RWArmor: a static-informed dynamic analysis approach for early detection of cryptographic windows ransomware

被引:0
作者
Md. Ahsan Ayub
Ambareen Siraj
Bobby Filar
Maanak Gupta
机构
[1] Tennessee Tech University,Department of Computer Science
[2] Sublime Security,undefined
[3] Inc.,undefined
关键词
Dynamic Analysis; Machine Learning; Ransomware; Static Analysis;
D O I
暂无
中图分类号
学科分类号
摘要
Ransomware attacks have captured news headlines worldwide for the last few years due to their criticality and intensity. Ransomware-as-a-service (RaaS) kits are aiding adversaries to launch such powerful attacks with little to no technical knowledge. Eventually, with the successful progression of ransomware attacks, organizations suffer financial loss, and their proprietary-based sensitive digital assets end up on the dark web for sale. Due to the severity of this situation, security researchers are seen to conduct static and dynamic analysis research for ransomware research. Both analyses have advantages and disadvantages, and prompt ransomware detection is expected to stop the irreversible encryption process. This research proposes a novel static-informed dynamic analysis approach, RWArmor, which includes the knowledge of the already-trained machine learning models based on static features to improve the ransomware detection capabilities during dynamic analysis. The effectiveness of our approach is evaluated by predicting a novel/unknown ransomware between 30 and 120 seconds of its execution. The random forest algorithm is utilized to accomplish this task and tested against 215 active cryptographic Windows ransomware collected between 2014 and 2022. Based on our empirical findings, our method achieves 97.67%, 92.38%, and 86.42% accuracy within 120, 60, and 30 seconds of behavioral logs, respectively.
引用
收藏
页码:533 / 556
页数:23
相关论文
共 50 条
  • [31] Detecting Cryptomining Malware: a Deep Learning Approach for Static and Dynamic Analysis
    Hamid Darabian
    Sajad Homayounoot
    Ali Dehghantanha
    Sattar Hashemi
    Hadis Karimipour
    Reza M. Parizi
    Kim-Kwang Raymond Choo
    Journal of Grid Computing, 2020, 18 : 293 - 303
  • [32] Detecting Cryptomining Malware: a Deep Learning Approach for Static and Dynamic Analysis
    Darabian, Hamid
    Homayounoot, Sajad
    Dehghantanha, Ali
    Hashemi, Sattar
    Karimipour, Hadis
    Parizi, Reza M.
    Choo, Kim-Kwang Raymond
    JOURNAL OF GRID COMPUTING, 2020, 18 (02) : 293 - 303
  • [33] XRan: Explainable deep learning-based ransomware detection using dynamic analysis
    Gulmez, Sibel
    Kakisim, Arzu Gorgulu
    Sogukpinar, Ibrahim
    COMPUTERS & SECURITY, 2024, 139
  • [34] Static, Dynamic and Semantic Dimensions: Towards a Multidisciplinary Approach of Social Networks Analysis
    Thovex, Christophe
    Trichet, Francky
    KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, 2010, 6291 : 567 - 572
  • [35] Blending Static and Dynamic Analysis for Web Application Vulnerability Detection: Methodology and Case Study
    Nunes, Paulo
    Fonseca, Jose
    Vieira, Marco
    IEEE ACCESS, 2025, 13 : 3139 - 3153
  • [36] A NUMERICAL APPROACH FOR STATIC AND DYNAMIC ANALYSIS OF DEFORMABLE JOURNAL BEARINGS
    Benasciutti, Denis
    Munteanu, Mircea Gh.
    Flumian, Fabio
    COMPUTATIONAL METHODS FOR COUPLED PROBLEMS IN SCIENCE AND ENGINEERING V, 2013, : 609 - 620
  • [37] Malware Detection Approach Based on Artifacts in Memory Image and Dynamic Analysis
    Sihwail, Rami
    Omar, Khairuddin
    Ariffin, Khairul Akram Zainol
    Al Afghani, Sanad
    APPLIED SCIENCES-BASEL, 2019, 9 (18):
  • [38] A domain decomposition approach for static and dynamic analysis of composite laminated curved beam with general elastic restrains
    Guo, Jianghua
    Shi, Dongyan
    Wang, Qingshan
    Pang, Fuzhen
    Liang, Qian
    MECHANICS OF ADVANCED MATERIALS AND STRUCTURES, 2019, 26 (16) : 1390 - 1402
  • [39] OPEM: A Static-Dynamic Approach for Machine-Learning-Based Malware Detection
    Santos, Igor
    Devesa, Jaime
    Brezo, Felix
    Nieves, Javier
    Garcia Bringas, Pablo
    INTERNATIONAL JOINT CONFERENCE CISIS'12 - ICEUTE'12 - SOCO'12 SPECIAL SESSIONS, 2013, 189 : 271 - 280
  • [40] Impact of Code Obfuscation on Android Malware Detection based on Static and Dynamic Analysis
    Bacci, Alessandro
    Bartoli, Alberto
    Martinelli, Fabio
    Medvet, Eric
    Mercaldo, Francesco
    Visaggio, Corrado Aaron
    ICISSP: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY, 2018, : 379 - 385