Ransomware detection method based on context-aware entropy analysis

被引:38
|
作者
Jung, Sangmoon [1 ]
Won, Yoojae [1 ]
机构
[1] Chungnam Natl Univ, Dept Comp Sci Engn, Daejeon, South Korea
关键词
API hooking; Command and control server; Context-based analysis; Cryptography; Entropy; Kernel system; Ransomware; System security process;
D O I
10.1007/s00500-018-3257-z
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Numerous countermeasures have been proposed since the first appearance of ransomware. However, many ransomware mutants continue to be created, and the damage they cause has been continually increasing. Existing antivirus tools are signature-dependent and cannot easily detect ransomware attack patterns. If the database used by the antivirus program does not contain the signature of the new malicious behavior, it is not possible to detect the new malware. Thus, the need has emerged for a normal/abnormal behavior analysis technique via a context-aware method. Therefore, a multilateral context-aware-based ransomware detection and response system model is presented in this paper. The proposed model is designed to preemptively respond to ransomware, and post-detection management is performed. An evaluation was conducted to obtain evidence that the given files were altered by ransomware through analyses based on multiple-context awareness. Entropy information was then used to detect abnormal behavior.
引用
收藏
页码:6731 / 6740
页数:10
相关论文
共 50 条
  • [31] Context-aware HRV Analysis System
    Ji, Lianying
    Wu, Jiankang
    Yang, Yuanjing
    Wang, Shaofeng
    Li, Aiguang
    2011 6TH IEEE CONFERENCE ON INDUSTRIAL ELECTRONICS AND APPLICATIONS (ICIEA), 2011, : 1050 - 1055
  • [32] Context-Aware Sarcasm Detection Using BERT
    Baruah, Arup
    Das, Kaushik Amar
    Barbhuiya, Ferdous Ahmed
    Dey, Kuntal
    FIGURATIVE LANGUAGE PROCESSING, 2020, : 83 - 87
  • [33] Anomaly detection in Context-aware Feature Models
    Mauro, Jacopo
    PROCEEDINGS OF 15TH INTERNATIONAL WORKING CONFERENCE ON VARIABILITY MODELLING OF SOFTWARE-INTENSIVE SYSTEMS, VAMOS 2021, 2021,
  • [34] Context-Aware Anomaly Detection in Embedded Systems
    Ehsani-Besheli, Fatemeh
    Zarandi, Hamid R.
    ADVANCES IN DEPENDABILITY ENGINEERING OF COMPLEX SYSTEMS, 2018, 582 : 151 - 165
  • [35] Context-Aware Anomaly Detection in Attributed Networks
    Liu, Ming
    Liao, Jianxin
    Wang, Jingyu
    Qi, Qi
    Sun, Haifeng
    KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, PT III, 2021, 12817 : 14 - 26
  • [36] On the Context-Aware Anomaly Detection in Vehicular Networks
    Aljaafari, Mohammed Abdullatif H.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (12) : 832 - 840
  • [37] Context-Aware Hard and Slow Fall Detection
    Besrour, Sinda
    Mubibya, Gael S.
    Liu, Zikuan
    Almhana, Jalal
    20TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE, IWCMC 2024, 2024, : 321 - 326
  • [38] Context-Aware Online Commercial Intention Detection
    Hu, Derek Hao
    Shen, Dou
    Sun, Jian-Tao
    Yang, Qiang
    Chen, Zheng
    ADVANCES IN MACHINE LEARNING, PROCEEDINGS, 2009, 5828 : 135 - +
  • [39] Context-aware Pedestrian Detection Using LIDAR
    Oliveira, Luciano
    Nunes, Urbano
    2010 IEEE INTELLIGENT VEHICLES SYMPOSIUM (IV), 2010, : 773 - 778
  • [40] Context-Aware Transfer Attacks for Object Detection
    Cai, Zikui
    Xie, Xinxin
    Li, Shasha
    Yin, Mingjun
    Song, Chengyu
    Krishnamurthy, Srikanth V.
    Roy-Chowdhury, Amit K.
    Asif, M. Salman
    THIRTY-SIXTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE / THIRTY-FOURTH CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE / THE TWELVETH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2022, : 149 - 157