Adaptive Ransomware Detection Using Similarity-Preserving Hashing

被引:0
|
作者
Almajali, Anas [1 ,2 ]
Elmosalamy, Adham [2 ]
Safwat, Omar [2 ]
Abouelela, Hassan [2 ]
机构
[1] Hashemite Univ, Dept Comp Engn, Zarqa 13115, Jordan
[2] Amer Univ Sharjah, Dept Comp Sci & Engn, Sharjah, U Arab Emirates
来源
APPLIED SCIENCES-BASEL | 2024年 / 14卷 / 20期
关键词
ransomware; Blake3; adaptive-integrity mesh hashing; ransomware detection; malware;
D O I
10.3390/app14209548
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Crypto-ransomware is a type of ransomware that encrypts the victim's files and demands a ransom to return the files. This type of attack has been on the rise in recent years, as it offers a lucrative business model for threat actors. Research into developing solutions for detecting and halting the spread of ransomware is vast, and it uses different approaches. Some approaches rely on analyzing system calls made via processes to detect malicious behavior, while other methods focus on the affected files by creating a file integrity monitor to detect rapid and abnormal changes in file hashes. In this paper, we present a novel approach that utilizes hashing and can accommodate large files and dynamically take into account the amount of change within each file. Mainly, our approach relies on dividing each file into partitions and then performing selective hashing on those partitions to rapidly detect encrypted partitions due to ransomware. Our new approach addresses the main weakness of a previous implementation that relies on hashing files, not file partitions. This new implementation strikes a balance between the detection time and false positives based on the partition size and the threshold of partition changes before issuing an alert.
引用
收藏
页数:17
相关论文
共 50 条
  • [31] Shift-Equivariant Similarity-Preserving Hypervector Representations of Sequences
    Rachkovskij, Dmitri A.
    COGNITIVE COMPUTATION, 2024, 16 (03) : 909 - 923
  • [32] Scalable Similarity Search With Topology Preserving Hashing
    Zhang, Lei
    Zhang, Yongdong
    Gu, Xiaoguang
    Tang, Jinhui
    Tian, Qi
    IEEE TRANSACTIONS ON IMAGE PROCESSING, 2014, 23 (07) : 3025 - 3039
  • [33] Representation of spatial objects by shift-equivariant similarity-preserving hypervectors
    Rachkovskij, Dmitri A.
    NEURAL COMPUTING & APPLICATIONS, 2022, 34 (24): : 22387 - 22403
  • [34] Searching for Fine-Grained Queries in Radiology Reports Using Similarity-Preserving Contrastive Embedding
    Syeda-Mahmood, Tanveer
    Shi, Luyao
    MACHINE LEARNING FOR HEALTHCARE CONFERENCE, VOL 182, 2022, 182 : 785 - 799
  • [35] Ranking Preserving Hashing for Fast Similarity Search
    Wang, Qifan
    Zhang, Zhiwei
    Si, Luo
    PROCEEDINGS OF THE TWENTY-FOURTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE (IJCAI), 2015, : 3911 - 3917
  • [36] Accelerating Similarity-Based Model Matching Using On-The-Fly Similarity Preserving Hashing
    He, Xiao
    Tang, Letian
    Li, Yutong
    PROCEEDINGS OF THE 25TH INTERNATIONAL ACM/IEEE CONFERENCE ON MODEL DRIVEN ENGINEERING LANGUAGES AND SYSTEMS, MODELS 2022, 2022, : 244 - 254
  • [37] HistoSketch: Fast Similarity-Preserving Sketching of Streaming Histograms with Concept Drift
    Yang, Dingqi
    Li, Bin
    Rettig, Laura
    Cudre-Mauroux, Philippe
    2017 17TH IEEE INTERNATIONAL CONFERENCE ON DATA MINING (ICDM), 2017, : 545 - 554
  • [38] Lightweight Depth Completion Network with Local Similarity-Preserving Knowledge Distillation
    Jeong, Yongseop
    Park, Jinsun
    Cho, Donghyeon
    Hwang, Yoonjin
    Choi, Seibum B.
    Kweon, In So
    SENSORS, 2022, 22 (19)
  • [39] Learning Similarity-Preserving Representations of Brain Structure-Function Coupling
    Li, Yang
    Mateos, Gonzalo
    2022 30TH EUROPEAN SIGNAL PROCESSING CONFERENCE (EUSIPCO 2022), 2022, : 922 - 926
  • [40] SPSD: Similarity-preserving self-distillation for video–text retrieval
    Jiachen Wang
    Yan Hua
    Yingyun Yang
    Hongwei Kou
    International Journal of Multimedia Information Retrieval, 2023, 12