RWArmor: a static-informed dynamic analysis approach for early detection of cryptographic windows ransomware

被引:0
|
作者
Md. Ahsan Ayub
Ambareen Siraj
Bobby Filar
Maanak Gupta
机构
[1] Tennessee Tech University,Department of Computer Science
[2] Sublime Security,undefined
[3] Inc.,undefined
关键词
Dynamic Analysis; Machine Learning; Ransomware; Static Analysis;
D O I
暂无
中图分类号
学科分类号
摘要
Ransomware attacks have captured news headlines worldwide for the last few years due to their criticality and intensity. Ransomware-as-a-service (RaaS) kits are aiding adversaries to launch such powerful attacks with little to no technical knowledge. Eventually, with the successful progression of ransomware attacks, organizations suffer financial loss, and their proprietary-based sensitive digital assets end up on the dark web for sale. Due to the severity of this situation, security researchers are seen to conduct static and dynamic analysis research for ransomware research. Both analyses have advantages and disadvantages, and prompt ransomware detection is expected to stop the irreversible encryption process. This research proposes a novel static-informed dynamic analysis approach, RWArmor, which includes the knowledge of the already-trained machine learning models based on static features to improve the ransomware detection capabilities during dynamic analysis. The effectiveness of our approach is evaluated by predicting a novel/unknown ransomware between 30 and 120 seconds of its execution. The random forest algorithm is utilized to accomplish this task and tested against 215 active cryptographic Windows ransomware collected between 2014 and 2022. Based on our empirical findings, our method achieves 97.67%, 92.38%, and 86.42% accuracy within 120, 60, and 30 seconds of behavioral logs, respectively.
引用
收藏
页码:533 / 556
页数:23
相关论文
共 50 条
  • [1] RWArmor: a static-informed dynamic analysis approach for early detection of cryptographic windows ransomware
    Ayub, Md. Ahsan
    Siraj, Ambareen
    Filar, Bobby
    Gupta, Maanak
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2024, 23 (01) : 533 - 556
  • [2] Static-RWArmor: A Static Analysis Approach for Prevention of Cryptographic Windows Ransomware
    Ayub, Md Ahsan
    Siraj, Ambareen
    Filar, Bobby
    Gupta, Maanak
    2023 IEEE 22ND INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS, TRUSTCOM, BIGDATASE, CSE, EUC, ISCI 2023, 2024, : 1673 - 1680
  • [3] RansomGuard: a framework for proactive detection and mitigation of cryptographic windows ransomware
    Alvi, M. Adnan
    Jalil, Zunera
    JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES, 2024, 20 (04): : 867 - 884
  • [4] A Holistic Approach to Ransomware Classification: Leveraging Static and Dynamic Analysis with Visualization
    Yamany, Bahaa
    Elsayed, Mahmoud Said
    Jurcut, Anca D.
    Abdelbaki, Nashwa
    Azer, Marianne A.
    INFORMATION, 2024, 15 (01)
  • [5] Forensic Analysis of Ransomware Families using Static and Dynamic Analysis
    Subedi, Kul Prasad
    Budhathoki, Daya Ram
    Dasgupta, Dipankar
    2018 IEEE SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (SPW 2018), 2018, : 180 - 185
  • [6] Static and Dynamic Analysis of Third Generation Cerber Ransomware
    Kara, Ilker
    Aydos, Murat
    2018 INTERNATIONAL CONGRESS ON BIG DATA, DEEP LEARNING AND FIGHTING CYBER TERRORISM (IBIGDELFT), 2018, : 12 - 17
  • [7] A Denotational Approach to the Static Analysis of Cryptographic Processes
    Aziz, Benjamin
    Hamilton, Geoff W.
    Gray, David
    ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2005, 118 : 19 - 36
  • [8] A static analysis of cryptographic processes: the denotational approach
    Aziz, B
    Hamilton, G
    Gray, D
    JOURNAL OF LOGIC AND ALGEBRAIC PROGRAMMING, 2005, 64 (02): : 285 - 320
  • [9] Comparative Analysis of Botnet and Ransomware for Early Detection
    Honnavalli B, Prasad
    Sushma, Ethadi
    Rao, Aditya
    Girimaji, Varun
    Girimaji, Vrinda
    Katta, Achyuta
    INTERNET OF THINGS, SMART SPACES, AND NEXT GENERATION NETWORKS AND SYSTEMS, PT I, NEW2AN 2023, RUSMART 2023, 2024, 14542 : 296 - 308
  • [10] Ransomware early detection by the analysis of file sharing traffic
    Morato, Daniel
    Berrueta, Eduardo
    Magana, Eduardo
    Izal, Mikel
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2018, 124 : 14 - 32