Skip to main navigation Skip to search Skip to main content

Graphite: Real-Time Graph-Based Detection of Windows Fileless Malware Attacks

  • State University of New York Binghamton University
  • IBM
  • Stony Brook University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Scopus citations

Abstract

Advanced malware attacks often employ sophisticated tactics such as DLL injection, script-based attacks, and the exploitation of zero-day vulnerabilities. As evidenced by the recent high-profile cyberattacks, these techniques have enabled attackers to infiltrate computer systems that were thought to be well-protected. There is thus an urgent need to enhance current malware defenses with advanced Artificial Intelligence (AI) techniques that can effectively detect in real-time the elusive traces of malware attacks concealed within the extensive realm of normal activities. This paper introduces Graphite, a graph-based approach for real-time detection of advanced malware attacks based on the event data collected from Event Tracing for Windows (ETW). Graphite first abstracts various entities and their relationships embodied within system events into computation graphs, which are amenable to graph-based machine learning methods. As a computation graph can be gigantic, making real-time malware detection inefficient, we project the graph into smaller graphlets, which are then subsequently fed into our graph-based approach to detect malicious activities. Our experimental results show that Graphite achieves classification accuracy in offline testing and accuracy in real-time detection.

Original languageEnglish
Title of host publicationSecurity and Privacy in Communication Networks - 20th EAI International Conference, SecureComm 2024, Proceedings
EditorsSaed Alrabaee, Kim-Kwang Raymond Choo, Ernesto Damiani, Robert H. Deng
PublisherSpringer Science and Business Media Deutschland GmbH
Pages154-178
Number of pages25
ISBN (Print)9783031944543
DOIs
StatePublished - 2026
Event20th EAI International Conference on Security and Privacy in Communication Networks, SecureComm 2024 - Dubai, United Arab Emirates
Duration: Oct 28 2024Oct 30 2024

Publication series

NameLecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST
Volume629 LNICST

Conference

Conference20th EAI International Conference on Security and Privacy in Communication Networks, SecureComm 2024
Country/TerritoryUnited Arab Emirates
CityDubai
Period10/28/2410/30/24

Keywords

  • Machine learning
  • Malware detection

Fingerprint

Dive into the research topics of 'Graphite: Real-Time Graph-Based Detection of Windows Fileless Malware Attacks'. Together they form a unique fingerprint.

Cite this