A New Scheme for Ransomware Classification and Clustering Using Static Features

被引:8
|
作者
Yamany, Bahaa [1 ]
Elsayed, Mahmoud Said [2 ]
Jurcut, Anca D. [2 ]
Abdelbaki, Nashwa [1 ]
Azer, Marianne A. [1 ,3 ]
机构
[1] Nile Univ, Sch Informat Technol & Comp Sci, Cairo 12566, Egypt
[2] Univ Coll Dublin, Sch Comp Sci, Dublin D04 V1W8, Ireland
[3] Nile Univ, Natl Telecommun Inst, Comp & Syst Dept, Cairo 12566, Egypt
关键词
dynamic analysis; encryption; honeypot; Jaccard index; malware; machine learning; ransomware; similarity matrix; shared code analysis; static analysis; MALWARE;
D O I
10.3390/electronics11203307
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Ransomware is a strain of malware that disables access to the user's resources after infiltrating a victim's system. Ransomware is one of the most dangerous malware organizations face by blocking data access or publishing private data over the internet. The major challenge of any entity is how to decrypt the files encrypted by ransomware. Ransomware's binary analysis can provide a means to characterize the relationships between different features used by ransomware families to track the ransomware encryption mechanism routine. In this paper, we compare the different ransomware detection approaches and techniques. We investigate the criteria, parameters, and tools used in the ransomware detection ecosystem. We present the main recommendations and best practices for ransomware mitigation. In addition, we propose an efficient ransomware indexing system that provides search functionalities, similarity checking, sample classification, and clustering. The new system scheme mainly targets native ransomware binaries, and the indexing engine depends on hybrid data from the static analyzer system. Our scheme tracks and classifies ransomware based on static features to find the similarity between different ransomware samples. This is done by calculating the absolute Jaccard index. Results have shown that Import Address Table (IAT) feature can be used to classify different ransomware more accurately than the Strings feature.
引用
收藏
页数:26
相关论文
共 50 条
  • [21] A New Classification Scheme for Spinal Vascular Abnormalities Based on Angiographic Features
    Qureshi, Adnan
    NEUROLOGY, 2012, 78
  • [22] A New Classification Scheme for Spinal Vascular Abnormalities based on Angiographic Features
    Qureshi, Adnan I.
    JOURNAL OF NEUROIMAGING, 2013, 23 (03) : 401 - 408
  • [23] Automatic Defect Classification Using Frequency and Spatial Features in a Boosting Scheme
    Kim, Hong Il
    Lee, Sang Hwa
    Cho, Nam Ik
    IEEE SIGNAL PROCESSING LETTERS, 2009, 16 (05) : 374 - 377
  • [24] Ransomware Detection and Classification Using Machine Learning and Deep Learning
    Ouerdi, Noura
    Mejjout, Brahim
    Laaroussi, Khadija
    Kasmi, Mohammed Amine
    ADVANCES IN SMART MEDICAL, IOT & ARTIFICIAL INTELLIGENCE, VOL 1, ICSMAI 2024, 2024, 11 : 194 - 201
  • [25] Ransomware detection based on machine learning using memory features
    Aljabri, Malak
    Alhaidari, Fahd
    Albuainain, Aminah
    Alrashidi, Samiyah
    Alansari, Jana
    Alqahtani, Wasmiyah
    Alshaya, Jana
    EGYPTIAN INFORMATICS JOURNAL, 2024, 25
  • [26] A few-shot meta-learning based siamese neural network using entropy features for ransomware classification
    Zhu, Jinting
    Jang-Jaccard, Julian
    Singh, Amardeep
    Welch, Ian
    Al-Sahaf, Harith
    Camtepe, Seyit
    COMPUTERS & SECURITY, 2022, 117
  • [27] On the classification of Microsoft-Windows ransomware using hardware profile
    Aurangzeb, Sana
    Bin Rais, Rao Naveed
    Aleem, Muhammad
    Islam, Muhammad Arshad
    Iqbal, Muhammad Azhar
    PEERJ COMPUTER SCIENCE, 2021, 7 : 1 - 24
  • [28] Binary and multi-class classification of Android applications using static features
    Dhalaria, Meghna
    Gandotra, Ekta
    INTERNATIONAL JOURNAL OF APPLIED MANAGEMENT SCIENCE, 2023, 15 (02) : 117 - 140
  • [29] Automatic Fingerprint Classification Scheme by Using Template Matching with New Set of Singular Point-Based Features
    Abbood, Alaa Ahmed
    Sulong, Ghazali
    Kaittan, Nada Mahdi
    Peters, Sabine U.
    NEW TRENDS IN INFORMATION AND COMMUNICATIONS TECHNOLOGY APPLICATIONS, NTICT 2018, 2018, 938 : 226 - 239
  • [30] NEW CLASSIFICATION SCHEME
    不详
    CESKOSLOVENSKY CASOPIS PRO FYSIKU SEKCE A, 1978, 28 (03): : 284 - 285