Ransomware Detection using Markov Chain Models over File Headers

被引:2
|
作者
Bailluet, Nicolas [1 ]
Le Bouder, Helene [2 ]
Lubicz, David [3 ]
机构
[1] ENS Rennes, Rennes, France
[2] OCIF IMT Atlantique Campus Rennes, Rennes, France
[3] DGA MI, Bruz, France
来源
SECRYPT 2021: PROCEEDINGS OF THE 18TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY | 2021年
关键词
Ransomware; Detection; Malware; Markov Chain; File Header;
D O I
10.5220/0010513104030411
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, a new approach for the detection of ransomware based on the runtime analysis of their behaviour is presented. The main idea is to get samples by using a mini-filter to intercept write requests, then decide if a sample corresponds to a benign or a malicious write request. To do so, in a learning phase, statistical models of structured file headers are built using Markov chains. Then in a detection phase, a maximum likelihood test is used to decide if a sample provided by a write request is normal or malicious. We introduce new statistical distances between two Markov chains, which are variants of the Kullback-Leibler divergence, which measure the efficiency of a maximum likelihood test to distinguish between two distributions given by Markov chains. This distance and extensive experiments are used to demonstrate the relevance of our method.
引用
收藏
页码:403 / 411
页数:9
相关论文
共 50 条
  • [31] Prediction of protein subcellular locations using Markov chain models
    Yuan, Z
    FEBS LETTERS, 1999, 451 (01) : 23 - 26
  • [32] Development of Pavement Deterioration Models Using Markov Chain Process
    Isradi, Muhammad
    Rifai, Andri I.
    Prasetijo, Joewono
    Kinasih, Reni K.
    Setiawan, Muhammad I.
    CIVIL ENGINEERING JOURNAL-TEHRAN, 2024, 10 (09): : 2954 - 2965
  • [33] Protein classification into domains of life using Markov chain models
    Zanoguera, F
    de Francesco, M
    2004 IEEE COMPUTATIONAL SYSTEMS BIOINFORMATICS CONFERENCE, PROCEEDINGS, 2004, : 517 - 519
  • [34] ISOLATED WORD RECOGNITION USING MARKOV-CHAIN MODELS
    DAI, JN
    IEEE TRANSACTIONS ON SPEECH AND AUDIO PROCESSING, 1995, 3 (06): : 458 - 463
  • [35] Classification of customer lifetime value models using Markov chain
    Permana, Dony
    Pasaribu, Udjianna S.
    Indratno, Sapto W.
    Suprayogi
    ASIAN MATHEMATICAL CONFERENCE 2016 (AMC 2016), 2017, 893
  • [36] Updating Markov chain models using the ensemble Kalman filter
    Dean S. Oliver
    Yan Chen
    Geir Nævdal
    Computational Geosciences, 2011, 15 : 325 - 344
  • [37] API-Based Ransomware Detection Using Machine Learning-Based Threat Detection Models
    Almousa, May
    Basavaraju, Sai
    Anwar, Mohd
    2021 18TH INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2021,
  • [38] Practical aspects related to using Hidden Markov Models for detecting metamorphic file infectors
    Cosovan, Doina
    Lita, Catalin Valeriu
    2017 19TH INTERNATIONAL SYMPOSIUM ON SYMBOLIC AND NUMERIC ALGORITHMS FOR SCIENTIFIC COMPUTING (SYNASC 2017), 2017, : 275 - 278
  • [39] Detection and prevention of spam over Internet telephony in Voice over Internet Protocol networks using Markov chain with incremental SVM
    Vennila, G.
    Manikandan, M. S. K.
    Suresh, M. N.
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2017, 30 (11)
  • [40] Markov chain models for pre-monsoon season thunderstorms over Pune
    Kulkarni, MK
    Kandalgaonkar, SS
    Tinmaker, MIR
    Nath, A
    INTERNATIONAL JOURNAL OF CLIMATOLOGY, 2002, 22 (11) : 1415 - 1420