YARAMON: A Memory-based Detection Framework for Ransomware Families

被引:0
|
作者
Medhat, May [2 ]
Essa, Menna [2 ]
Faisal, Hend [2 ]
Sayed, Samir G. [1 ,2 ]
机构
[1] Helwan Univ, Dept Elect & Commun, Cairo, Egypt
[2] EG CERT, NTRA, Dept Malware Anal, Giza, Egypt
关键词
Ransomware; Hybrid Analysis; YARA-based Detection;
D O I
10.23919/ICITST51030.2020.9351319
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Ransomware attacks have evolved to become more sophisticated, persistent and irreversible. In 2019, many high profile ransomware developers extorted high-value entities for money by encrypting their data and deleting any backup files. Once a system is infected with a crypto-ransomware attack, it will be tough to recover the victim's data unless a backup is available or the malware author shares the decryption key with the victim. Moreover, ransomware developers nowadays adopt new tactics and techniques to spread and evade detection. One of those techniques is packing in order to enhance their defensive mechanisms to avoid detection. This paper suggests a hybrid approach to detect packed ransomware samples based on scanning process memory dumps and dropped executable files using enhanced YARA rules framework. Through describing common ransomware artifacts using YARA rules, upon testing, the detection rate reached 97.9% of dumped files.
引用
收藏
页码:114 / 119
页数:6
相关论文
共 50 条
  • [21] MEMORY-BASED PEDESTRIAN DETECTION THROUGH SEQUENCE LEARNING
    Li, Xudong
    Ye, Mao
    Liu, Yiguang
    Zhu, Ce
    2017 IEEE INTERNATIONAL CONFERENCE ON MULTIMEDIA AND EXPO (ICME), 2017, : 1129 - 1134
  • [22] Automatic memory-based detection of changes in sound duration
    Jacobsen, T
    Schroger, E
    JOURNAL OF COGNITIVE NEUROSCIENCE, 2002, : 85 - 85
  • [23] MEMORY-BASED PARSING
    LEBOWITZ, M
    ARTIFICIAL INTELLIGENCE, 1983, 21 (04) : 363 - 404
  • [24] Learning by reusing previous advice: a memory-based teacher–student framework
    Changxi Zhu
    Yi Cai
    Shuyue Hu
    Ho-fung Leung
    Dickson K. W. Chiu
    Autonomous Agents and Multi-Agent Systems, 2023, 37
  • [25] A Memory-based Multiagent Framework for Adaptive Decision Making Extended Abstract
    Khadka, Shauharda
    Yates, Connor
    Tumer, Kagan
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AUTONOMOUS AGENTS AND MULTIAGENT SYSTEMS (AAMAS' 18), 2018, : 1977 - 1979
  • [26] Nonlinear clutter cancellation and detection using a memory-based predictor
    Defence Research Establishment, Ottawa, Ottawa, Canada
    IEEE Trans Aerosp Electron Syst, 4 (1249-1256):
  • [27] Memory-based detection of task-irrelevant visual changes
    Czigler, I
    Balázs, L
    Winkler, I
    PSYCHOPHYSIOLOGY, 2002, 39 (06) : 869 - 873
  • [28] Pacing Electrocardiogram Detection With Memory-Based Autoencoder and Metric Learning
    Ge, Zhaoyang
    Cheng, Huiqing
    Tong, Zhuang
    Yang, Lihong
    Zhou, Bing
    Wang, Zongmin
    FRONTIERS IN PHYSIOLOGY, 2021, 12
  • [29] Nonlinear clutter cancellation and detection using a memory-based predictor
    Leung, H
    IEEE TRANSACTIONS ON AEROSPACE AND ELECTRONIC SYSTEMS, 1996, 32 (04) : 1249 - 1256
  • [30] AI-Powered Ransomware Detection Framework
    Poudyal, Subash
    Dasgupta, Dipankar
    2020 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (SSCI), 2020, : 1154 - 1161