A New Scheme for Ransomware Classification and Clustering Using Static Features

被引:8
|
作者
Yamany, Bahaa [1 ]
Elsayed, Mahmoud Said [2 ]
Jurcut, Anca D. [2 ]
Abdelbaki, Nashwa [1 ]
Azer, Marianne A. [1 ,3 ]
机构
[1] Nile Univ, Sch Informat Technol & Comp Sci, Cairo 12566, Egypt
[2] Univ Coll Dublin, Sch Comp Sci, Dublin D04 V1W8, Ireland
[3] Nile Univ, Natl Telecommun Inst, Comp & Syst Dept, Cairo 12566, Egypt
关键词
dynamic analysis; encryption; honeypot; Jaccard index; malware; machine learning; ransomware; similarity matrix; shared code analysis; static analysis; MALWARE;
D O I
10.3390/electronics11203307
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Ransomware is a strain of malware that disables access to the user's resources after infiltrating a victim's system. Ransomware is one of the most dangerous malware organizations face by blocking data access or publishing private data over the internet. The major challenge of any entity is how to decrypt the files encrypted by ransomware. Ransomware's binary analysis can provide a means to characterize the relationships between different features used by ransomware families to track the ransomware encryption mechanism routine. In this paper, we compare the different ransomware detection approaches and techniques. We investigate the criteria, parameters, and tools used in the ransomware detection ecosystem. We present the main recommendations and best practices for ransomware mitigation. In addition, we propose an efficient ransomware indexing system that provides search functionalities, similarity checking, sample classification, and clustering. The new system scheme mainly targets native ransomware binaries, and the indexing engine depends on hybrid data from the static analyzer system. Our scheme tracks and classifies ransomware based on static features to find the similarity between different ransomware samples. This is done by calculating the absolute Jaccard index. Results have shown that Import Address Table (IAT) feature can be used to classify different ransomware more accurately than the Strings feature.
引用
收藏
页数:26
相关论文
共 50 条
  • [41] Static pickup and delivery problems: a classification scheme and survey
    Gerardo Berbeglia
    Jean-François Cordeau
    Irina Gribkovskaia
    Gilbert Laporte
    TOP, 2007, 15 : 1 - 31
  • [42] Hybrid Clustering Scheme for the Classification of Lesions in Mammogram Images
    Vedanarayanan, V.
    RESEARCH JOURNAL OF PHARMACEUTICAL BIOLOGICAL AND CHEMICAL SCIENCES, 2015, 6 (03): : 352 - 359
  • [43] A coarse classification scheme based on clustering and distance thresholds
    Chiang, TW
    Tsai, TW
    PROCEEDINGS OF THE 8TH JOINT CONFERENCE ON INFORMATION SCIENCES, VOLS 1-3, 2005, : 1473 - 1476
  • [44] Static human behavior classification based on LLC features and GIST features
    Wang Ende
    Hou Xukui
    Li Xuepeng
    2017 IEEE 7TH ANNUAL INTERNATIONAL CONFERENCE ON CYBER TECHNOLOGY IN AUTOMATION, CONTROL, AND INTELLIGENT SYSTEMS (CYBER), 2017, : 651 - 656
  • [45] Overview and Case Study for Ransomware Classification Using Deep Neural Network
    Nurnoby, M. Faisal
    El-Alfy, El-Sayed M.
    2019 2ND IEEE MIDDLE EAST AND NORTH AFRICA COMMUNICATIONS CONFERENCE (IEEEMENACOMM'19), 2019, : 273 - 278
  • [46] Malware detection using static analysis in Android: a review of FeCO (features, classification, and obfuscation)
    Jusoh, Rosmalissa
    Firdaus, Ahmad
    Anwar, Shahid
    Osman, Mohd Zamri
    Darmawan, Mohd Faaizie
    Ab Razak, Mohd Faizal
    PEERJ COMPUTER SCIENCE, 2021, 7 : 1 - 54
  • [47] Ransomware Classification Framework Using the Behavioral Performance Visualization of Execution Objects
    Kim, Jun-Seob
    Park, Ki-Woong
    CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 72 (02): : 3401 - 3424
  • [48] Classification of Leukocyte Images Using K-Means Clustering Based on Geometry Features
    Rosyadi, Tsalis
    Arif, Agus
    Nopriadi
    Achmad, Balza
    Faridah
    2016 6TH INTERNATIONAL ANNUAL ENGINEERING SEMINAR (INAES), 2016, : 245 - 249
  • [49] Classification of PD Faults Using Features Extraction and K-Means Clustering Techniques
    Kumar, Haresh
    Shafiq, Muhammad
    Hussain, Ghulam Amjad
    Kumpulainen, Lauri
    Kauhaniemi, Kimmo
    2020 IEEE PES INNOVATIVE SMART GRID TECHNOLOGIES EUROPE (ISGT-EUROPE 2020): SMART GRIDS: KEY ENABLERS OF A GREEN POWER SYSTEM, 2020, : 919 - 923
  • [50] Image classification using SURF and bag of LBP features constructed by clustering with fixed centers
    Srivastava, Divya
    Bakthula, Rajitha
    Agarwal, Suneeta
    MULTIMEDIA TOOLS AND APPLICATIONS, 2019, 78 (11) : 14129 - 14153