Show simple item record

dc.contributor.authorKhodaei, Elaheh
dc.date.accessioned2024-04-24 20:15:13 (GMT)
dc.date.available2024-04-24 20:15:13 (GMT)
dc.date.issued2024-04-24
dc.date.submitted2024-04-23
dc.identifier.urihttp://hdl.handle.net/10012/20491
dc.description.abstractMicroarchitectural events have been the subject of previous investigations for malware detection. While some studies assert the effectiveness of utilizing hardware events in detecting malware, others contend that they may not be beneficial for this purpose. We argue and empirically show that the efficacy of using hardware events for malware detection relies on accurately selecting hardware events during detector training. Through rigorous analysis, we demonstrate that the conventional approach of selecting a single subset of hardware events for training a malware detection model is insufficient for creating a robust system capable of effectively handling all types of malware, even when using a ensemble of powerful classifiers. Accordingly, we propose the use of multiple subsets of hardware events, each dedicated to training a distinct malware detection model. Since only a single subset of events can be monitored at any given time, we adopt a game-theoretic approach to determine the optimal strategy for selecting the subset of hardware events to be monitored. In addition to the theoretical analysis of our approach, we empirically demonstrate its effectiveness by comparing it to other baselines.en
dc.language.isoenen
dc.publisherUniversity of Waterlooen
dc.subjectMalware Detectionen
dc.subjectGame Theoryen
dc.subjectMicroarchitectural Eventsen
dc.subjectHardware Performance Countersen
dc.titleSalus: Stackelberg Games for Malware Detection with Microarchitectural Eventsen
dc.typeMaster Thesisen
dc.pendingfalse
uws-etd.degree.departmentElectrical and Computer Engineeringen
uws-etd.degree.disciplineElectrical and Computer Engineeringen
uws-etd.degree.grantorUniversity of Waterlooen
uws-etd.degreeMaster of Applied Scienceen
uws-etd.embargo.terms0en
uws.contributor.advisorZahedi, Majid
uws.contributor.affiliation1Faculty of Engineeringen
uws.published.cityWaterlooen
uws.published.countryCanadaen
uws.published.provinceOntarioen
uws.typeOfResourceTexten
uws.peerReviewStatusUnrevieweden
uws.scholarLevelGraduateen


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record


UWSpace

University of Waterloo Library
200 University Avenue West
Waterloo, Ontario, Canada N2L 3G1
519 888 4883

All items in UWSpace are protected by copyright, with all rights reserved.

DSpace software

Service outages