A Case-Control Study to Measure Behavioral Risks of Malware Encounters in Organizations

被引:0
|
作者
Meschini, Marcello [1 ]
Di Tizio, Giorgio [1 ]
Balduzzi, Marco [2 ]
Massacci, Fabio [1 ,3 ]
机构
[1] Univ Trento, I-38122 Trento, Italy
[2] TRL, Trend Micro, I-20099 Sesto San Giovanni, Italy
[3] Vrije Univ Amsterdam, NL-1081HV Amsterdam, Netherlands
关键词
Malware; Organizations; Ransomware; Market research; Cancer; Web sites; Standards organizations; case-control study; risk factors;
D O I
10.1109/TIFS.2024.3456960
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The behavior of enterprise users (e.g. browsing at night or visiting gambling sites) is a potential factor that might increase the chances of malware encounters (e.g. coinminers vs ransomware) on the field. We report a case-control study on telemetry data collected by Trend Micro, a global cybersecurity vendor, to identify users' behavioral characteristics that can be used to differentiate cybersecurity risks profiles. Our results show that different types of 'patients zero' are vulnerable to different types of epidemics. The odds ratio of encountering malware such as PUAs, trojans, and hacktools is higher for a variety of network and system behavior (e.g. number, types, and diversity of visited web sites, visit of gambling sites, etc.) but it is not significant for other factors such as browsing at night. Other type of malware such as coinminers have an increase in the odds ratio only for few type of factors (e.g. gambling web sites). We also present a specific methodology tailored for investigating self-propagating malware such as ransomware in which one is infected by one's neighbor. With this approach, we observed a more accurate characterization of the odds of encountering ransomware based on system-based behaviors than with a standard case-control study setup. Experiments with different vendors may be needed to generalize the results and offset potential bias due to differences in market share.
引用
收藏
页码:9419 / 9432
页数:14
相关论文
共 50 条
  • [31] Risks factors for endometriosis in the rhesus monkey (Macaca mulatta): A case-control study
    Hadfield, RM
    Yudkin, PL
    Coe, CL
    Scheffer, J
    Uno, H
    Barlow, DH
    Kemnitz, JW
    Kennedy, SH
    HUMAN REPRODUCTION UPDATE, 1997, 3 (02) : 109 - 115
  • [32] CASE-CONTROL STUDY
    不详
    BMJ-BRITISH MEDICAL JOURNAL, 1979, 2 (6195): : 884 - 885
  • [33] CASE-CONTROL STUDY
    SJOBERG, A
    EUROPEAN JOURNAL OF RESPIRATORY DISEASES, 1980, 61 : 105 - 108
  • [34] A CASE-CONTROL STUDY
    ALVAREZDARDET, C
    PIERA, MC
    COLOMER, C
    MEDICINA CLINICA, 1988, 90 (02): : 89 - 89
  • [35] Automated Behavioral Analysis of Malware A Case Study of WannaCry Ransomware
    Chen, Qian
    Bridges, Robert A.
    2017 16TH IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLICATIONS (ICMLA), 2017, : 454 - 460
  • [36] Estimating risks for matching factors in case-control studies
    Siskind, V
    Kelly, JP
    Kaufman, DW
    JOURNAL OF CLINICAL EPIDEMIOLOGY, 2000, 53 (03) : 251 - 256
  • [37] Sleep disorders and behavioral disorders in Jamaican children with epilepsy: A case-control study
    Graham, Leohrandra
    Gossell-Williams, Maxine
    Tapper, Judy
    Melbourne-Chambers, Roxanne
    EPILEPSY & BEHAVIOR, 2019, 99
  • [38] Constitutional and Behavioral Risk Factors for Chilblains: A Case-Control Study From Pakistan
    Raza, Naeem
    Habib, Aamir
    Razvi, Syed Kamran Amir
    Dar, Nasser Rashid
    WILDERNESS & ENVIRONMENTAL MEDICINE, 2010, 21 (01) : 17 - 21
  • [39] Nutritional and behavioral determinants of adolescent obesity: a case-control study in Sri Lanka
    Rathnayake, Kumari M.
    Roopasingam, Tharrmini
    Wickramasighe, V. P.
    BMC PUBLIC HEALTH, 2014, 14
  • [40] Psycho-behavioral predictors of uncontrolled blood pressure: A case-control study
    Javadivala, Zeinab
    Ranjbarkhah, Akbar
    Mohammadpoorasl, Asghar
    Shekari, Farhad
    Bhalla, Devender
    Gilani, Neda
    HEALTH PROMOTION PERSPECTIVES, 2022, 12 (02): : 218 - 225