Ransomware detection method based on context-aware entropy analysis

被引:38
|
作者
Jung, Sangmoon [1 ]
Won, Yoojae [1 ]
机构
[1] Chungnam Natl Univ, Dept Comp Sci Engn, Daejeon, South Korea
关键词
API hooking; Command and control server; Context-based analysis; Cryptography; Entropy; Kernel system; Ransomware; System security process;
D O I
10.1007/s00500-018-3257-z
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Numerous countermeasures have been proposed since the first appearance of ransomware. However, many ransomware mutants continue to be created, and the damage they cause has been continually increasing. Existing antivirus tools are signature-dependent and cannot easily detect ransomware attack patterns. If the database used by the antivirus program does not contain the signature of the new malicious behavior, it is not possible to detect the new malware. Thus, the need has emerged for a normal/abnormal behavior analysis technique via a context-aware method. Therefore, a multilateral context-aware-based ransomware detection and response system model is presented in this paper. The proposed model is designed to preemptively respond to ransomware, and post-detection management is performed. An evaluation was conducted to obtain evidence that the given files were altered by ransomware through analyses based on multiple-context awareness. Entropy information was then used to detect abnormal behavior.
引用
收藏
页码:6731 / 6740
页数:10
相关论文
共 50 条
  • [1] Ransomware detection method based on context-aware entropy analysis
    Sangmoon Jung
    Yoojae Won
    Soft Computing, 2018, 22 : 6731 - 6740
  • [2] A Context-Aware Trigger Mechanism for Ransomware Forensics
    Singh, Avinash
    Ikuesan, Adeyemi
    Venter, Hein
    PROCEEDINGS OF THE 14TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2019), 2019, : 629 - 638
  • [3] Predictive Analysis of Ransomware Attacks using Context-aware AI in IoT Systems
    Mathane, Vytarani
    Lakshmi, P., V
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (04) : 240 - 244
  • [4] Context-Aware Saliency Detection
    Goferman, Stas
    Zelnik-Manor, Lihi
    Tal, Ayellet
    2010 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2010, : 2376 - 2383
  • [5] Context-Aware Drone Detection
    Oligeri, Gabriele
    Sciancalepore, Savio
    CPSS'22: PROCEEDINGS OF THE 8TH ACM CYBER-PHYSICAL SYSTEM SECURITY WORKSHOP, 2022, : 63 - 71
  • [6] Context-Aware Saliency Detection
    Goferman, Stas
    Zelnik-Manor, Lihi
    Tal, Ayellet
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2012, 34 (10) : 1915 - 1926
  • [7] Context -Aware Anomaly -based Detection for Ransomware using Multivariate Feature
    Pratiwi, Milla
    Choi, Yoon-Ho
    2024 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY, CNS 2024, 2024,
  • [8] Context-Aware Drift Detection
    Cobb, Oliver
    Van Looveren, Arnaud
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 162, 2022,
  • [9] Context-Aware Agents for People Detection and Stereoscopic Analysis
    Rodriguez, Sara
    De Paz, Juan F.
    Sanchez, Pablo
    Corchado, Juan M.
    TRENDS IN PRACTICAL APPLICATIONS OF AGENTS AND MULTIAGENT SYSTEMS, 2010, 71 : 173 - 181
  • [10] A Context-Aware Recommender Method Based on Text Mining
    Sundermann, Camila Vaccari
    de Padua, Renan
    Tonon, Vitor Rodrigues
    Domingues, Marcos Aurelio
    Rezende, Solange Oliveira
    PROGRESS IN ARTIFICIAL INTELLIGENCE, PT II, 2019, 11805 : 385 - 396