The Inadequacy of Entropy-Based Ransomware Detection

被引:39
|
作者
McIntosh, Timothy [1 ]
Jang-Jaccard, Julian [1 ]
Watters, Paul [2 ]
Susnjak, Teo [1 ]
机构
[1] Massey Univ, Auckland 0632, New Zealand
[2] La Trobe Univ, Bundoora, Vic 3086, Australia
关键词
Ransomware; Entropy; Encryption; File integrity;
D O I
10.1007/978-3-030-36802-9_20
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Many state-of-the-art anti-ransomware implementations monitoring file system activities choose to monitor file entropy-based changes to determine whether the changes may have been committed by ransomware, or to distinguish between compression and encryption operations. However, such detections can be victims of spoofing attacks, when attackers manipulate the entropy values in the expected range during the attacks. This paper explored the limitations of entropy-based ransomware detection on several different file types. We demonstrated how to use Base64-Encoding and Distributed Non-Selective Partial Encryption to manipulate entropy values and to bypass current entropy-based detection mechanisms. By exploiting this vulnerability, attackers can avoid entropy-based detection or degrade detection performance. We recommended that the practice of relying on file entropy change thresholds to detect ransomware encryption should be deprecated.
引用
收藏
页码:181 / 189
页数:9
相关论文
共 50 条
  • [21] Vietnamese treebank construction and entropy-based error detection
    Phuong-Thai Nguyen
    Anh-Cuong Le
    Tu-Bao Ho
    Van-Hiep Nguyen
    Language Resources and Evaluation, 2015, 49 : 487 - 519
  • [22] Sample entropy-based fault detection for photovoltaic arrays
    Khoshnami, Aria
    Sadeghkhani, Iman
    IET RENEWABLE POWER GENERATION, 2018, 12 (16) : 1966 - 1976
  • [23] Entropy-Based Methods for Motor Fault Detection: A Review
    Aguayo-Tapia, Sarahi
    Avalos-Almazan, Gerardo
    Rangel-Magdaleno, Jose de Jesus
    ENTROPY, 2024, 26 (04)
  • [24] Vietnamese treebank construction and entropy-based error detection
    Phuong-Thai Nguyen
    Anh-Cuong Le
    Tu-Bao Ho
    Van-Hiep Nguyen
    LANGUAGE RESOURCES AND EVALUATION, 2015, 49 (03) : 487 - 519
  • [25] Entropy-based electricity theft detection in AMI network
    Singh, Sandeep Kumar
    Bose, Ranjan
    Joshi, Anupam
    IET CYBER-PHYSICAL SYSTEMS: THEORY & APPLICATIONS, 2018, 3 (02) : 99 - 105
  • [26] An Analysis of Entropy-Based Eye Movement Events Detection
    Harezlak, Katarzyna
    Augustyn, Dariusz R.
    Kasprowski, Pawel
    ENTROPY, 2019, 21 (02)
  • [27] Voice Activity Detection Using Entropy-Based Method
    Xu, Ning
    Wang, Chengcheng
    Bao, Jingyi
    2015 9TH INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND COMMUNICATION SYSTEMS (ICSPCS), 2015,
  • [28] Entropy-based multipath detection model for MIMO radar
    Shi, Junpeng
    Hu, Guoping
    Zhou, Hao
    JOURNAL OF SYSTEMS ENGINEERING AND ELECTRONICS, 2017, 28 (01) : 51 - 57
  • [29] Entropy-Based Anomaly Detection for In-Vehicle Networks
    Mueter, Michael
    Asaj, Naim
    2011 IEEE INTELLIGENT VEHICLES SYMPOSIUM (IV), 2011, : 1110 - 1115
  • [30] Entropy-Based Anomaly Detection in Household Electricity Consumption
    Moure-Garrido, Marta
    Campo, Celeste
    Garcia-Rubio, Carlos
    ENERGIES, 2022, 15 (05)