Ransomware Detection using Markov Chain Models over File Headers

被引:2
|
作者
Bailluet, Nicolas [1 ]
Le Bouder, Helene [2 ]
Lubicz, David [3 ]
机构
[1] ENS Rennes, Rennes, France
[2] OCIF IMT Atlantique Campus Rennes, Rennes, France
[3] DGA MI, Bruz, France
来源
SECRYPT 2021: PROCEEDINGS OF THE 18TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY | 2021年
关键词
Ransomware; Detection; Malware; Markov Chain; File Header;
D O I
10.5220/0010513104030411
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, a new approach for the detection of ransomware based on the runtime analysis of their behaviour is presented. The main idea is to get samples by using a mini-filter to intercept write requests, then decide if a sample corresponds to a benign or a malicious write request. To do so, in a learning phase, statistical models of structured file headers are built using Markov chains. Then in a detection phase, a maximum likelihood test is used to decide if a sample provided by a write request is normal or malicious. We introduce new statistical distances between two Markov chains, which are variants of the Kullback-Leibler divergence, which measure the efficiency of a maximum likelihood test to distinguish between two distributions given by Markov chains. This distance and extensive experiments are used to demonstrate the relevance of our method.
引用
收藏
页码:403 / 411
页数:9
相关论文
共 50 条
  • [41] Masquerade detection using profile hidden Markov models
    Huang, Lin
    Stamp, Mark
    COMPUTERS & SECURITY, 2011, 30 (08) : 732 - 747
  • [42] Flame detection in video using hidden Markov models
    Töreyin, BU
    Dedeoglu, Y
    Çetin, AE
    2005 INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), VOLS 1-5, 2005, : 2457 - 2460
  • [43] Riboswitch Detection Using Profile Hidden Markov Models
    Payal Singh
    Pradipta Bandyopadhyay
    Sudha Bhattacharya
    A Krishnamachari
    Supratim Sengupta
    BMC Bioinformatics, 10
  • [44] Using Hidden Markov Models in Vehicular Crash Detection
    Singh, Gautam B.
    Song, Haiping
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2009, 58 (03) : 1119 - 1128
  • [45] Helicopter detection and classification using hidden Markov models
    Kuklinski, WS
    O'Neil, SD
    Tromp, LD
    SIGNAL PROCESSING, SENSOR FUSION, AND TARGET RECOGNITION VIII, 1999, 3720 : 130 - 139
  • [46] Riboswitch Detection Using Profile Hidden Markov Models
    Singh, Payal
    Bandyopadhyay, Pradipta
    Bhattacharya, Sudha
    Krishnamachari, A.
    Sengupta, Supratim
    BMC BIOINFORMATICS, 2009, 10
  • [47] Face detection and recognition using Hidden Markov Models
    Nefian, AV
    Hayes, MH
    1998 INTERNATIONAL CONFERENCE ON IMAGE PROCESSING - PROCEEDINGS, VOL 1, 1998, : 141 - 145
  • [48] Detection of myocardial ischemia using hidden Markov models
    Bardonova, J
    Provaznik, I
    Novakova, M
    Vesela, R
    PROCEEDINGS OF THE 25TH ANNUAL INTERNATIONAL CONFERENCE OF THE IEEE ENGINEERING IN MEDICINE AND BIOLOGY SOCIETY, VOLS 1-4: A NEW BEGINNING FOR HUMAN HEALTH, 2003, 25 : 2869 - 2872
  • [49] Detection of the markov signals in a mixture with the markov correlated clutters using autoregressive models
    Prokopenko, I. G.
    2006 EUROPEAN RADAR CONFERENCE, 2006, : 237 - 240
  • [50] Markov chain Markov field dynamics: Models and statistics
    Guyon, X
    Hardouin, C
    STATISTICS, 2002, 36 (04) : 339 - 363