MITRE ATLAS
mitre-atlas-cs0000
Evasion of Deep Learning Detector for Malware C&C Traffic
- Predictive ML & Computer Vision
- Model Evasion & Bypass
The Palo Alto Networks Security AI research team tested a deep learning model for malware command and control (C&C) traffic detection in HTTP traffic. Based on the publicly available paper by Le et al. (https://arxiv.org/abs/1802.03162), we built a model that was trained on a similar dataset as our production model and had similar performance. Then we crafted adversarial samples, queried the model, and adjusted the adversarial sample accordingly until the model was evaded.