A New Scheme for Ransomware Classification and Clustering Using Static Features

被引:8
|
作者
Yamany, Bahaa [1 ]
Elsayed, Mahmoud Said [2 ]
Jurcut, Anca D. [2 ]
Abdelbaki, Nashwa [1 ]
Azer, Marianne A. [1 ,3 ]
机构
[1] Nile Univ, Sch Informat Technol & Comp Sci, Cairo 12566, Egypt
[2] Univ Coll Dublin, Sch Comp Sci, Dublin D04 V1W8, Ireland
[3] Nile Univ, Natl Telecommun Inst, Comp & Syst Dept, Cairo 12566, Egypt
关键词
dynamic analysis; encryption; honeypot; Jaccard index; malware; machine learning; ransomware; similarity matrix; shared code analysis; static analysis; MALWARE;
D O I
10.3390/electronics11203307
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Ransomware is a strain of malware that disables access to the user's resources after infiltrating a victim's system. Ransomware is one of the most dangerous malware organizations face by blocking data access or publishing private data over the internet. The major challenge of any entity is how to decrypt the files encrypted by ransomware. Ransomware's binary analysis can provide a means to characterize the relationships between different features used by ransomware families to track the ransomware encryption mechanism routine. In this paper, we compare the different ransomware detection approaches and techniques. We investigate the criteria, parameters, and tools used in the ransomware detection ecosystem. We present the main recommendations and best practices for ransomware mitigation. In addition, we propose an efficient ransomware indexing system that provides search functionalities, similarity checking, sample classification, and clustering. The new system scheme mainly targets native ransomware binaries, and the indexing engine depends on hybrid data from the static analyzer system. Our scheme tracks and classifies ransomware based on static features to find the similarity between different ransomware samples. This is done by calculating the absolute Jaccard index. Results have shown that Import Address Table (IAT) feature can be used to classify different ransomware more accurately than the Strings feature.
引用
收藏
页数:26
相关论文
共 50 条
  • [1] An Efficient Text Classification Scheme Using Clustering
    Thomas, Anisha Mariam
    Resmipriya, M. G.
    INTERNATIONAL CONFERENCE ON EMERGING TRENDS IN ENGINEERING, SCIENCE AND TECHNOLOGY (ICETEST - 2015), 2016, 24 : 1220 - 1225
  • [2] Fuzzy clustering in classification using weighted features
    Bandeira, LPC
    Sousa, JMC
    Kaymak, U
    FUZZY SETS AND SYSTEMS - IFSA 2003, PROCEEDINGS, 2003, 2715 : 560 - 567
  • [3] Ransomware Detection Using Binary Classification
    Kader, Kazi Samiul
    Tahsin, Md Tareque Hasan
    Hossain, Md Shohrab
    Narman, Husnu S.
    2021 IEEE INTL CONF ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING, INTL CONF ON PERVASIVE INTELLIGENCE AND COMPUTING, INTL CONF ON CLOUD AND BIG DATA COMPUTING, INTL CONF ON CYBER SCIENCE AND TECHNOLOGY CONGRESS DASC/PICOM/CBDCOM/CYBERSCITECH 2021, 2021, : 979 - 984
  • [4] Malware Classification Using Static Analysis Based Features
    Hassen, Mehadi
    Carvalho, Marco M.
    Chan, Philip K.
    2017 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (SSCI), 2017, : 734 - 740
  • [5] A New Static-based Framework for Ransomware Detection
    Medhat, May
    Gaber, Samir
    Abdelbaki, Nashwa
    2018 16TH IEEE INT CONF ON DEPENDABLE, AUTONOM AND SECURE COMP, 16TH IEEE INT CONF ON PERVAS INTELLIGENCE AND COMP, 4TH IEEE INT CONF ON BIG DATA INTELLIGENCE AND COMP, 3RD IEEE CYBER SCI AND TECHNOL CONGRESS (DASC/PICOM/DATACOM/CYBERSCITECH), 2018, : 710 - 715
  • [6] Lockout-Tagout Ransomware: A Detection Method for Ransomware using Fuzzy Hashing and Clustering
    Naik, Nitin
    Jenkins, Paul
    Gillett, Jonathan
    Mouratidis, Haralambos
    Naik, Kshirasagar
    Song, Jingping
    2019 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (IEEE SSCI 2019), 2019, : 641 - 648
  • [7] A Holistic Approach to Ransomware Classification: Leveraging Static and Dynamic Analysis with Visualization
    Yamany, Bahaa
    Elsayed, Mahmoud Said
    Jurcut, Anca D.
    Abdelbaki, Nashwa
    Azer, Marianne A.
    INFORMATION, 2024, 15 (01)
  • [8] Ensemble Model Ransomware Classification: A Static Analysis-based Approach
    Johnson, Shanoop
    Gowtham, R.
    Nair, Anand R.
    INVENTIVE COMPUTATION AND INFORMATION TECHNOLOGIES, ICICIT 2021, 2022, 336 : 153 - 167
  • [9] Crawler Classification using Ant-based Clustering Scheme
    Kuze, Naomi
    Ishikura, Shu
    Yagi, Takeshi
    Chiba, Daiki
    Murata, Masayuki
    2015 10TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2015, : 84 - 89
  • [10] IMAGE CLASSIFICATION: NO FEATURES, NO CLUSTERING
    Cui, Shiyong
    Schwarz, Gottfried
    Datcu, Mihai
    2015 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2015, : 1960 - 1964