Early Detection of Ransomware Activity based on Hardware Performance Counters

被引:10
|
作者
Anand, P. Mohan [1 ]
Charan, P. V. Sai [1 ]
Shukla, Sandeep K. [1 ]
机构
[1] Indian Inst Technol, Dept Comp Sci & Engn, Kanpur, India
关键词
Hardware Performance Counters; Ransomware; Early Detection; Wiper; Dynamic Malware Analysis;
D O I
10.1145/3579375.3579377
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Modern-day ransomware variants are quick in their operations and start to encrypt the files within a few seconds after the initial payload execution. This poses an exigency towards early detection of ransomware payloads. Although there are multiple methods of ransomware detection based on API calls, file entropy, memory forensics, and network indicators - fast and early detection is hard to achieve through these methods. Hardware performance counters (HPC) are special-purpose registers built into current microprocessors that allow for low-level system performance analysis. Although HPC counters provide significant information for identifying ransomware behavior at the hardware level, the difficulty lies in deciding the optimal HPC features required for early detection and the time granularity at which these features are to be collected. In this work, we address this research gap by examining the HPC counters statistics gathered for every 100ms, 500ms, and five seconds to recommend the most effective time frame and the appropriate HPC registers for early detection of ransomware. According to our findings, capturing only 5 HPC registers per 100ms until 3 seconds of payload execution delivers the best results with the AdaBoost classifier, with an accuracy above 90%. Furthermore, we validate our model against recent wiper malware variants (used against organizations in Ukraine). We highlight behavioral patterns of ransomware and wiper malware based on HPC statistics and the challenges in identifying wiper payload behavior using an HPC-based approach.
引用
收藏
页码:10 / 17
页数:8
相关论文
共 50 条
  • [21] Metis: a profiling toolkit based on the virtualization of hardware performance counters
    Xie, Xia
    Jiang, Haiou
    Jin, Hai
    Cao, Wenzhi
    Yuan, Pingpeng
    Yang, Laurence Tianruo
    HUMAN-CENTRIC COMPUTING AND INFORMATION SCIENCES, 2012, 2
  • [22] DeepWare: Imaging Performance Counters With Deep Learning to Detect Ransomware
    Ganfure, Gaddisa Olani
    Wu, Chun-Feng
    Chang, Yuan-Hao
    Shih, Wei-Kuan
    IEEE TRANSACTIONS ON COMPUTERS, 2023, 72 (03) : 600 - 613
  • [23] Ransomware early detection: A survey
    Cen, Mingcan
    Jiang, Frank
    Qin, Xingsheng
    Jiang, Qinghong
    Doss, Robin
    COMPUTER NETWORKS, 2024, 239
  • [24] Can Hardware Performance Counters be Trusted?
    Weaver, Vincent M.
    Mckee, Sally A.
    2008 IEEE INTERNATIONAL SYMPOSIUM ON WORKLOAD CHARACTERIZATION, 2008, : 131 - 140
  • [25] Software-based Control-Flow Error Detection with Hardware Performance Counters in ARM Processors
    Ahmad, Hussien Al-Haj
    Sedaghat, Yasser
    2022 CPSSI 4TH INTERNATIONAL SYMPOSIUM ON REAL-TIME AND EMBEDDED SYSTEMS AND TECHNOLOGIES (RTEST 2022), 2022,
  • [26] Demand-Driven Software Race Detection using Hardware Performance Counters
    Greathouse, Joseph L.
    Ma, Zhiqiang
    Frank, Matthew I.
    Peri, Ramesh
    Austin, Todd
    ISCA 2011: PROCEEDINGS OF THE 38TH ANNUAL INTERNATIONAL SYMPOSIUM ON COMPUTER ARCHITECTURE, 2011, : 165 - 176
  • [27] Fight Hardware with Hardware: Systemwide Detection and Mitigation of Side-channel Attacks Using Performance Counters
    Carna, Stefano
    Ferracci, Serena
    Quaglia, Francesco
    Pellegrini, Alessandro
    DIGITAL THREATS: RESEARCH AND PRACTICE, 2023, 4 (01):
  • [28] Ransomware Early Detection Method Based on API Latent Semantics
    Luo B.
    Guo C.
    Shen G.-W.
    Cui Y.-H.
    Chen Y.
    Ping Y.
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2024, 52 (04): : 1288 - 1295
  • [29] Ransomware Early Detection Method Based on Short API Sequence
    Chen, Chang-Qing
    Cuo, Chun
    Cui, Yun-He
    Shen, Guo-Wei
    Jiang, Chao-Hui
    Tien Tzu Hsueh Pao/Acta Electronica Sinica, 2021, 49 (03): : 586 - 595
  • [30] Real time detection of cache-based side-channel attacks using hardware performance counters
    Chiappetta, Marco
    Savas, Erkay
    Yilmaz, Cemal
    APPLIED SOFT COMPUTING, 2016, 49 : 1162 - 1174