YARAMON: A Memory-based Detection Framework for Ransomware Families

被引:0
|
作者
Medhat, May [2 ]
Essa, Menna [2 ]
Faisal, Hend [2 ]
Sayed, Samir G. [1 ,2 ]
机构
[1] Helwan Univ, Dept Elect & Commun, Cairo, Egypt
[2] EG CERT, NTRA, Dept Malware Anal, Giza, Egypt
关键词
Ransomware; Hybrid Analysis; YARA-based Detection;
D O I
10.23919/ICITST51030.2020.9351319
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Ransomware attacks have evolved to become more sophisticated, persistent and irreversible. In 2019, many high profile ransomware developers extorted high-value entities for money by encrypting their data and deleting any backup files. Once a system is infected with a crypto-ransomware attack, it will be tough to recover the victim's data unless a backup is available or the malware author shares the decryption key with the victim. Moreover, ransomware developers nowadays adopt new tactics and techniques to spread and evade detection. One of those techniques is packing in order to enhance their defensive mechanisms to avoid detection. This paper suggests a hybrid approach to detect packed ransomware samples based on scanning process memory dumps and dropped executable files using enhanced YARA rules framework. Through describing common ransomware artifacts using YARA rules, upon testing, the detection rate reached 97.9% of dumped files.
引用
收藏
页码:114 / 119
页数:6
相关论文
共 50 条
  • [31] A long short-term memory-based encoder-decoder framework for discharge waveform anomaly detection
    Shen, Wenwen
    Li, Suicheng
    He, Zizhou
    Chen, Youxin
    RADIATION DETECTION TECHNOLOGY AND METHODS, 2025, 9 (01) : 17 - 24
  • [32] An Ensemble-based Supervised Machine Learning Framework for Android Ransomware Detection
    Sharma, Shweta
    Challa, Rama Krishna
    Kumar, Rakesh
    INTERNATIONAL ARAB JOURNAL OF INFORMATION TECHNOLOGY, 2021, 18 (3A) : 422 - 429
  • [33] A THEORY FOR MEMORY-BASED LEARNING
    LIN, JH
    VITTER, JS
    MACHINE LEARNING, 1994, 17 (2-3) : 143 - 167
  • [34] Digital memory-based predistortion
    McBeath, S
    Pinckley, D
    2005 IEEE MTT-S INTERNATIONAL MICROWAVE SYMPOSIUM, VOLS 1-4, 2005, : 2055 - 2058
  • [35] The scope of memory-based processing
    Gerrig, RJ
    O'Brien, EJ
    DISCOURSE PROCESSES, 2005, 39 (2-3) : 225 - 242
  • [36] A MEMORY-BASED APPROACH TO NAVIGATION
    CRESPI, B
    FURLANELLO, C
    STRINGA, L
    BIOLOGICAL CYBERNETICS, 1993, 69 (5-6) : 385 - 393
  • [37] Memory-Based Semantic Parsing
    Jain, Parag
    Lapata, Mirella
    TRANSACTIONS OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS, 2021, 9 : 1197 - 1212
  • [38] Memory-based language processing
    Millett, Ronald P.
    JOURNAL OF QUANTITATIVE LINGUISTICS, 2008, 15 (02) : 212 - 219
  • [39] Accurate object detection using memory-based models in surveillance scenes
    Li, Xudong
    Ye, Mao
    Liu, Yiguang
    Zhang, Feng
    Liu, Dan
    Tang, Song
    PATTERN RECOGNITION, 2017, 67 : 73 - 84
  • [40] Memory-based algorithms for abrupt change detection in sensor data streams
    Nikovski, Daniel
    Jain, Ankur
    2007 5TH IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL INFORMATICS, VOLS 1-3, 2007, : 547 - 552