RWArmor: a static-informed dynamic analysis approach for early detection of cryptographic windows ransomware

被引:0
|
作者
Md. Ahsan Ayub
Ambareen Siraj
Bobby Filar
Maanak Gupta
机构
[1] Tennessee Tech University,Department of Computer Science
[2] Sublime Security,undefined
[3] Inc.,undefined
关键词
Dynamic Analysis; Machine Learning; Ransomware; Static Analysis;
D O I
暂无
中图分类号
学科分类号
摘要
Ransomware attacks have captured news headlines worldwide for the last few years due to their criticality and intensity. Ransomware-as-a-service (RaaS) kits are aiding adversaries to launch such powerful attacks with little to no technical knowledge. Eventually, with the successful progression of ransomware attacks, organizations suffer financial loss, and their proprietary-based sensitive digital assets end up on the dark web for sale. Due to the severity of this situation, security researchers are seen to conduct static and dynamic analysis research for ransomware research. Both analyses have advantages and disadvantages, and prompt ransomware detection is expected to stop the irreversible encryption process. This research proposes a novel static-informed dynamic analysis approach, RWArmor, which includes the knowledge of the already-trained machine learning models based on static features to improve the ransomware detection capabilities during dynamic analysis. The effectiveness of our approach is evaluated by predicting a novel/unknown ransomware between 30 and 120 seconds of its execution. The random forest algorithm is utilized to accomplish this task and tested against 215 active cryptographic Windows ransomware collected between 2014 and 2022. Based on our empirical findings, our method achieves 97.67%, 92.38%, and 86.42% accuracy within 120, 60, and 30 seconds of behavioral logs, respectively.
引用
收藏
页码:533 / 556
页数:23
相关论文
共 50 条
  • [31] Detection of Android Malware: Combined with Static Analysis and. Dynamic Analysis
    Su, Ming-Yang
    Fung, Kek-Tung
    Huang, Yu-Hao
    Kang, Ming-Zhi
    Chung, Yen-Heng
    2016 INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING & SIMULATION (HPCS 2016), 2016, : 1013 - 1018
  • [32] ReDoSHunter: A Combined Static and Dynamic Approach for Regular Expression DoS Detection
    Li, Yeting
    Chen, Zixuan
    Cao, Jialun
    Xu, Zhiwu
    Peng, Qiancheng
    Chen, Haiming
    Chen, Liyuan
    Cheung, Shing-Chi
    PROCEEDINGS OF THE 30TH USENIX SECURITY SYMPOSIUM, 2021, : 3847 - 3864
  • [33] A Research of Virus Detection Combined Dynamic and Static Analysis Methods
    Miao, Chunyu
    Chen, Lina
    SPORTS MATERIALS, MODELLING AND SIMULATION, 2011, 187 : 625 - +
  • [34] Software Vulnerability Detection Methodology Combined with Static and Dynamic Analysis
    Seokmo Kim
    R. Young Chul Kim
    Young B. Park
    Wireless Personal Communications, 2016, 89 : 777 - 793
  • [35] Software Vulnerability Detection Methodology Combined with Static and Dynamic Analysis
    Kim, Seokmo
    Kim, R. Young Chul
    Park, Young B.
    WIRELESS PERSONAL COMMUNICATIONS, 2016, 89 (03) : 777 - 793
  • [36] Random Early Dynamic Detection Approach for Congestion Control
    Abdel-Jaber, Hussein
    Thabtah, Fadi
    Woodward, Mike
    Jaffar, Ahmad
    Al Bazar, Hussein
    BALTIC JOURNAL OF MODERN COMPUTING, 2014, 2 (01): : 16 - 31
  • [37] HEAT: An integrated static and dynamic approach for thread escape analysis
    Department of Computer Science, University of Wyoming, United States
    不详
    Proc Int Comput Software Appl Conf, 1600, (142-147):
  • [38] A NUMERICAL APPROACH FOR STATIC AND DYNAMIC ANALYSIS OF DEFORMABLE JOURNAL BEARINGS
    Benasciutti, Denis
    Munteanu, Mircea Gh.
    Flumian, Fabio
    COMPUTATIONAL METHODS FOR COUPLED PROBLEMS IN SCIENCE AND ENGINEERING V, 2013, : 609 - 620
  • [39] HEAT: An Integrated Static and Dynamic Approach for Thread Escape Analysis
    Chen, Qichang
    Wang, Liqiang
    Yang, Zijiang
    2009 IEEE 33RD INTERNATIONAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE, VOLS 1 AND 2, 2009, : 142 - +
  • [40] Analysis of internal rate of return on investments: Dynamic and static approach
    Maric, Branislav
    Ivanisevic, Andrea
    Mitrovic, Slavica
    Aleksic, Sreto
    Rovcanin, Mihailo
    AFRICAN JOURNAL OF BUSINESS MANAGEMENT, 2011, 5 (08): : 3269 - 3273