Ransomware detection method based on context-aware entropy analysis

被引:38
|
作者
Jung, Sangmoon [1 ]
Won, Yoojae [1 ]
机构
[1] Chungnam Natl Univ, Dept Comp Sci Engn, Daejeon, South Korea
关键词
API hooking; Command and control server; Context-based analysis; Cryptography; Entropy; Kernel system; Ransomware; System security process;
D O I
10.1007/s00500-018-3257-z
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Numerous countermeasures have been proposed since the first appearance of ransomware. However, many ransomware mutants continue to be created, and the damage they cause has been continually increasing. Existing antivirus tools are signature-dependent and cannot easily detect ransomware attack patterns. If the database used by the antivirus program does not contain the signature of the new malicious behavior, it is not possible to detect the new malware. Thus, the need has emerged for a normal/abnormal behavior analysis technique via a context-aware method. Therefore, a multilateral context-aware-based ransomware detection and response system model is presented in this paper. The proposed model is designed to preemptively respond to ransomware, and post-detection management is performed. An evaluation was conducted to obtain evidence that the given files were altered by ransomware through analyses based on multiple-context awareness. Entropy information was then used to detect abnormal behavior.
引用
收藏
页码:6731 / 6740
页数:10
相关论文
共 50 条
  • [41] A context-aware system based on scent
    Terada, Tsutomu
    Kobayashi, Yasuki
    Tsukamoto, Masahiko
    Computer Software, 2012, 29 (04) : 324 - 334
  • [42] Multi-Scale Based Context-Aware Net for Action Detection
    Liu, Haijun
    Wang, Shiguang
    Wang, Wen
    Cheng, Jian
    IEEE TRANSACTIONS ON MULTIMEDIA, 2020, 22 (02) : 337 - 348
  • [43] An IoT-based context-aware model for danger situations detection
    Tundis, Andrea
    Uzair, Muhammad
    Muhlhauser, Max
    COMPUTERS & ELECTRICAL ENGINEERING, 2021, 96 (96)
  • [44] Context-Aware Model Based Facial Expression Nets Analysis
    Xu, Chao
    Fang, Zhiyong
    Zhang, Yu
    MECHANICAL AND ELECTRONICS ENGINEERING III, PTS 1-5, 2012, 130-134 : 3173 - +
  • [45] Context-aware part-based people detection for video monitoring
    Garcia-Martin, A.
    SanMiguel, J. C.
    ELECTRONICS LETTERS, 2015, 51 (23) : 1865 - 1866
  • [46] HCAM: A context-aware middleware to support logic-based context conflict detection
    Rao, Ruonan
    Ye, Guangchang
    You, Jinyuan
    2007 SECOND INTERNATIONAL CONFERENCE IN COMMUNICATIONS AND NETWORKING IN CHINA, VOLS 1 AND 2, 2007, : 259 - 263
  • [47] Context-aware security framework based on Traffic Anomaly Detection Indicator
    Antonio Cuadra
    Javier Aracil
    Telecommunication Systems, 2017, 65 : 319 - 330
  • [48] Remote Sensing Object Detection Based on Gated Context-Aware Module
    Dong, Xiaohu
    Qin, Yao
    Fu, Ruigang
    Gao, Yinghui
    Liu, Songlin
    Ye, Yuanxin
    IEEE GEOSCIENCE AND REMOTE SENSING LETTERS, 2022, 19
  • [49] Context-aware security framework based on Traffic Anomaly Detection Indicator
    Cuadra, Antonio
    Aracil, Javier
    TELECOMMUNICATION SYSTEMS, 2017, 65 (02) : 319 - 330
  • [50] Measuring privacy through entropy in context-aware mobile services
    Patrikakis, Charalarnpas
    Voulodimos, Athanasios
    IEEE PERVASIVE COMPUTING, 2007, 6 (04) : 73 - 74