A Multi-Classifier Network-Based Crypto Ransomware Detection System: A Case Study of Locky Ransomware

A Multi-Classifier Network-Based Crypto Ransomware Detection System: A Case Study of Locky Ransomware
复制标题

DOI:
10.1109/access.2019.2907485
复制
发表时间:
2019-01-01
期刊:
影响因子:
3.9
通讯作者:
O'Kane, Philip
O'Kane, Philip
中科院分区:
计算机科学3区
文献类型:
--
作者:
Almashhadani, Ahmad O.;Kaiiali, Mustafa;O'Kane, Philip

文献摘要

被引文献

相似文献

勒索软件是一种先进的恶意软件,近年来迅速蔓延,给包括组织、医疗机构和个人在内的广泛受害者造成了重大的经济损失。现代基于主机的检测方法要求主机首先被感染,以便识别异常并检测恶意软件。到感染时,可能已经太晚了,因为系统的一些资产已经被恶意软件泄露或加密。相反,基于网络的方法可以有效地检测勒索软件攻击,因为大多数勒索软件家族在执行其有害有效载荷之前尝试连接到命令和控制服务器。因此,仔细分析勒索软件网络流量可能是早期检测的关键手段之一。本文展示了加密勒索软件网络活动的全面行为分析,以最严重的家庭之一Locky为案例研究。建立了一个专用的测试床,提取了一组有价值和信息丰富的网络特征,并将其分类为多种类型。实现了一个基于网络的入侵检测系统,采用两个独立的分类器并行工作在不同的级别:包和流的水平。实验结果表明,该检测系统具有较高的检测准确率、较低的误报率、有效的提取特征,能够高效地跟踪勒索软件网络活动。
Ransomware is a type of advanced malware that has spread rapidly in recent years, causing significant financial losses for a wide range of victims, including organizations, healthcare facilities, and individuals. Modern host-based detection methods require the host to be infected first in order to identify anomalies and detect the malware. By the time of infection, it can be too late as some of the system's assets would have been already exfiltrated or encrypted by the malware. Conversely, the network-based methods can be effective in detecting ransomware attacks, as most ransomware families try to connect to command and control servers before their harmful payloads are executed. Therefore, a careful analysis of ransomware network traffic can be one of the key means for early detection. This paper demonstrates a comprehensive behavioral analysis of crypto ransomware network activities, taking Locky, one of the most serious families, as a case study. A dedicated testbed was built, and a set of valuable and informative network features were extracted and classified into multiple types. A network-based intrusion detection system was implemented, employing two independent classifiers working in parallel on different levels: packet and flow levels. The experimental evaluation of the proposed detection system demonstrates that it offers high detection accuracy, low false positive rate, valid extracted features, and is highly effective in tracking ransomware network activities.