Mitigating adversarial evasion attacks of ransomware using ensemble learning

被引:29
作者
Ahmed, Usman [1 ]
Lin, Jerry Chun-Wei [1 ]
Srivastava, Gautam [2 ,3 ]
机构
[1] Western Norway Univ Appl Sci, Dept Comp Sci Elect Engn & Math Sci, N-5063 Bergen, Norway
[2] Brandon Univ, Dept Math & Comp Sci, Brandon, MB, Canada
[3] China Med Univ, Res Ctr Interneural Comp, Taichung, Taiwan
关键词
Android ransomware; Adversarial evasion attacks; Machine learning-based ensemble analysis; Attack mitigation; Ransomware detection; MALWARE CLASSIFICATION;
D O I
10.1016/j.compeleceng.2022.107903
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Ransomware continues to pose a significant threat to cybersecurity by extorting money from users by locking their devices and personal data. The attackers force the payment of a ransom in order to restore access to personal files. Because of the structural similarity, detection of ransomware and benign applications becomes vulnerable to evasion attacks. Ensemble learning can provide countermeasures, while attackers can use the same technique to improve the effectiveness of their respective attacks. This motivates us to investigate whether the distinct ensemble method can achieve better performance when combined with the votingbased method. This research proposes a hybrid approach that examines permissions, text, and network-based features both statically and dynamically by monitoring memory usage, system call logs, and CPU usage. Ensemble machine learning analyzers on static and dynamic features extracted from Android malware applications (ransomware and non-ransomware) are then trained in the designed model. Our experimental results show that the proposed ensemble classification and detection technique can classify unknown static and dynamic ransomware behavior to mitigate adversarial evasion attacks.
引用
收藏
页数:14
相关论文
共 25 条
  • [11] DNA-Droid: A Real-Time Android Ransomware Detection Framework
    Gharib, Amirhossein
    Ghorbani, Ali
    [J]. NETWORK AND SYSTEM SECURITY, 2017, 10394 : 184 - 198
  • [12] Adversarial Deep Ensemble: Evasion Attacks and Defenses for Malware Detection
    Li, Deqiang
    Li, Qianmu
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 : 3886 - 3900
  • [13] Mahindru A, 2020, JOURNEY BIOINSPIRED, V185, P103
  • [14] Mathur A, J INFORM SECUR APPL, V58
  • [15] Ransomware Steals Your Phone. Formal Methods Rescue It
    Mercaldo, Francesco
    Nardone, Vittoria
    Santone, Antonella
    Visaggio, Corrado Aaron
    [J]. FORMAL TECHNIQUES FOR DISTRIBUTED OBJECTS, COMPONENTS, AND SYSTEMS (FORTE 2016), 2016, 9688 : 212 - 221
  • [16] Experimental Analysis of Ransomware on Windows and Android Platforms: Evolution and Characterization
    Monika
    Zavarsky, Pavol
    Lindskog, Dale
    [J]. 11TH INTERNATIONAL CONFERENCE ON FUTURE NETWORKS AND COMMUNICATIONS (FNC 2016) / THE 13TH INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS AND PERVASIVE COMPUTING (MOBISPC 2016) / AFFILIATED WORKSHOPS, 2016, 94 : 465 - 472
  • [17] Evaluation of machine learning classifiers for mobile malware detection
    Narudin, Fairuz Amalina
    Feizollah, Ali
    Anuar, Nor Badrul
    Gani, Abdullah
    [J]. SOFT COMPUTING, 2016, 20 (01) : 343 - 357
  • [18] Nieuwenhuizen Daniel, 2017, MWR Labs Whitepaper
  • [19] Ensemble Machine Learning Approach for Android Malware Classification Using Hybrid Features
    Pektas, Abdurrahman
    Acarman, Tankut
    [J]. PROCEEDINGS OF THE 10TH INTERNATIONAL CONFERENCE ON COMPUTER RECOGNITION SYSTEMS CORES 2017, 2018, 578 : 191 - 200
  • [20] The Effective Ransomware Prevention Technique Using Process Monitoring on Android Platform
    Song, Sanggeun
    Kim, Bongjoon
    Lee, Sangjun
    [J]. MOBILE INFORMATION SYSTEMS, 2016, 2016