A New Scheme for Ransomware Classification and Clustering Using Static Features

被引:8
|
作者
Yamany, Bahaa [1 ]
Elsayed, Mahmoud Said [2 ]
Jurcut, Anca D. [2 ]
Abdelbaki, Nashwa [1 ]
Azer, Marianne A. [1 ,3 ]
机构
[1] Nile Univ, Sch Informat Technol & Comp Sci, Cairo 12566, Egypt
[2] Univ Coll Dublin, Sch Comp Sci, Dublin D04 V1W8, Ireland
[3] Nile Univ, Natl Telecommun Inst, Comp & Syst Dept, Cairo 12566, Egypt
关键词
dynamic analysis; encryption; honeypot; Jaccard index; malware; machine learning; ransomware; similarity matrix; shared code analysis; static analysis; MALWARE;
D O I
10.3390/electronics11203307
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Ransomware is a strain of malware that disables access to the user's resources after infiltrating a victim's system. Ransomware is one of the most dangerous malware organizations face by blocking data access or publishing private data over the internet. The major challenge of any entity is how to decrypt the files encrypted by ransomware. Ransomware's binary analysis can provide a means to characterize the relationships between different features used by ransomware families to track the ransomware encryption mechanism routine. In this paper, we compare the different ransomware detection approaches and techniques. We investigate the criteria, parameters, and tools used in the ransomware detection ecosystem. We present the main recommendations and best practices for ransomware mitigation. In addition, we propose an efficient ransomware indexing system that provides search functionalities, similarity checking, sample classification, and clustering. The new system scheme mainly targets native ransomware binaries, and the indexing engine depends on hybrid data from the static analyzer system. Our scheme tracks and classifies ransomware based on static features to find the similarity between different ransomware samples. This is done by calculating the absolute Jaccard index. Results have shown that Import Address Table (IAT) feature can be used to classify different ransomware more accurately than the Strings feature.
引用
收藏
页数:26
相关论文
共 50 条
  • [31] Using Data Mining on Students' Learning Features: A Clustering Approach for Student Classification
    Zhou, Xiaolan
    An, Jianqi
    Zhao, Xin
    Dong, Yuanxing
    JOURNAL OF ADVANCED COMPUTATIONAL INTELLIGENCE AND INTELLIGENT INFORMATICS, 2016, 20 (07) : 1141 - 1146
  • [32] Spectral Classification of Retinal Features Using K-Means Clustering Algorithm
    Cho, Julie
    Kashani, Amir H.
    Humayun, Mark S.
    INVESTIGATIVE OPHTHALMOLOGY & VISUAL SCIENCE, 2015, 56 (07)
  • [33] AUDIO GENRE CLASSIFICATION USING PERCUSSIVE PATTERN CLUSTERING COMBINED WITH TIMBRAL FEATURES
    Tsunoo, Emiru
    Tzanetakis, George
    Ono, Nobutaka
    Sagayama, Shigeki
    ICME: 2009 IEEE INTERNATIONAL CONFERENCE ON MULTIMEDIA AND EXPO, VOLS 1-3, 2009, : 382 - +
  • [34] A comprehensive analysis combining structural features for detection of new ransomware families
    Moreira, Caio C.
    Moreira, Davi C.
    Sales Jr, Claudomiro
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2024, 81
  • [35] Remote Sensing Image Classification: No Features, No Clustering
    Cui, Shiyong
    Schwarz, Gottfried
    Datcu, Mihai
    IEEE JOURNAL OF SELECTED TOPICS IN APPLIED EARTH OBSERVATIONS AND REMOTE SENSING, 2015, 8 (11) : 5158 - 5170
  • [36] A static clustering scheme for wireless multimedia sensor networks routing
    Yin, G. (yinguofu@163.com), 1600, Advanced Institute of Convergence Information Technology (07):
  • [37] Face liveness detection scheme with static and dynamic features
    Wu, Lifang
    Xu, Yaowen
    Jian, Meng
    Xu, Xiao
    Qi, Wei
    INTERNATIONAL JOURNAL OF WAVELETS MULTIRESOLUTION AND INFORMATION PROCESSING, 2018, 16 (02)
  • [38] Selecting Genes for Cancer Classification Using SVM: An Adaptive Multiple Features Scheme
    Hsu, Wen-Chin
    Liu, Chan-Cheng
    Chang, Fu
    Chen, Su-Shing
    INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2013, 28 (12) : 1196 - 1213
  • [39] Routing algorithms on static interconnection networks: a classification scheme
    Demaine, E
    Srinivas, S
    COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 1997, 12 (06): : 359 - 367
  • [40] Static pickup and delivery problems: a classification scheme and survey
    Berbeglia, Gerardo
    Cordeau, Jean-Francois
    Gribkovskaia, Irina
    Laporte, Gilbert
    TOP, 2007, 15 (01) : 1 - 31