YARAMON: A Memory-based Detection Framework for Ransomware Families

被引:0
|
作者
Medhat, May [2 ]
Essa, Menna [2 ]
Faisal, Hend [2 ]
Sayed, Samir G. [1 ,2 ]
机构
[1] Helwan Univ, Dept Elect & Commun, Cairo, Egypt
[2] EG CERT, NTRA, Dept Malware Anal, Giza, Egypt
关键词
Ransomware; Hybrid Analysis; YARA-based Detection;
D O I
10.23919/ICITST51030.2020.9351319
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Ransomware attacks have evolved to become more sophisticated, persistent and irreversible. In 2019, many high profile ransomware developers extorted high-value entities for money by encrypting their data and deleting any backup files. Once a system is infected with a crypto-ransomware attack, it will be tough to recover the victim's data unless a backup is available or the malware author shares the decryption key with the victim. Moreover, ransomware developers nowadays adopt new tactics and techniques to spread and evade detection. One of those techniques is packing in order to enhance their defensive mechanisms to avoid detection. This paper suggests a hybrid approach to detect packed ransomware samples based on scanning process memory dumps and dropped executable files using enhanced YARA rules framework. Through describing common ransomware artifacts using YARA rules, upon testing, the detection rate reached 97.9% of dumped files.
引用
收藏
页码:114 / 119
页数:6
相关论文
共 50 条
  • [11] A Framework for Supporting Ransomware Detection and Prevention Based on Hybrid Analysis
    Cuzzocrea, Alfredo
    Mercaldo, Francesco
    Martinelli, Fabio
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS, ICCSA 2021, PT III, 2021, 12951 : 16 - 27
  • [12] Ransomware Detection using Process Memory
    Singh, Avinash
    Ikuesan, Richard Adeyemi
    Venter, Hein
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2022), 2022, : 413 - 422
  • [13] Involvement of memory-based change detection in visual distraction
    Kimura, Motohiro
    Katayama, Jun'ichi
    Murohashi, Harumitsu
    PSYCHOPHYSIOLOGY, 2007, 44 : S98 - S98
  • [14] ARdetector: android ransomware detection framework
    Dan Li
    Wenbo Shi
    Ning Lu
    Sang-Su Lee
    Sokjoon Lee
    The Journal of Supercomputing, 2024, 80 : 7557 - 7584
  • [16] Personality- and Memory-based framework for Emotionally Intelligent agents
    Nardelli, Alice
    Maccagni, Giacomo
    Minutoli, Federico
    Sgorbissa, Antonio
    Recchiuto, Carmine Tommaso
    2024 33RD IEEE INTERNATIONAL CONFERENCE ON ROBOT AND HUMAN INTERACTIVE COMMUNICATION, ROMAN 2024, 2024, : 769 - 776
  • [17] A Scalable Memory-Based Reconfigurable Computing Framework for Nanoscale Crossbar
    Paul, Somnath
    Bhunia, Swarup
    IEEE TRANSACTIONS ON NANOTECHNOLOGY, 2012, 11 (03) : 451 - 462
  • [18] ARdetector: android ransomware detection framework
    Li, Dan
    Shi, Wenbo
    Lu, Ning
    Lee, Sang-Su
    Lee, Sokjoon
    JOURNAL OF SUPERCOMPUTING, 2024, 80 (06): : 7557 - 7584
  • [19] MHDFS: A Memory-Based Hadoop Framework for Large Data Storage
    Song, Aibo
    Zhao, Maoxian
    Xue, Yingying
    Luo, Junzhou
    SCIENTIFIC PROGRAMMING, 2016, 2016
  • [20] A Memory-Based Label Propagation Algorithm for Community Detection
    Fiscarelli, Antonio Maria
    Brust, Matthias R.
    Danoy, Gregoire
    Bouvry, Pascal
    COMPLEX NETWORKS AND THEIR APPLICATIONS VII, VOL 1, 2019, 812 : 171 - 182