机构:
INRIA, LHS PEC, F-35042 Rennes, FranceMohammed V Univ Rabat, Fac Sci, LabMIASI BP, BP 1014 RP, Rabat 10000, Morocco
Lanet, Jean-Louis
[2
]
Souidi, El Mamoun
论文数: 0引用数: 0
h-index: 0
机构:
Mohammed V Univ Rabat, Fac Sci, LabMIASI BP, BP 1014 RP, Rabat 10000, MoroccoMohammed V Univ Rabat, Fac Sci, LabMIASI BP, BP 1014 RP, Rabat 10000, Morocco
Souidi, El Mamoun
[1
]
机构:
[1] Mohammed V Univ Rabat, Fac Sci, LabMIASI BP, BP 1014 RP, Rabat 10000, Morocco
During recent years, many papers have been published on ransomware, but to the best of our knowledge, no previous academic studies have been conducted on ransom note files. In this paper, we present the results of a depth study on filenames and the content of ransom files. We propose a prototype to identify the ransom files. Then we explore how the filenames and the content of these files can minimize the risk of ransomware encryption of some specified ransomware or increase the effectiveness of some ransomware detection tools. To achieve these objectives, two approaches are discussed in this paper. The first uses Latent Semantic Analysis (LSA) to check similarities between the contents of files. The second uses some Machine Learning models to classify the filenames into two classes-ransom filenames and benign filenames.
机构:
Istanbul Univ, Sosyal Hizmet Bolumu, Tezli Yuksek Lisans Ogrencisi, Istanbul, TurkeyIstanbul Univ, Sosyal Hizmet Bolumu, Tezli Yuksek Lisans Ogrencisi, Istanbul, Turkey