Avoiding Future Digital Extortion Through Robust Protection Against Ransomware Threats Using Deep Learning Based Adaptive Approaches

Avoiding Future Digital Extortion Through Robust Protection Against Ransomware Threats Using Deep Learning Based Adaptive Approaches
复制标题

使用基于深度学习的自适应方法,通过针对勒索软件威胁的强大保护,避免未来的数字勒索

DOI:
10.1109/access.2020.2970466
复制
发表时间:
2020
期刊:
影响因子:
3.9
通讯作者:
Mohammad Mehedi Hassan
Mohammad Mehedi Hassan
中科院分区:
计算机科学3区
文献类型:
--
作者:
Shaila Sharmeen;Yahye Abukar Ahmed;Shamsul Huda;B. Koçer;Mohammad Mehedi Hassan

文献摘要

被引文献

相似文献

数字勒索已成为许多组织的主要网络风险;中小型企业(SME)到大型企业和个人企业家。勒索软件是一种恶意软件,是数字勒索的主要威胁,近年来通过向网络犯罪分子支付更高的赎金要求,导致许多组织损失了巨额收入。勒索软件的爆炸性增长是由于现有的大型感染媒介,如社交工程,电子邮件附件,zip文件下载,浏览恶意网站,受感染的搜索引擎,这些都是由易于获得的加密工具,勒索软件即服务(RaaS),增加的云存储和离线勒索软件工具包大幅提升的。大型感染载体和可用的工具包不仅极大地增加了勒索软件,而且使它们在新的变体中更加模糊,加密和变化。这反过来又导致传统的监督分析和检测引擎无法检测到勒索软件的新变种。本文针对传统监督检测引擎的局限性,提出了一种半监督框架,利用深度学习方法,以无监督的方式计算新变体中变化模式的固有潜在来源。所提出的框架提取的固有特征,在不同的模式从未标记的勒索软件从野生环境中获得的可扩展,以适应即将到来的恶意可执行文件。然后将无监督学习模型与监督分类相结合,构建自适应检测模型。已使用动态分析测试平台使用真实的勒索软件数据验证了拟议的框架。我们广泛的实验结果和讨论表明,所提出的自适应框架可以成功地识别勒索软件的不同变体,并实现比现有监督方法更高的性能。
Digital extortion has become a major cyber risk for many organizations; small-medium enterprises (SME) to large enterprises business and individual entrepreneurs. Ransomware is a kind of malware that is the main threat to digital extortion and has caused many organizations to lose huge revenue by paying much bigger ransom demands to the cybercriminals in recent years. The explosive growth of ransomware is due to the existing large infection vector such as social engineering, email attachment, zip file download, browsing malicious site, infected search engine which are boosted dramatically by easily available cryptographic tools, Ransomware As a Service (RaaS), increased cloud storage and off-the-self ransomware toolkits. The large infection vector and available toolkits not only grew ransomware extremely, but also made them more obfuscated, encrypted and varying patterns in the new variants. This, in turn, caused the conventional supervised analysis and detection engine to fail to detect the new variants of ransomware. This paper addresses the limitations of conventional supervised detection engine and proposes semi-supervised framework to compute the inherent latent sources of the varying patterns in the new variants in an unsupervised way using deep learning approaches. The proposed framework extracts the inherent characteristics in the varying patterns from the unlabelled ransomware obtained from the wild which is scalable to accommodate upcoming malicious executables. Then the unsupervised learned model is combined with supervised classification, thus constructing an adaptive detection model. The proposed framework has been verified using real ransomware data with a dynamic analysis testbed. Our extensive experimental results and discussion demonstrate that the proposed adaptive framework can successfully identify different variants of ransomware and achieve higher performance than existing supervised approaches.