RansomAI: AI-powered Ransomware for Stealthy Encryption

被引:0
|
作者
von der Assen, Jan [1 ]
Celdran, Alberto Huertas [1 ]
Luechinger, Janik [1 ]
Sanchez, Pedro Miguel Sanchez [2 ]
Bovet, Gerome [3 ]
Perez, Gregorio Marinez [2 ]
Stiller, Burkhard [1 ]
机构
[1] Univ Zurich UZH, Dept Informat, Commun Syst Grp CSG, CH-8050 Zurich, Switzerland
[2] Univ Murcia, Dept Informat & Commun Engn, Murcia 30100, Spain
[3] Cyber Def Campus Armasuisse Sci & Technol, CH-3602 Thun, Switzerland
关键词
Ransomware; Reinforcement Learning; Artificial Intelligence; Malware; Evasion; MALWARE;
D O I
10.1109/GLOBECOM54140.2023.10437393
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Cybersecurity solutions have shown promising performance when detecting ransomware samples that use fixed algorithms and encryption rates. However, due to the current explosion of Artificial Intelligence (AI), sooner than later, ransomware, and malware in general, will incorporate AI techniques to intelligently and dynamically adapt its behavior to be undetected. It might result in ineffective and obsolete cybersecurity solutions, but the literature lacks AI-powered ransomware samples to verify it. Thus, this work proposes RansomAI, a Reinforcement Learning-based framework that can be integrated into existing ransomware samples to adapt their encryption behavior and stay stealthy while encrypting files. RansomAI presents an agent that learns the best encryption algorithm, rate, and duration that minimizes its detection (using a reward mechanism and a fingerprinting intelligent detection system) while maximizing its damage. The proposed framework was validated with Ransomware-PoC, a ransomware that infected a Raspberry Pi 4 acting as a crowdsensor. A pool of experiments with Deep Q-Learning and Isolation Forest (deployed on the agent and detection system, respectively) has demonstrated that RansomAI evades the detection of Ransomware-PoC affecting the Raspberry Pi 4 in a few minutes with >90% accuracy.
引用
收藏
页码:2578 / 2583
页数:6
相关论文
共 50 条
  • [1] AI-Powered Ransomware Detection Framework
    Poudyal, Subash
    Dasgupta, Dipankar
    [J]. 2020 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (SSCI), 2020, : 1154 - 1161
  • [2] AI-powered positioning
    不详
    [J]. BRITISH DENTAL JOURNAL, 2023, 235 (11) : 900 - 900
  • [3] AI-powered positioning
    [J]. British Dental Journal, 2023, 235 : 900 - 900
  • [4] AI-powered decarbonisation
    Summerbell, Daniel
    [J]. ZKG International, 2024, 77 (07): : 110 - 112
  • [5] AI-Powered Image Security: Utilizing Autoencoders for Advanced Medical Image Encryption
    Alqahtani, Fehaid
    [J]. CMES-COMPUTER MODELING IN ENGINEERING & SCIENCES, 2024, : 1709 - 1724
  • [6] ChatGeppetto - an AI-powered Storyteller
    de Lima, Edirlei Soares
    Feijo, Bruno
    Casanova, Marco A.
    Furtado, Antonio L.
    [J]. PROCEEDINGS OF THE 22ND BRAZILIAN SYMPOSIUM ON COMPUTER GAMES AND DIGITAL ENTERTAINMENT, SBGAMES, 2023, 2023, : 28 - 37
  • [7] AI-powered neural implants
    N. A. Sudharson
    M. Joseph
    N. Kurian
    K. G. Varghese
    S. Wadhwa
    H. A. Thomas
    [J]. British Dental Journal, 2023, 234 : 359 - 360
  • [8] On the Engineering of AI-Powered Systems
    Kusmenko, Evgeny
    Pavlitskaya, Svetlana
    Rumpe, Bernhard
    Stueber, Sebastian
    [J]. 2019 34TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING WORKSHOPS (ASEW 2019), 2019, : 126 - 133
  • [9] AI-powered neural implants
    Waters, E.
    Leadbeatter, D.
    Spallek, H.
    [J]. BRITISH DENTAL JOURNAL, 2023, 234 (06) : 359 - 360
  • [10] AI-powered aptamer generation
    Khabbazian, Majid
    Jabbari, Hosna
    [J]. NATURE COMPUTATIONAL SCIENCE, 2022, 2 (06): : 356 - 357