A New Static-based Framework for Ransomware Detection

被引:20
|
作者
Medhat, May [1 ,2 ]
Gaber, Samir [2 ,3 ]
Abdelbaki, Nashwa [4 ]
机构
[1] Nile Univ, Informat Secur Program, Giza, Egypt
[2] EG CERT, Giza, Egypt
[3] Helwan Univ, Helwan, Egypt
[4] Nile Univ, Giza, Egypt
关键词
Ransomware; YARA rules; Malicious detection; Static analysis;
D O I
10.1109/DASC/PiCom/DataCom/CyberSciTec.2018.00124
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Recently, ransomware attacks are on the rise hitting critical infrastructures and organizations globally. Ransomware uses advanced encryption techniques to encrypt important files on the targeted computer, then it requests payment to decrypt the encrypted files again. Therefore, the detection and prevention of ransomware attacks represent major challenges for security researchers. This research proposes a novel static-based rules ransomware detection framework. The decision rules of the proposed framework are based on static features extracted from the ransomware files. When scanned file reached rules threshold, the framework evaluates triggered rules through logical operations to assign a score for each file. Every score represents a confidence level whether this file is ransomware or not from critical to low. The proposed framework has proven that it can detect new families based on rules and logical operations with high accuracy and detection ratio.
引用
收藏
页码:710 / 715
页数:6
相关论文
共 50 条
  • [21] A New Scheme for Ransomware Classification and Clustering Using Static Features
    Yamany, Bahaa
    Elsayed, Mahmoud Said
    Jurcut, Anca D.
    Abdelbaki, Nashwa
    Azer, Marianne A.
    ELECTRONICS, 2022, 11 (20)
  • [22] A Graph-Structured Representation with BRNN for Static-based Facial Expression Recognition
    Zhong, Lei
    Bai, Chaugmin
    Li, Jianfeng
    Chen, Tong
    Li, Shigang
    Liu, Yiguang
    2019 14TH IEEE INTERNATIONAL CONFERENCE ON AUTOMATIC FACE AND GESTURE RECOGNITION (FG 2019), 2019, : 270 - 274
  • [23] The Static Analysis of WannaCry Ransomware
    Hsiao, Shou-Ching
    Kao, Da-Yu
    2018 20TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT), 2018, : 153 - 158
  • [24] RansomGuard: a framework for proactive detection and mitigation of cryptographic windows ransomware
    Alvi, M. Adnan
    Jalil, Zunera
    JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2024, 20 (04): : 867 - 884
  • [25] The Inadequacy of Entropy-Based Ransomware Detection
    McIntosh, Timothy
    Jang-Jaccard, Julian
    Watters, Paul
    Susnjak, Teo
    NEURAL INFORMATION PROCESSING, ICONIP 2019, PT V, 2019, 1143 : 181 - 189
  • [26] On the Effectiveness of Behavior-Based Ransomware Detection
    Han, Jaehyun
    Lin, Zhiqiang
    Porter, Donald E.
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS (SECURECOMM 2020), PT II, 2020, 336 : 120 - 140
  • [27] Deep Learning LSTM based Ransomware Detection
    Maniath, Sumith
    Ashok, Aravind
    Poornachandran, Prabaharan
    Sujadevi, V. G.
    Sankar, Prem A. U.
    Jan, Srinath
    2017 RECENT DEVELOPMENTS IN CONTROL, AUTOMATION AND POWER ENGINEERING (RDCAPE), 2017, : 442 - 446
  • [28] ProtectNIC: SmartNIC-based Ransomware Detection
    Xu, Anson
    Choudhury, Arnav
    Liu, Eason
    Choi, Sean
    2024 SILICON VALLEY CYBERSECURITY CONFERENCE, SVCC 2024, 2024,
  • [29] Ransomware Attack Modeling and Artificial Intelligence-Based Ransomware Detection for Digital Substations
    Alvee, Syed R. B.
    Ahn, Bohyun
    Kim, Taesic
    Su, Ying
    Youn, Young-Woo
    Ryu, Myung-Hyo
    2021 6TH IEEE WORKSHOP ON THE ELECTRONIC GRID (EGRID), 2021,
  • [30] Ensemble Model Ransomware Classification: A Static Analysis-based Approach
    Johnson, Shanoop
    Gowtham, R.
    Nair, Anand R.
    INVENTIVE COMPUTATION AND INFORMATION TECHNOLOGIES, ICICIT 2021, 2022, 336 : 153 - 167