A Framework for Analyzing Ransomware using Machine Learning

A Framework for Analyzing Ransomware using Machine Learning
复制标题

使用机器学习分析勒索软件的框架

DOI:
--
复制
发表时间:
2018
期刊:
IEEE Symposium Series on Computational Intelligence
影响因子:
--
通讯作者:
D. Dasgupta
D. Dasgupta
中科院分区:
--
文献类型:
--
作者:
Subash Poudyal;Kul Prasad Subedi;D. Dasgupta

文献摘要

被引文献

相似文献

近年来,勒索软件攻击增加,对企业造成重大损害和中断。可执行文件(或二进制文件)的反向工程等取证分析是检查此类恶意软件特征的常见做法。在这项工作中,我们开发了一个逆向工程框架,结合了特征生成引擎和机器学习(ML)来有效地检测勒索软件。此框架用于执行多级分析(例如原始二进制文件、汇编代码、库和函数调用),以便更好地检查和解释恶意软件代码段的用途。我们利用对象代码转储工具(Linux)和可移植的可执行(PE)解析器解码二进制汇编级指令和动态链接库(DLL)。勒索软件和正常二进制文件都被认为是进行实验,首先对样本进行预处理以提取特征,然后应用不同的(监督)ML技术对这些样本进行分类。实验结果报告了性能,即,勒索软件样本的检测准确率根据所使用的ML技术从76%到97%不等。特别是,在测试的八个ML分类器中,其中七个表现良好,检测率至少为90%。这项研究还表明,ASM级别和DLL级别的静态级别分析的组合可以更好地区分勒索软件和正常的二进制文件。
Ransomware attacks increased in recent years causing significant damages and disruptions to businesses. Forensic analysis such as reverse engineering of executables (or binary files) is the common practice of examining such malware characteristics. In this work, we developed a reverse engineering framework incorporating feature generation engines and machine learning (ML) to efficiently detect ransomware. This framework is used to perform multi-level analysis (such as raw binaries, assembly codes, libraries, and function calls) in order to better examine and interpret the purpose of malware code segments. We leverage the object-code dump tool (Linux) and portable executable (PE) parser to decode binaries to assembly level instructions and dynamic link libraries (DLLs). Both ransomware and normal binaries are considered to conduct experiments where samples are first pre-processed to extract features and then different (supervised) ML techniques are applied to classify these samples. Experimental results reported the performance i.e., the detection accuracy of ransomware samples which varied from 76% to 97% based on the ML technique used. In particular, among the eight ML classifiers tested, seven of these performed well with detection rate of at least 90%. This study also demonstrated that the combination of static level analysis at the ASM-level and DLL-level can better distinguish ransomware from normal binaries.