RWArmor: a static-informed dynamic analysis approach for early detection of cryptographic windows ransomware

被引:0
|
作者
Md. Ahsan Ayub
Ambareen Siraj
Bobby Filar
Maanak Gupta
机构
[1] Tennessee Tech University,Department of Computer Science
[2] Sublime Security,undefined
[3] Inc.,undefined
关键词
Dynamic Analysis; Machine Learning; Ransomware; Static Analysis;
D O I
暂无
中图分类号
学科分类号
摘要
Ransomware attacks have captured news headlines worldwide for the last few years due to their criticality and intensity. Ransomware-as-a-service (RaaS) kits are aiding adversaries to launch such powerful attacks with little to no technical knowledge. Eventually, with the successful progression of ransomware attacks, organizations suffer financial loss, and their proprietary-based sensitive digital assets end up on the dark web for sale. Due to the severity of this situation, security researchers are seen to conduct static and dynamic analysis research for ransomware research. Both analyses have advantages and disadvantages, and prompt ransomware detection is expected to stop the irreversible encryption process. This research proposes a novel static-informed dynamic analysis approach, RWArmor, which includes the knowledge of the already-trained machine learning models based on static features to improve the ransomware detection capabilities during dynamic analysis. The effectiveness of our approach is evaluated by predicting a novel/unknown ransomware between 30 and 120 seconds of its execution. The random forest algorithm is utilized to accomplish this task and tested against 215 active cryptographic Windows ransomware collected between 2014 and 2022. Based on our empirical findings, our method achieves 97.67%, 92.38%, and 86.42% accuracy within 120, 60, and 30 seconds of behavioral logs, respectively.
引用
收藏
页码:533 / 556
页数:23
相关论文
共 50 条
  • [21] Early Detection of Ransomware by Indicator Analysis and WinAPI Call Sequence Pattern
    Sharma, Harshit
    Kant, Shri
    INFORMATION AND COMMUNICATION TECHNOLOGY FOR INTELLIGENT SYSTEMS, ICTIS 2018, VOL 2, 2019, 107 : 201 - 211
  • [22] Detection of Android Malware: Combined with Static Analysis and. Dynamic Analysis
    Su, Ming-Yang
    Fung, Kek-Tung
    Huang, Yu-Hao
    Kang, Ming-Zhi
    Chung, Yen-Heng
    2016 INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING & SIMULATION (HPCS 2016), 2016, : 1013 - 1018
  • [23] IoT malware detection using static and dynamic analysis techniques: A systematic literature review
    Kumar, Sumit
    Ahlawat, Prachi
    Sahni, Jyoti
    SECURITY AND PRIVACY, 2024, 7 (06):
  • [24] Windows malware detection based on static analysis with multiple features
    Yousuf, Muhammad Irfan
    Anwer, Izza
    Riasat, Ayesha
    Zia, Khawaja Tahir
    Kim, Suhyun
    PEERJ COMPUTER SCIENCE, 2023, 9
  • [25] Windows malware detection based on static analysis with multiple features
    Yousuf M.I.
    Anwer I.
    Riasat A.
    Zia K.T.
    Kim S.
    PeerJ Computer Science, 2023, 9
  • [26] An approach for mapping features to code based on static and dynamic analysis
    Rohatgi, Abhishek
    Hamou-Lhadj, Abdelwahab
    Rilling, Juergen
    PROCEEDINGS OF THE 16TH IEEE INTERNATIONAL CONFERENCE ON PROGRAM COMPREHENSION, 2008, : 234 - 239
  • [27] Ranker: Early Ransomware Detection Through Kernel-Level Behavioral Analysis
    Zhang, Huan
    Zhao, Lixin
    Yu, Aimin
    Cai, Lijun
    Meng, Dan
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 6113 - 6127
  • [28] A Synergy between Static and Dynamic Analysis for the Detection of Software Security Vulnerabilities
    Hanna, Aiman
    Ling, Hai Zhou
    Yang, XiaoChun
    Debbabi, Mourad
    ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS: OTM 2009, PT 2, 2009, 5871 : 815 - 832
  • [29] Dockerfile TF smell detection based on dynamic and static analysis methods
    Xu, Jiwei
    Wu, Yuewen
    Lu, Zhigang
    Wang, Tao
    2019 IEEE 43RD ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), VOL 1, 2019, : 185 - 190
  • [30] A Proactive Forensics Approach for Virtual Machines via Dynamic and Static Analysis
    Hu Bo
    Li Nan
    Liu Zhiyong
    Li Min
    Liu Chao
    PROCEEDINGS OF 2016 IEEE 18TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS; IEEE 14TH INTERNATIONAL CONFERENCE ON SMART CITY; IEEE 2ND INTERNATIONAL CONFERENCE ON DATA SCIENCE AND SYSTEMS (HPCC/SMARTCITY/DSS), 2016, : 514 - 521