A New Static-based Framework for Ransomware Detection

被引:20
|
作者
Medhat, May [1 ,2 ]
Gaber, Samir [2 ,3 ]
Abdelbaki, Nashwa [4 ]
机构
[1] Nile Univ, Informat Secur Program, Giza, Egypt
[2] EG CERT, Giza, Egypt
[3] Helwan Univ, Helwan, Egypt
[4] Nile Univ, Giza, Egypt
关键词
Ransomware; YARA rules; Malicious detection; Static analysis;
D O I
10.1109/DASC/PiCom/DataCom/CyberSciTec.2018.00124
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Recently, ransomware attacks are on the rise hitting critical infrastructures and organizations globally. Ransomware uses advanced encryption techniques to encrypt important files on the targeted computer, then it requests payment to decrypt the encrypted files again. Therefore, the detection and prevention of ransomware attacks represent major challenges for security researchers. This research proposes a novel static-based rules ransomware detection framework. The decision rules of the proposed framework are based on static features extracted from the ransomware files. When scanned file reached rules threshold, the framework evaluates triggered rules through logical operations to assign a score for each file. Every score represents a confidence level whether this file is ransomware or not from critical to low. The proposed framework has proven that it can detect new families based on rules and logical operations with high accuracy and detection ratio.
引用
收藏
页码:710 / 715
页数:6
相关论文
共 50 条
  • [1] Static-Based Test Case Dynamic Generation for SQLIVs Detection
    Li, Ling
    Qi, Junxin
    Liu, Nan
    Han, Lifang
    Cui, Baojiang
    2015 10TH INTERNATIONAL CONFERENCE ON BROADBAND AND WIRELESS COMPUTING, COMMUNICATION AND APPLICATIONS (BWCCA 2015), 2015, : 173 - 177
  • [2] E2E-RDS: Efficient End-to-End Ransomware Detection System Based on Static-Based ML and Vision-Based DL Approaches
    Almomani, Iman
    Alkhayer, Aala
    El-Shafai, Walid
    SENSORS, 2023, 23 (09)
  • [3] Static-Based Damage Detection Using Measured Strain and Deflection Data
    Eun, Hee-Chang
    Park, Su-Yong
    Lee, Min-Su
    ADVANCES IN CIVIL ENGINEERING II, PTS 1-4, 2013, 256-259 : 1097 - 1100
  • [4] Static-based verification of memory BIST integration
    Lee, KJ
    Kim, S
    Park, S
    Yoo, Y
    PROCEEDINGS OF THE SECOND IEEE ASIA PACIFIC CONFERENCE ON ASICS, 2000, : 151 - 154
  • [5] YARAMON: A Memory-based Detection Framework for Ransomware Families
    Medhat, May
    Essa, Menna
    Faisal, Hend
    Sayed, Samir G.
    INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST-2020), 2020, : 114 - 119
  • [7] A framework for supporting ransomware detection and prevention based on hybrid analysis
    Francesco Mercaldo
    Journal of Computer Virology and Hacking Techniques, 2021, 17 : 221 - 227
  • [8] A Framework for Supporting Ransomware Detection and Prevention Based on Hybrid Analysis
    Cuzzocrea, Alfredo
    Mercaldo, Francesco
    Martinelli, Fabio
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS, ICCSA 2021, PT III, 2021, 12951 : 16 - 27
  • [9] ARdetector: android ransomware detection framework
    Dan Li
    Wenbo Shi
    Ning Lu
    Sang-Su Lee
    Sokjoon Lee
    The Journal of Supercomputing, 2024, 80 : 7557 - 7584
  • [10] ARdetector: android ransomware detection framework
    Li, Dan
    Shi, Wenbo
    Lu, Ning
    Lee, Sang-Su
    Lee, Sokjoon
    JOURNAL OF SUPERCOMPUTING, 2024, 80 (06): : 7557 - 7584