YARAMON: A Memory-based Detection Framework for Ransomware Families

被引:0
|
作者
Medhat, May [2 ]
Essa, Menna [2 ]
Faisal, Hend [2 ]
Sayed, Samir G. [1 ,2 ]
机构
[1] Helwan Univ, Dept Elect & Commun, Cairo, Egypt
[2] EG CERT, NTRA, Dept Malware Anal, Giza, Egypt
关键词
Ransomware; Hybrid Analysis; YARA-based Detection;
D O I
10.23919/ICITST51030.2020.9351319
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Ransomware attacks have evolved to become more sophisticated, persistent and irreversible. In 2019, many high profile ransomware developers extorted high-value entities for money by encrypting their data and deleting any backup files. Once a system is infected with a crypto-ransomware attack, it will be tough to recover the victim's data unless a backup is available or the malware author shares the decryption key with the victim. Moreover, ransomware developers nowadays adopt new tactics and techniques to spread and evade detection. One of those techniques is packing in order to enhance their defensive mechanisms to avoid detection. This paper suggests a hybrid approach to detect packed ransomware samples based on scanning process memory dumps and dropped executable files using enhanced YARA rules framework. Through describing common ransomware artifacts using YARA rules, upon testing, the detection rate reached 97.9% of dumped files.
引用
收藏
页码:114 / 119
页数:6
相关论文
共 50 条
  • [41] Deep rhythm and long short term memory-based drowsiness detection
    Turkoglu, Muammer
    Alcin, Omer F.
    Aslan, Muzaffer
    Al-Zebari, Adel
    Sengur, Abdulkadir
    BIOMEDICAL SIGNAL PROCESSING AND CONTROL, 2021, 65
  • [42] Memory-Based Lyapunov Functions and Path-complete Framework: Equivalence and Properties
    Della Rossa, Matteo
    Jungers, Raphael M.
    2022 10TH INTERNATIONAL CONFERENCE ON SYSTEMS AND CONTROL (ICSC), 2022, : 12 - 17
  • [43] Memory-based stochastic optimization
    Moore, AW
    Schneider, J
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 8: PROCEEDINGS OF THE 1995 CONFERENCE, 1996, 8 : 1066 - 1072
  • [44] Learning by reusing previous advice: a memory-based teacher-student framework
    Zhu, Changxi
    Cai, Yi
    Hu, Shuyue
    Leung, Ho-fung
    Chiu, Dickson K. W.
    AUTONOMOUS AGENTS AND MULTI-AGENT SYSTEMS, 2023, 37 (01)
  • [45] Memory-based label propagation algorithm for community detection in social networks
    Hosseini, Razieh
    Azmi, Reza
    2015 INTERNATIONAL SYMPOSIUM ON ARTIFICIAL INTELLIGENCE AND SIGNAL PROCESSING (AISP), 2015, : 256 - 260
  • [46] A long short-term memory-based framework for crash detection on freeways with traffic data of different temporal resolutions
    Jiang, Feifeng
    Yuen, Kwok Kit Richard
    Lee, Eric Wai Ming
    ACCIDENT ANALYSIS AND PREVENTION, 2020, 141
  • [47] Memory-based shallow parsing
    Sang, EFTK
    JOURNAL OF MACHINE LEARNING RESEARCH, 2002, 2 (04) : 559 - 594
  • [48] Memory-based modes of presentation
    Recanati, Francois
    SYNTHESE, 2024, 203 (04)
  • [49] Cell memory-based therapy
    Anjamrooz, Seyed Hadi
    JOURNAL OF CELLULAR AND MOLECULAR MEDICINE, 2015, 19 (11) : 2682 - 2689
  • [50] Memory-Based Sequential Attention
    Stock, Jason
    Anderson, Charles
    GAZE MEETS MACHINE LEARNING WORKSHOP, 2023, 226 : 236 - 252