A Survey of Stealth Malware: Attacks, Mitigation Measures, and Steps Toward Autonomous Open World Solutions
As our professional, social, and financial existences become increasingly\ndigitized and as our government, healthcare, and military infrastructures rely\nmore on computer technologies, they present larger and more lucrative targets\nfor malware. Stealth malware in particular poses an increased threat because it\nis specifically designed to evade detection mechanisms, spreading dormant, in\nthe wild for extended periods of time, gathering sensitive information or\npositioning itself for a high-impact zero-day attack. Policing the growing\nattack surface requires the development of efficient anti-malware solutions\nwith improved generalization to detect novel types of malware and resolve these\noccurrences with as little burden on human experts as possible. In this paper,\nwe survey malicious stealth technologies as well as existing solutions for\ndetecting and categorizing these countermeasures autonomously. While machine\nlearning offers promising potential for increasingly autonomous solutions with\nimproved generalization to new malware types, both at the network level and at\nthe host level, our findings suggest that several flawed assumptions inherent\nto most recognition algorithms prevent a direct mapping between the stealth\nmalware recognition problem and a machine learning solution. The most notable\nof these flawed assumptions is the closed world assumption: that no sample\nbelonging to a class outside of a static training set will appear at query\ntime. We present a formalized adaptive open world framework for stealth malware\nrecognition and relate it mathematically to research from other machine\nlearning domains.\n