Adaptive Ransomware Detection Using Similarity-Preserving Hashing

被引:0
|
作者
Almajali, Anas [1 ,2 ]
Elmosalamy, Adham [2 ]
Safwat, Omar [2 ]
Abouelela, Hassan [2 ]
机构
[1] Hashemite Univ, Dept Comp Engn, Zarqa 13115, Jordan
[2] Amer Univ Sharjah, Dept Comp Sci & Engn, Sharjah, U Arab Emirates
来源
APPLIED SCIENCES-BASEL | 2024年 / 14卷 / 20期
关键词
ransomware; Blake3; adaptive-integrity mesh hashing; ransomware detection; malware;
D O I
10.3390/app14209548
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Crypto-ransomware is a type of ransomware that encrypts the victim's files and demands a ransom to return the files. This type of attack has been on the rise in recent years, as it offers a lucrative business model for threat actors. Research into developing solutions for detecting and halting the spread of ransomware is vast, and it uses different approaches. Some approaches rely on analyzing system calls made via processes to detect malicious behavior, while other methods focus on the affected files by creating a file integrity monitor to detect rapid and abnormal changes in file hashes. In this paper, we present a novel approach that utilizes hashing and can accommodate large files and dynamically take into account the amount of change within each file. Mainly, our approach relies on dividing each file into partitions and then performing selective hashing on those partitions to rapidly detect encrypted partitions due to ransomware. Our new approach addresses the main weakness of a previous implementation that relies on hashing files, not file partitions. This new implementation strikes a balance between the detection time and false positives based on the partition size and the threshold of partition changes before issuing an alert.
引用
收藏
页数:17
相关论文
共 50 条
  • [41] Representation of spatial objects by shift-equivariant similarity-preserving hypervectors
    Dmitri A. Rachkovskij
    Neural Computing and Applications, 2022, 34 : 22387 - 22403
  • [42] A Local Similarity-Preserving Framework for Nonlinear Dimensionality Reduction with Neural Networks
    Wang, Xiang
    Li, Xiaoyong
    Zhu, Junxing
    Xu, Zichen
    Ren, Kaijun
    Zhang, Weiming
    Liu, Xinwang
    Yu, Kui
    DATABASE SYSTEMS FOR ADVANCED APPLICATIONS (DASFAA 2021), PT II, 2021, 12682 : 376 - 391
  • [43] Supervised Adaptive Similarity Matrix Hashing
    Shi, Yang
    Nie, Xiushan
    Liu, Xingbo
    Zou, Li
    Yin, Yilong
    IEEE TRANSACTIONS ON IMAGE PROCESSING, 2022, 31 : 2755 - 2766
  • [44] Adaptive Hashing for Fast Similarity Search
    Cakir, Fatih
    Sclaroff, Stan
    2015 IEEE INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV), 2015, : 1044 - 1052
  • [45] Neutralization Method of Ransomware Detection Technology Using Format Preserving Encryption
    Lee, Jaehyuk
    Lee, Sun-Young
    Yim, Kangbin
    Lee, Kyungroul
    SENSORS, 2023, 23 (10)
  • [46] Micro-expression Action Unit Detection with Dual-view Attentive Similarity-Preserving Knowledge Distillation
    Li, Yante
    Peng, Wei
    Zhao, Guoying
    2021 16TH IEEE INTERNATIONAL CONFERENCE ON AUTOMATIC FACE AND GESTURE RECOGNITION (FG 2021), 2021,
  • [47] Android Ransomware Detection Using Reduced Opcode Sequence And Image Similarity
    Karimi, Alireza
    Moattar, Mohammad Hosein
    PROCEEDINGS OF THE 2017 7TH INTERNATIONAL CONFERENCE ON COMPUTER AND KNOWLEDGE ENGINEERING (ICCKE), 2017, : 229 - 234
  • [48] A Ransomware Detection Method Using Fuzzy Hashing for Mitigating the Risk of Occlusion of Information Systems
    Naik, Nitin
    Jenkins, Paul
    Savage, Nick
    2019 5TH IEEE INTERNATIONAL SYMPOSIUM ON SYSTEMS ENGINEERING (IEEE ISSE 2019), 2019,
  • [49] A Similarity-preserving Neural Network Trained on Transformed Images Recapitulates Salient Features of the Fly Motion Detection Circuit
    Bahroun, Yanis
    Sengupta, Anirvan M.
    Chklovskii, Dmitri B.
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 32 (NIPS 2019), 2019, 32
  • [50] Deep Top Similarity Preserving Hashing for Image Retrieval
    Li, Qiang
    Fu, Haiyan
    Kong, Xiangwei
    IMAGE AND GRAPHICS (ICIG 2017), PT II, 2017, 10667 : 206 - 215