Real-time open-file backup system with machine-learning detection model for ransomware

被引:0
|
作者
Higuchi, Kosuke [1 ]
Kobayashi, Ryotaro [1 ]
机构
[1] Kogakuin Univ, 1-24-2 Nishi Shinjuku,Shinjuku Ku, Tokyo, Japan
基金
日本学术振兴会;
关键词
Backup system; File prevention; Machine learning; Ransomware detection; eBPF;
D O I
10.1007/s10207-024-00966-1
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The recent rapid increase in ransomware attacks has heightened threat levels for various targets, including critical infrastructure. Traditional signature-based detection methods are effective against known ransomware but struggle to address unknown and obfuscated attacks. Furthermore, in current machine-learning-based detection approaches, files are at risk of encryption during the detection time, i.e., the time taken from detection of the ransomware to its termination. In response to these issues, this study proposes the Real-time Open-File Backup System (ROFBS), which aims to minimize encryption damage by performing immediate backups upon file opening detection. We conduct three experiments to evaluate the effectiveness of ROFBS. First, we measure the backup ratio during ransomware attacks and find consistently high backup rates for ROFBS. Second, we analyze detection time trends and find that longer detection times correlate with an increase in encrypted files. Third, we measure central processing unit, memory, and disk input/output usage. Results indicate that the impact of ROFBS on normal system performance is minimal. These experiments not only quantitatively demonstrate the effectiveness of ROFBS but also highlight the importance of considering detection time in future research. The results of this study suggest that ROFBS can enhance defense against ransomware attacks and ensure data security.
引用
收藏
页数:21
相关论文
共 50 条
  • [1] Machine Learning Based File Entropy Analysis for Ransomware Detection in Backup Systems
    Lee, Kyungroul
    Lee, Sun-Young
    Yim, Kangbin
    IEEE ACCESS, 2019, 7 : 110205 - 110215
  • [2] Real-time Biosignal Recording and Machine-Learning Analysis System
    Li, Hanrui
    Wang, Junzhe
    Zhao, Shiqi
    Tian, Fengshi
    Yang, Jie
    Sawan, Mohamad
    2022 IEEE INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE CIRCUITS AND SYSTEMS (AICAS 2022): INTELLIGENT TECHNOLOGY IN THE POST-PANDEMIC ERA, 2022, : 427 - 430
  • [3] Real-time bot infection detection system using DNS fingerprinting and machine-learning
    Quezada, Vicente
    Astudillo-Salinas, Fabian
    Tello-Oquendo, Luis
    Bernal, Paul
    COMPUTER NETWORKS, 2023, 228
  • [4] Real-Time Implementation of Machine-Learning DSP
    Borjeson, Erik
    Liu, Keren
    Hager, Christian
    Larsson-Edefors, Per
    2024 OPTICAL FIBER COMMUNICATIONS CONFERENCE AND EXHIBITION, OFC, 2024,
  • [5] Real-time condition monitoring and fault detection of components based on machine-learning reconstruction model
    Yang, Chunzhen
    Liu, Jingquan
    Zeng, Yuyun
    Xie, Guangyao
    RENEWABLE ENERGY, 2019, 133 : 433 - 441
  • [6] Automated real-time anomaly detection of temperature sensors through machine-learning
    Nayak, Debanjana
    Perros, Harry
    INTERNATIONAL JOURNAL OF SENSOR NETWORKS, 2020, 34 (03) : 137 - 152
  • [7] Machine-Learning Based Automatic and Real-time Detection of Mouse Scratching Behaviors
    Park, Ingyu
    Lee, Kyeongho
    Bishayee, Kausik
    Jeon, Hong Jin
    Lee, Hyosang
    Lee, Unjoo
    EXPERIMENTAL NEUROBIOLOGY, 2019, 28 (01) : 54 - 61
  • [8] Real-time system call-based ransomware detection
    Chew, Christopher Jun Wen
    Kumar, Vimal
    Patros, Panos
    Malik, Robi
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2024, 23 (03) : 1839 - 1858
  • [9] RWGuard: A Real-Time Detection System Against Cryptographic Ransomware
    Mehnaz, Shagufta
    Mudgerikar, Anand
    Bertino, Elisa
    RESEARCH IN ATTACKS, INTRUSIONS, AND DEFENSES, RAID 2018, 2018, 11050 : 114 - 136
  • [10] A Hybrid Machine-Learning Ensemble for Anomaly Detection in Real-Time Industry 4.0 Systems
    Velasquez, David
    Perez, Enrique
    Oregui, Xabier
    Artetxe, Arkaitz
    Manteca, Jorge
    Mansilla, Jordi Escayola
    Toro, Mauricio
    Maiza, Mikel
    Sierra, Basilio
    IEEE ACCESS, 2022, 10 : 72024 - 72036