1036592026-06-02T12:44:21Z |
| dc.title.none.fl_str_mv |
ReinforSec: an automatic generator of synthetic malware samples and denial-of-service attacks through reinforcement learning |
| title |
ReinforSec: an automatic generator of synthetic malware samples and denial-of-service attacks through reinforcement learning |
| spellingShingle |
ReinforSec: an automatic generator of synthetic malware samples and denial-of-service attacks through reinforcement learning Hernandez Suarez, Aldo 004.8 004.056 Malware Denial of service Reinforcement learning Synthetic sampling Cybersecurity Machine learning Cybersecurity datasets Artificial intelligence Q learning Seguridad informática Inteligencia artificial (Informática) 1203.04 Inteligencia Artificial 1203.17 Informática |
| title_short |
ReinforSec: an automatic generator of synthetic malware samples and denial-of-service attacks through reinforcement learning |
| title_full |
ReinforSec: an automatic generator of synthetic malware samples and denial-of-service attacks through reinforcement learning |
| title_fullStr |
ReinforSec: an automatic generator of synthetic malware samples and denial-of-service attacks through reinforcement learning |
| title_full_unstemmed |
ReinforSec: an automatic generator of synthetic malware samples and denial-of-service attacks through reinforcement learning |
| title_sort |
ReinforSec: an automatic generator of synthetic malware samples and denial-of-service attacks through reinforcement learning |
| dc.creator.none.fl_str_mv |
Hernandez Suarez, Aldo Sanchez Perez, Gabriel Toscano Medina, Linda K. Perez Meana, Hector Olivares Mercado, Jesus Portillo Portillo, Jose Benitez Garcia, Gibran Sandoval Orozco, Ana Lucila García Villalba, Luis Javier |
| author |
Hernandez Suarez, Aldo |
| author_facet |
Hernandez Suarez, Aldo Sanchez Perez, Gabriel Toscano Medina, Linda K. Perez Meana, Hector Olivares Mercado, Jesus Portillo Portillo, Jose Benitez Garcia, Gibran Sandoval Orozco, Ana Lucila García Villalba, Luis Javier |
| author_role |
author |
| author2 |
Sanchez Perez, Gabriel Toscano Medina, Linda K. Perez Meana, Hector Olivares Mercado, Jesus Portillo Portillo, Jose Benitez Garcia, Gibran Sandoval Orozco, Ana Lucila García Villalba, Luis Javier |
| author2_role |
author author author author author author author author |
| dc.contributor.none.fl_str_mv |
Universidad Complutense de Madrid |
| dc.subject.none.fl_str_mv |
004.8 004.056 Malware Denial of service Reinforcement learning Synthetic sampling Cybersecurity Machine learning Cybersecurity datasets Artificial intelligence Q learning Seguridad informática Inteligencia artificial (Informática) 1203.04 Inteligencia Artificial 1203.17 Informática |
| topic |
004.8 004.056 Malware Denial of service Reinforcement learning Synthetic sampling Cybersecurity Machine learning Cybersecurity datasets Artificial intelligence Q learning Seguridad informática Inteligencia artificial (Informática) 1203.04 Inteligencia Artificial 1203.17 Informática |
| description |
In recent years, cybersecurity has been strengthened through the adoption of processes, mechanisms and rapid sources of indicators of compromise in critical areas. Among the most latent challenges are the detection, classification and eradication of malware and Denial of Service Cyber-Attacks (DoS). The literature has presented different ways to obtain and evaluate malware- and DoS-cyber-attack-related instances, either from a technical point of view or by offering ready-to-use datasets. However, acquiring fresh, up-to-date samples requires an arduous process of exploration, sandbox configuration and mass storage, which may ultimately result in an unbalanced or under-represented set. Synthetic sample generation has shown that the cost associated with setting up controlled environments and time spent on sample evaluation can be reduced. Nevertheless, the process is performed when the observations already belong to a characterized set, totally detached from a real environment. In order to solve the aforementioned, this work proposes a methodology for the generation of synthetic samples of malicious Portable Executable binaries and DoS cyber-attacks. The task is performed via a Reinforcement Learning engine, which learns from a baseline of different malware families and DoS cyber-attack network properties, resulting in new, mutated and highly functional samples. Experimental results demonstrate the high adaptability of the outputs as new input datasets for different Machine Learning algorithms. |
| publishDate |
2023 |
| dc.date.none.fl_str_mv |
2023 2023-01-01 2023 2023-01-01 |
| dc.type.none.fl_str_mv |
journal article http://purl.org/coar/resource_type/c_6501 VoR http://purl.org/coar/version/c_970fb48d4fbd8a85 |
| dc.type.openaire.fl_str_mv |
info:eu-repo/semantics/article |
| format |
article |
| dc.identifier.none.fl_str_mv |
https://hdl.handle.net/20.500.14352/103659 |
| url |
https://hdl.handle.net/20.500.14352/103659 |
| dc.language.none.fl_str_mv |
Inglés eng |
| language_invalid_str_mv |
Inglés |
| language |
eng |
| dc.relation.none.fl_str_mv |
European Commission http://dx.doi.org/10.13039/501100000780 Horizon Europe Framework Programme 101070303 |
| dc.rights.none.fl_str_mv |
open access http://purl.org/coar/access_right/c_abf2 Attribution 4.0 International http://creativecommons.org/licenses/by/4.0/ |
| dc.rights.openaire.fl_str_mv |
info:eu-repo/semantics/openAccess |
| rights_invalid_str_mv |
open access http://purl.org/coar/access_right/c_abf2 Attribution 4.0 International http://creativecommons.org/licenses/by/4.0/ |
| eu_rights_str_mv |
openAccess |
| dc.format.none.fl_str_mv |
application/pdf |
| dc.publisher.none.fl_str_mv |
MDPI |
| publisher.none.fl_str_mv |
MDPI |
| dc.source.none.fl_str_mv |
reponame:Docta Complutense instname:Universidad Complutense de Madrid (UCM) |
| instname_str |
Universidad Complutense de Madrid (UCM) |
| reponame_str |
Docta Complutense |
| collection |
Docta Complutense |
| repository.name.fl_str_mv |
|
| repository.mail.fl_str_mv |
|
| _version_ |
1869414574634041344 |
| score |
15.301603 |