Early Detection of Ransomware Activity based on Hardware Performance Counters

被引:10
|
作者
Anand, P. Mohan [1 ]
Charan, P. V. Sai [1 ]
Shukla, Sandeep K. [1 ]
机构
[1] Indian Inst Technol, Dept Comp Sci & Engn, Kanpur, India
关键词
Hardware Performance Counters; Ransomware; Early Detection; Wiper; Dynamic Malware Analysis;
D O I
10.1145/3579375.3579377
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Modern-day ransomware variants are quick in their operations and start to encrypt the files within a few seconds after the initial payload execution. This poses an exigency towards early detection of ransomware payloads. Although there are multiple methods of ransomware detection based on API calls, file entropy, memory forensics, and network indicators - fast and early detection is hard to achieve through these methods. Hardware performance counters (HPC) are special-purpose registers built into current microprocessors that allow for low-level system performance analysis. Although HPC counters provide significant information for identifying ransomware behavior at the hardware level, the difficulty lies in deciding the optimal HPC features required for early detection and the time granularity at which these features are to be collected. In this work, we address this research gap by examining the HPC counters statistics gathered for every 100ms, 500ms, and five seconds to recommend the most effective time frame and the appropriate HPC registers for early detection of ransomware. According to our findings, capturing only 5 HPC registers per 100ms until 3 seconds of payload execution delivers the best results with the AdaBoost classifier, with an accuracy above 90%. Furthermore, we validate our model against recent wiper malware variants (used against organizations in Ukraine). We highlight behavioral patterns of ransomware and wiper malware based on HPC statistics and the challenges in identifying wiper payload behavior using an HPC-based approach.
引用
收藏
页码:10 / 17
页数:8
相关论文
共 50 条
  • [1] HiPeR - Early Detection of a Ransomware Attack using Hardware Performance Counters
    Anand, P. Mohan
    Charan, P. V. Sai
    Shukla, Sandeep K.
    DIGITAL THREATS: RESEARCH AND PRACTICE, 2023, 4 (03):
  • [2] Ransomware Classification Using Hardware Performance Counters on a Non-Virtualized System
    Hill, Jennie E.
    Walker, T. Owens
    Blanco, Justin A.
    Ives, Robert W.
    Rakvic, Ryan
    Jacob, Bruce
    IEEE ACCESS, 2024, 12 : 63865 - 63884
  • [3] Malicious Firmware Detection with Hardware Performance Counters
    Wang, Xueyang
    Konstantinou, Charalambos
    Maniatakos, Michail
    Karri, Ramesh
    Lee, Serena
    Robison, Patricia
    Stergiou, Paul
    Kim, Steve
    IEEE TRANSACTIONS ON MULTI-SCALE COMPUTING SYSTEMS, 2016, 2 (03): : 160 - 173
  • [4] Intelligent Malware Detection based on Hardware Performance Counters: A Comprehensive Survey
    Sayadi, Hossein
    He, Zhangying
    Makrani, Hosein Mohammadi
    Homayoun, Houman
    2024 25TH INTERNATIONAL SYMPOSIUM ON QUALITY ELECTRONIC DESIGN, ISQED 2024, 2024,
  • [5] A Theoretical Study of Hardware Performance Counters-Based Malware Detection
    Basu, Kanad
    Krishnamurthy, Prashanth
    Khorrami, Farshad
    Karri, Ramesh
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 : 512 - 525
  • [6] Hardware Performance Counters based Runtime Anomaly Detection using SVM
    Bin Abbas, Muhamed Fauzi
    Kadiyala, Sai Praveen
    Prakash, Alok
    Srikanthan, Thambipillai
    Aung, Yan Lin
    2017 TRON SYMPOSIUM (TRONSHOW), 2017,
  • [7] On the Performance of Malware Detection Classifiers Using Hardware Performance Counters
    Zeraatkar, Alireza Abolhasani
    Kamran, Parnian Shabani
    Kaur, Inderpreet
    Ramu, Nagabindu
    Sheaves, Tyler
    Al-Asaad, Hussain
    2024 INTERNATIONAL CONFERENCE ON SMART APPLICATIONS, COMMUNICATIONS AND NETWORKING, SMARTNETS-2024, 2024,
  • [8] Early Detection of System-Level Anomalous Behaviour using Hardware Performance Counters
    Woo, Lai Leng
    Zwolinski, Mark
    Halak, Basel
    PROCEEDINGS OF THE 2018 DESIGN, AUTOMATION & TEST IN EUROPE CONFERENCE & EXHIBITION (DATE), 2018, : 485 - 490
  • [9] Hardware Performance Counters for Embedded Software Anomaly Detection
    Ott, Karl
    Mahapatra, Rabi
    2018 16TH IEEE INT CONF ON DEPENDABLE, AUTONOM AND SECURE COMP, 16TH IEEE INT CONF ON PERVAS INTELLIGENCE AND COMP, 4TH IEEE INT CONF ON BIG DATA INTELLIGENCE AND COMP, 3RD IEEE CYBER SCI AND TECHNOL CONGRESS (DASC/PICOM/DATACOM/CYBERSCITECH), 2018, : 528 - 535
  • [10] Time Series-based Malware Detection using Hardware Performance Counters
    Kuruvila, Abraham Peedikayil
    Karmakar, Sayar
    Basu, Kanad
    2021 IEEE INTERNATIONAL SYMPOSIUM ON HARDWARE ORIENTED SECURITY AND TRUST (HOST), 2021, : 102 - 112