Ransomware Detection using Markov Chain Models over File Headers

被引:2
|
作者
Bailluet, Nicolas [1 ]
Le Bouder, Helene [2 ]
Lubicz, David [3 ]
机构
[1] ENS Rennes, Rennes, France
[2] OCIF IMT Atlantique Campus Rennes, Rennes, France
[3] DGA MI, Bruz, France
关键词
Ransomware; Detection; Malware; Markov Chain; File Header;
D O I
10.5220/0010513104030411
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, a new approach for the detection of ransomware based on the runtime analysis of their behaviour is presented. The main idea is to get samples by using a mini-filter to intercept write requests, then decide if a sample corresponds to a benign or a malicious write request. To do so, in a learning phase, statistical models of structured file headers are built using Markov chains. Then in a detection phase, a maximum likelihood test is used to decide if a sample provided by a write request is normal or malicious. We introduce new statistical distances between two Markov chains, which are variants of the Kullback-Leibler divergence, which measure the efficiency of a maximum likelihood test to distinguish between two distributions given by Markov chains. This distance and extensive experiments are used to demonstrate the relevance of our method.
引用
收藏
页码:403 / 411
页数:9
相关论文
共 50 条
  • [1] Multilayer ransomware detection using grouped registry key operations, file entropy and file signature monitoring
    Jethva, Brijesh
    Traore, Issa
    Ghaleb, Asem
    Ganame, Karim
    Ahmed, Sherif
    JOURNAL OF COMPUTER SECURITY, 2020, 28 (03) : 337 - 373
  • [2] Crypto-ransomware detection using machine learning models in file-sharing network scenarios with encrypted traffic
    Berrueta, Eduardo
    Morato, Daniel
    Magana, Eduardo
    Izal, Mikel
    EXPERT SYSTEMS WITH APPLICATIONS, 2022, 209
  • [3] Crypto-ransomware detection using machine learning models in file-sharing network scenarios with encrypted traffic
    Berrueta, Eduardo
    Morato, Daniel
    Magaña, Eduardo
    Izal, Mikel
    Expert Systems with Applications, 2022, 209
  • [4] Ransomware early detection by the analysis of file sharing traffic
    Morato, Daniel
    Berrueta, Eduardo
    Magana, Eduardo
    Izal, Mikel
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2018, 124 : 14 - 32
  • [5] FRAGMENTED JPEG FILE RECOVERY USING PSEUDO HEADERS
    Tang, Yanbin
    Tan, Zheng
    Chow, Kam-Pui
    Yiu, Siu-Ming
    Fang, Junbin
    Niu, Xiamu
    Han, Qi
    Wu, Xianyan
    ADVANCES IN DIGITAL FORENSICS XI, 2015, 462 : 215 - 231
  • [6] Visualizing Portable Executable Headers for Ransomware Detection: A Deep Learning-Based Approach
    Dam, Tien Quang
    Nguyen, Nghia Thinh
    Le, Trung Viet
    Le, Tran Duc
    Uwizeyemungu, Sylvestre
    Le-Dinh, Thang
    JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2024, 30 (02) : 262 - 286
  • [7] R-Sentry: Deception based ransomware detection using file access patterns
    Sheen, Shina
    Asmitha, K. A.
    Venkatesan, Sridhar
    COMPUTERS & ELECTRICAL ENGINEERING, 2022, 103
  • [8] Detecting Ransomware Encryption with File Signatures and Machine Learning Models
    Duignan, Michael
    Schukat, Michael
    Barrett, Enda
    2023 34TH IRISH SIGNALS AND SYSTEMS CONFERENCE, ISSC, 2023,
  • [9] Ransomware Detection and Prevention through Strategically Hidden Decoy File
    Lin, Yung-She
    Lee, Chin-Feng
    International Journal of Network Security, 2023, 25 (02): : 212 - 220
  • [10] A Behaviour based Ransomware Detection using Neural Network Models
    Ketzaki, Eleni
    Toupas, Petros
    Giannoutakis, Konstantinos M.
    Drosou, Anastasios
    Tzovaras, Dimitrios
    2020 10TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTER INFORMATION TECHNOLOGIES (ACIT), 2020, : 747 - 750