Ransomware detection method based on context-aware entropy analysis

被引:38
|
作者
Jung, Sangmoon [1 ]
Won, Yoojae [1 ]
机构
[1] Chungnam Natl Univ, Dept Comp Sci Engn, Daejeon, South Korea
关键词
API hooking; Command and control server; Context-based analysis; Cryptography; Entropy; Kernel system; Ransomware; System security process;
D O I
10.1007/s00500-018-3257-z
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Numerous countermeasures have been proposed since the first appearance of ransomware. However, many ransomware mutants continue to be created, and the damage they cause has been continually increasing. Existing antivirus tools are signature-dependent and cannot easily detect ransomware attack patterns. If the database used by the antivirus program does not contain the signature of the new malicious behavior, it is not possible to detect the new malware. Thus, the need has emerged for a normal/abnormal behavior analysis technique via a context-aware method. Therefore, a multilateral context-aware-based ransomware detection and response system model is presented in this paper. The proposed model is designed to preemptively respond to ransomware, and post-detection management is performed. An evaluation was conducted to obtain evidence that the given files were altered by ransomware through analyses based on multiple-context awareness. Entropy information was then used to detect abnormal behavior.
引用
收藏
页码:6731 / 6740
页数:10
相关论文
共 50 条
  • [21] Context-aware and Personalization Method based on Ubiquitous Learning Analytics
    Mouri, Kousuke
    Ogata, Hiroaki
    Uosaki, Noriko
    Lkhagvasuren, Erdenesaikhan
    JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2016, 22 (10) : 1380 - 1397
  • [22] A Context-aware Map Matching Method Based on Supported Degree
    Liu, Congcong
    Chen, Hengxin
    Gao, Mingqi
    2019 IEEE SMARTWORLD, UBIQUITOUS INTELLIGENCE & COMPUTING, ADVANCED & TRUSTED COMPUTING, SCALABLE COMPUTING & COMMUNICATIONS, CLOUD & BIG DATA COMPUTING, INTERNET OF PEOPLE AND SMART CITY INNOVATION (SMARTWORLD/SCALCOM/UIC/ATC/CBDCOM/IOP/SCI 2019), 2019, : 530 - 535
  • [23] A context-aware recommender method based on text and opinion mining
    Sundermann, Camila Vaccari
    de Padua, Renan
    Tonon, Vitor Rodrigues
    Marcacini, Ricardo Marcondes
    Domingues, Marcos Aurelio
    Rezende, Solange Oliveira
    EXPERT SYSTEMS, 2020, 37 (06)
  • [24] Context-aware emergency detection method for edge computing-based healthcare monitoring system
    Wang, Lei
    Xu, Boyi
    Cai, Hongming
    Zhang, Pengzhu
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2022, 33 (06)
  • [25] The Inadequacy of Entropy-Based Ransomware Detection
    McIntosh, Timothy
    Jang-Jaccard, Julian
    Watters, Paul
    Susnjak, Teo
    NEURAL INFORMATION PROCESSING, ICONIP 2019, PT V, 2019, 1143 : 181 - 189
  • [26] Toward Context-aware Sentiment Analysis
    Cheng, Otto
    Lau, Raymond
    4TH INTERNATIONAL CONFERENCE ON MATERIALS ENGINEERING FOR ADVANCED TECHNOLOGIES (ICMEAT 2015), 2015, : 713 - 716
  • [27] Gesture Saliency: A Context-Aware Analysis
    Mancas, Matei
    Glowinski, Donald
    Volpe, Gualtiero
    Coletta, Paolo
    Camurri, Antonio
    GESTURE IN EMBODIED COMMUNICATION AND HUMAN-COMPUTER INTERACTION, 2010, 5934 : 146 - +
  • [28] On wandering detection methods in context-aware scenarios
    Batista, Edgar
    Casino, Fran
    Solanas, Agusti
    2016 7TH INTERNATIONAL CONFERENCE ON INFORMATION, INTELLIGENCE, SYSTEMS & APPLICATIONS (IISA), 2016,
  • [29] Context-aware CNNs for person head detection
    Tuan-Hung Vu
    Osokin, Anton
    Laptev, Ivan
    2015 IEEE INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV), 2015, : 2893 - 2901
  • [30] Scene Context-Aware Salient Object Detection
    Siris, Avishek
    Jiao, Jianbo
    Tam, Gary K. L.
    Xie, Xianghua
    Lau, Rynson W. H.
    2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 4136 - 4146