A New Static-based Framework for Ransomware Detection

被引:20
|
作者
Medhat, May [1 ,2 ]
Gaber, Samir [2 ,3 ]
Abdelbaki, Nashwa [4 ]
机构
[1] Nile Univ, Informat Secur Program, Giza, Egypt
[2] EG CERT, Giza, Egypt
[3] Helwan Univ, Helwan, Egypt
[4] Nile Univ, Giza, Egypt
关键词
Ransomware; YARA rules; Malicious detection; Static analysis;
D O I
10.1109/DASC/PiCom/DataCom/CyberSciTec.2018.00124
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Recently, ransomware attacks are on the rise hitting critical infrastructures and organizations globally. Ransomware uses advanced encryption techniques to encrypt important files on the targeted computer, then it requests payment to decrypt the encrypted files again. Therefore, the detection and prevention of ransomware attacks represent major challenges for security researchers. This research proposes a novel static-based rules ransomware detection framework. The decision rules of the proposed framework are based on static features extracted from the ransomware files. When scanned file reached rules threshold, the framework evaluates triggered rules through logical operations to assign a score for each file. Every score represents a confidence level whether this file is ransomware or not from critical to low. The proposed framework has proven that it can detect new families based on rules and logical operations with high accuracy and detection ratio.
引用
收藏
页码:710 / 715
页数:6
相关论文
共 50 条
  • [41] A Universal Malicious Documents Static Detection Framework Based on Feature Generalization
    Lu, Xiaofeng
    Wang, Fei
    Jiang, Cheng
    Lio, Pietro
    APPLIED SCIENCES-BASEL, 2021, 11 (24):
  • [42] A Framework for Information-Based Sensor Management for the Detection of Static Targets
    Kolba, Mark P.
    Scott, Waymond R., Jr.
    Collins, Leslie M.
    IEEE TRANSACTIONS ON SYSTEMS MAN AND CYBERNETICS PART A-SYSTEMS AND HUMANS, 2011, 41 (01): : 105 - 120
  • [43] Static Anomaly Detection Framework for Android-based Mobile Phones
    Ji, Xiaobo
    Zeng, Fan
    Ye, Bangxian
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2016, 10 (12): : 251 - 259
  • [44] RansoGuard: A RNN-based framework leveraging pre-attack sensitive APIs for early ransomware detection
    Cen, Mingcan
    Jiang, Frank
    Doss, Robin
    COMPUTERS & SECURITY, 2025, 150
  • [45] AI driven IOMT security framework for advanced malware and ransomware detection in SDN
    Almotiri, Sultan H.
    JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2025, 14 (01):
  • [46] DNA-Droid: A Real-Time Android Ransomware Detection Framework
    Gharib, Amirhossein
    Ghorbani, Ali
    NETWORK AND SYSTEM SECURITY, 2017, 10394 : 184 - 198
  • [47] Limits of I/O Based Ransomware Detection: An Imitation Based Attack
    Zhou, Chijin
    Guo, Lihua
    Hou, Yiwei
    Ma, Zhenya
    Zhang, Quan
    Wang, Mingzhe
    Liu, Zhe
    Jiang, Yu
    2023 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, SP, 2023, : 2584 - 2601
  • [48] RWArmor: a static-informed dynamic analysis approach for early detection of cryptographic windows ransomware
    Md. Ahsan Ayub
    Ambareen Siraj
    Bobby Filar
    Maanak Gupta
    International Journal of Information Security, 2024, 23 (1) : 533 - 556
  • [49] RWArmor: a static-informed dynamic analysis approach for early detection of cryptographic windows ransomware
    Ayub, Md. Ahsan
    Siraj, Ambareen
    Filar, Bobby
    Gupta, Maanak
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2024, 23 (01) : 533 - 556
  • [50] A Multi-Classifier Network-Based Crypto Ransomware Detection System: A Case Study of Locky Ransomware
    Almashhadani, Ahmad O.
    Kaiiali, Mustafa
    Sezer, Sakir
    O'Kane, Philip
    IEEE ACCESS, 2019, 7 : 47053 - 47067