Machine Learning Based Ransomware Detection Using Storage Access Patterns Obtained From Live-forensic Hypervisor

Machine Learning Based Ransomware Detection Using Storage Access Patterns Obtained From Live-forensic Hypervisor
复制标题

使用从实时取证管理程序获得的存储访问模式进行基于机器学习的勒索软件检测

DOI:
--
复制
发表时间:
2019
期刊:
International Conference on Internet of Things: Systems, Management and Security
影响因子:
--
通讯作者:
R. Kobayashi
R. Kobayashi
中科院分区:
--
文献类型:
--
作者:
Manabu Hirano;R. Kobayashi

文献摘要

参考文献

被引文献

相似文献

随着物联网设备、移动设备、云服务和网络物理系统数量的快速增加,针对企业和公共部门的大规模网络攻击也在增加。特别是,勒索软件攻击在2017年损害了英国国家医疗服务体系和世界各地的许多企业。因此,研究人员提出了勒索软件检测和预防系统。然而,静态和动态勒索软件分析中的人工检查非常耗时,而且无法应对勒索软件家族变种的快速增加。最近,机器学习被用于通过创建相同勒索软件族的行为模型来自动化勒索软件分析。为了创建有效的勒索软件行为模型,我们首先使用名为Wayback Visor的实时取证管理程序获取实时勒索软件样本和良性应用程序的存储访问模式。为了区分勒索软件与行为类似于勒索软件的良性应用程序,我们仔细选择了从实际勒索软件的输入和输出(I/O)日志以及良性程序的I/O日志中提取的五个维度特征。我们使用随机森林、支持向量机和K-近邻来创建和评估机器学习模型。我们使用提出的存储访问模式的五个特征进行实验,获得了98%的F-测定率。
With the rapid increase in the number of Internet of Things (IoT) devices, mobile devices, cloud services, and cyber-physical systems, the large-scale cyber attacks on enterprises and public sectors have increased. In particular, ransomware attacks damaged UK’s National Health Service and many enterprises around the world in 2017. Therefore, researchers have proposed ransomware detection and prevention systems. However, manual inspection in static and dynamic ransomware analysis is time-consuming and it cannot cope with the rapid increase in variants of ransomware family. Recently, machine learning has been used to automate ransomware analysis by creating a behavioral model of same ransomware family. To create effective behavioral models of ransomware, we first obtained storage access patterns of live ransomware samples and of a benign application by using a live-forensic hypervisor called WaybackVisor. To distinguish ransomware from a benign application that has similar behavior to ransomware, we carefully selected five dimensional features that were extracted both from actual ransomware’s Input and Output (I/O) logs and from a benign program’s I/O logs. We created and evaluated machine learning models by using Random Forest, Support Vector Machine, and K-Nearest Neighbors. Our experiments using the proposed five features of storage access patterns achieved F-measure rate of 98%.
深度学习如何让信息安全变得更加智能
DOI: 10.1109/msec.2019.2902347
发表时间: 2019
影响因子: 1.9
作者:
Singla, Ankush;Bertino, Elisa
通讯作者: Bertino, Elisa