RWArmor: a static-informed dynamic analysis approach for early detection of cryptographic windows ransomware

被引:0
|
作者
Md. Ahsan Ayub
Ambareen Siraj
Bobby Filar
Maanak Gupta
机构
[1] Tennessee Tech University,Department of Computer Science
[2] Sublime Security,undefined
[3] Inc.,undefined
关键词
Dynamic Analysis; Machine Learning; Ransomware; Static Analysis;
D O I
暂无
中图分类号
学科分类号
摘要
Ransomware attacks have captured news headlines worldwide for the last few years due to their criticality and intensity. Ransomware-as-a-service (RaaS) kits are aiding adversaries to launch such powerful attacks with little to no technical knowledge. Eventually, with the successful progression of ransomware attacks, organizations suffer financial loss, and their proprietary-based sensitive digital assets end up on the dark web for sale. Due to the severity of this situation, security researchers are seen to conduct static and dynamic analysis research for ransomware research. Both analyses have advantages and disadvantages, and prompt ransomware detection is expected to stop the irreversible encryption process. This research proposes a novel static-informed dynamic analysis approach, RWArmor, which includes the knowledge of the already-trained machine learning models based on static features to improve the ransomware detection capabilities during dynamic analysis. The effectiveness of our approach is evaluated by predicting a novel/unknown ransomware between 30 and 120 seconds of its execution. The random forest algorithm is utilized to accomplish this task and tested against 215 active cryptographic Windows ransomware collected between 2014 and 2022. Based on our empirical findings, our method achieves 97.67%, 92.38%, and 86.42% accuracy within 120, 60, and 30 seconds of behavioral logs, respectively.
引用
收藏
页码:533 / 556
页数:23
相关论文
共 50 条
  • [41] An approach for mapping features to code based on static and dynamic analysis
    Rohatgi, Abhishek
    Hamou-Lhadj, Abdelwahab
    Rilling, Juergen
    PROCEEDINGS OF THE 16TH IEEE INTERNATIONAL CONFERENCE ON PROGRAM COMPREHENSION, 2008, : 234 - 239
  • [42] EARLY DETECTION OF FAILURES BY ANALYSIS OF DYNAMIC SIGNALS
    LIEWERS, P
    KERNENERGIE, 1984, 27 (02): : 58 - 66
  • [43] Deep Learning of Static and Dynamic Brain Functional Networks for Early MCI Detection
    Kam, Tae-Eui
    Zhang, Han
    Jiao, Zhicheng
    Shen, Dinggang
    IEEE TRANSACTIONS ON MEDICAL IMAGING, 2020, 39 (02) : 478 - 487
  • [44] A Static Analysis Approach to Data Race Detection in SystemC Designs
    Moiseev, Mikhail
    Glukhikh, Mikhail
    Zakharov, Alexey
    Richter, Harald
    PROCEEDINGS OF THE 2013 IEEE 16TH INTERNATIONAL SYMPOSIUM ON DESIGN AND DIAGNOSTICS OF ELECTRONIC CIRCUITS & SYSTEMS (DDECS), 2013, : 54 - 59
  • [45] DeDroid: A Mobile Botnet Detection Approach Based on Static Analysis
    Karim, Ahmad
    Salleh, Rosli
    Shah, Syed Adeel Ali
    IEEE 12TH INT CONF UBIQUITOUS INTELLIGENCE & COMP/IEEE 12TH INT CONF ADV & TRUSTED COMP/IEEE 15TH INT CONF SCALABLE COMP & COMMUN/IEEE INT CONF CLOUD & BIG DATA COMP/IEEE INT CONF INTERNET PEOPLE AND ASSOCIATED SYMPOSIA/WORKSHOPS, 2015, : 1327 - 1332
  • [46] A Modular Static Analysis Approach to Affine Loop Invariants Detection
    Ancourt, Corinne
    Coelho, Fabien
    Irigoin, Francois
    ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2010, 267 (01) : 3 - 16
  • [47] Novel physics-informed neural network approach for dynamic and static displacement reconstruction via strain and acceleration
    Xu, Kaikai
    Wang, Qiangyong
    Yang, Xuesong
    Ding, Ding
    Zhao, Zifeng
    Hu, Zhicheng
    Wang, Xuelin
    MEASUREMENT, 2024, 231
  • [48] Efficient Flame Detection Based on Static and Dynamic Texture Analysis in Forest Fire Detection
    C. Emmy Prema
    S. S. Vinsley
    S. Suresh
    Fire Technology, 2018, 54 : 255 - 288
  • [49] Efficient Flame Detection Based on Static and Dynamic Texture Analysis in Forest Fire Detection
    Prema, C. Emmy
    Vinsley, S. S.
    Suresh, S.
    FIRE TECHNOLOGY, 2018, 54 (01) : 255 - 288
  • [50] Fault Localization for Novice Programs Combining Static Analysis and Dynamic Detection
    Wan, Han
    Nie, Wenhao
    Yue, Shiyang
    Luo, Xiaoyan
    2024 IEEE 48TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE, COMPSAC 2024, 2024, : 94 - 102