Corpus ID: 54484775

Deep Program Reidentification: A Graph Neural Network Solution

  title={Deep Program Reidentification: A Graph Neural Network Solution},
  author={Shen Wang and Zhengzhang Chen and Ding Li and Lu An Tang and Jingchao Ni and Zhichun Li and Junghwan John Rhee and Haifeng Chen and Philip S. Yu},
Program or process is an integral part of almost every IT/OT system. Can we trust the identity/ID (e.g., executable name) of the program? To avoid detection, malware may disguise itself using the ID of a legitimate program, and a system tool (e.g., PowerShell) used by the attackers may have the fake ID of another common software, which is less sensitive. However, existing intrusion detection techniques often overlook this critical program reidentification problem (i.e., checking the program's… 

Figures and Tables from this paper


