The Inadequacy of Entropy-Based Ransomware Detection

被引:39
|
作者
McIntosh, Timothy [1 ]
Jang-Jaccard, Julian [1 ]
Watters, Paul [2 ]
Susnjak, Teo [1 ]
机构
[1] Massey Univ, Auckland 0632, New Zealand
[2] La Trobe Univ, Bundoora, Vic 3086, Australia
关键词
Ransomware; Entropy; Encryption; File integrity;
D O I
10.1007/978-3-030-36802-9_20
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Many state-of-the-art anti-ransomware implementations monitoring file system activities choose to monitor file entropy-based changes to determine whether the changes may have been committed by ransomware, or to distinguish between compression and encryption operations. However, such detections can be victims of spoofing attacks, when attackers manipulate the entropy values in the expected range during the attacks. This paper explored the limitations of entropy-based ransomware detection on several different file types. We demonstrated how to use Base64-Encoding and Distributed Non-Selective Partial Encryption to manipulate entropy values and to bypass current entropy-based detection mechanisms. By exploiting this vulnerability, attackers can avoid entropy-based detection or degrade detection performance. We recommended that the practice of relying on file entropy change thresholds to detect ransomware encryption should be deprecated.
引用
收藏
页码:181 / 189
页数:9
相关论文
共 50 条
  • [31] RELATIONAL ENTROPY-BASED SALIENCY DETECTION IN IMAGES AND VIDEOS
    Duncan, Kester
    Sarkar, Sudeep
    2012 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP 2012), 2012, : 1093 - 1096
  • [32] Decentralized detection: Optimizing with Bayes' or entropy-based criterion?
    Pomorski, D
    FUSION 2003: PROCEEDINGS OF THE SIXTH INTERNATIONAL CONFERENCE OF INFORMATION FUSION, VOLS 1 AND 2, 2003, : 894 - 901
  • [33] Entropy-Based Detection of Genetic Markers for Bacteria Genotyping
    Nykrynova, Marketa
    Maderankova, Denisa
    Barton, Vojtech
    Bezdicek, Matej
    Lengerova, Martina
    Skutkova, Helena
    BIOINFORMATICS AND BIOMEDICAL ENGINEERING (IWBBIO 2019), PT II, 2019, 11466 : 177 - 188
  • [34] An Empirical Evaluation of Entropy-based Traffic Anomaly Detection
    Nychis, George
    Sekar, Vyas
    Andersen, David G.
    Kim, Hyong
    Zhang, Hui
    IMC'08: PROCEEDINGS OF THE 2008 ACM SIGCOMM INTERNET MEASUREMENT CONFERENCE, 2008, : 151 - 156
  • [35] Entropy-based thresholding for detection of microcalcifications in a digital mammogram
    Bhajammanavar, VM
    Keong, KC
    Krishnan, SM
    CARS 2000: COMPUTER ASSISTED RADIOLOGY AND SURGERY, 2000, 1214 : 735 - 740
  • [36] Entropy-based concept drift detection in information systems
    Sun, Yingying
    Mi, Jusheng
    Jin, Chenxia
    KNOWLEDGE-BASED SYSTEMS, 2024, 290
  • [37] Entropy-Based Feature Selection for Network Anomaly Detection
    Alabi, Ruth
    Yurtkan, Kamil
    2018 2ND INTERNATIONAL SYMPOSIUM ON MULTIDISCIPLINARY STUDIES AND INNOVATIVE TECHNOLOGIES (ISMSIT), 2018, : 563 - 569
  • [38] Ransomware detection method based on context-aware entropy analysis
    Sangmoon Jung
    Yoojae Won
    Soft Computing, 2018, 22 : 6731 - 6740
  • [39] Ransomware detection method based on context-aware entropy analysis
    Jung, Sangmoon
    Won, Yoojae
    SOFT COMPUTING, 2018, 22 (20) : 6731 - 6740
  • [40] Entropy-based False Detection Filtering in Spoken Term Detection Tasks
    Natori, Satoshi
    Furuya, Yuto
    Nishizaki, Thromitsu
    Sekiguchi, Yoshihiro
    2013 ASIA-PACIFIC SIGNAL AND INFORMATION PROCESSING ASSOCIATION ANNUAL SUMMIT AND CONFERENCE (APSIPA), 2013,