A New Static-based Framework for Ransomware Detection

被引:20
|
作者
Medhat, May [1 ,2 ]
Gaber, Samir [2 ,3 ]
Abdelbaki, Nashwa [4 ]
机构
[1] Nile Univ, Informat Secur Program, Giza, Egypt
[2] EG CERT, Giza, Egypt
[3] Helwan Univ, Helwan, Egypt
[4] Nile Univ, Giza, Egypt
关键词
Ransomware; YARA rules; Malicious detection; Static analysis;
D O I
10.1109/DASC/PiCom/DataCom/CyberSciTec.2018.00124
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Recently, ransomware attacks are on the rise hitting critical infrastructures and organizations globally. Ransomware uses advanced encryption techniques to encrypt important files on the targeted computer, then it requests payment to decrypt the encrypted files again. Therefore, the detection and prevention of ransomware attacks represent major challenges for security researchers. This research proposes a novel static-based rules ransomware detection framework. The decision rules of the proposed framework are based on static features extracted from the ransomware files. When scanned file reached rules threshold, the framework evaluates triggered rules through logical operations to assign a score for each file. Every score represents a confidence level whether this file is ransomware or not from critical to low. The proposed framework has proven that it can detect new families based on rules and logical operations with high accuracy and detection ratio.
引用
收藏
页码:710 / 715
页数:6
相关论文
共 50 条
  • [11] Compound continuum manipulator for surgery: Efficient static-based kinematics
    Su, Jing
    Zhang, Gang
    Wei, Hangxing
    Song, Rui
    Du, Fuxin
    INTERNATIONAL JOURNAL OF MEDICAL ROBOTICS AND COMPUTER ASSISTED SURGERY, 2023, 19 (06):
  • [12] Static-based early-damage detection using symbolic data analysis and unsupervised learning methods
    Santos, Joao Pedro
    Cremona, Christian
    Orcesi, Andre D.
    Silveira, Paulo
    Calado, Luis
    FRONTIERS OF STRUCTURAL AND CIVIL ENGINEERING, 2015, 9 (01) : 1 - 16
  • [13] Static-based early-damage detection using symbolic data analysis and unsupervised learning methods
    Joo Pedro SANTOS
    Christian CREMONA
    Andr DORCESI
    Paulo SILVEIRA
    Luis CALADO
    Frontiers of Structural and Civil Engineering, 2015, 9 (01) : 1 - 16
  • [14] AI-Powered Ransomware Detection Framework
    Poudyal, Subash
    Dasgupta, Dipankar
    2020 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (SSCI), 2020, : 1154 - 1161
  • [15] AN APP BASED ON STATIC ANALYSIS FOR ANDROID RANSOMWARE
    Kanwal, Meet
    Thakur, Sanjeev
    2017 IEEE INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND AUTOMATION (ICCCA), 2017, : 813 - 818
  • [16] Static-based early-damage detection using symbolic data analysis and unsupervised learning methods
    João Pedro Santos
    Christian Cremona
    André D. Orcesi
    Paulo Silveira
    Luis Calado
    Frontiers of Structural and Civil Engineering, 2015, 9 : 1 - 16
  • [17] AN APP BASED ON STATIC ANALYSIS FOR ANDROID RANSOMWARE
    Kanwal, Meet
    Thakur, Sanjeev
    Lashkari, Rishabh
    2017 8TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2017,
  • [18] An Ensemble-based Supervised Machine Learning Framework for Android Ransomware Detection
    Sharma, Shweta
    Challa, Rama Krishna
    Kumar, Rakesh
    INTERNATIONAL ARAB JOURNAL OF INFORMATION TECHNOLOGY, 2021, 18 (3A) : 422 - 429
  • [19] Static Detection of Ransomware Using LSTM Network and PE Header
    Manavi, Farnoush
    Hamzeh, Ali
    2021 26TH INTERNATIONAL COMPUTER CONFERENCE, COMPUTER SOCIETY OF IRAN (CSICC), 2021,
  • [20] VoterChoice: A ransomware detection honeypot with multiple voting framework
    Keong Ng, Chee
    Rajasegarar, Sutharshan
    Pan, Lei
    Jiang, Frank
    Zhang, Leo Yu
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2020, 32 (14):