MFMCNS: a multi-feature and multi-classifier network-based system for ransomworm detection

MFMCNS: a multi-feature and multi-classifier network-based system for ransomworm detection
复制标题

MFMCNS:一种基于多特征、多分类器网络的勒索蠕虫检测系统

DOI:
10.1016/j.cose.2022.102860
复制
发表时间:
2022
影响因子:
5.6
通讯作者:
Almashhadani A
Almashhadani A
中科院分区:
计算机科学3区
文献类型:
--
作者:
Almashhadani A

文献摘要

参考文献

被引文献

相似文献

勒索软件是一种高级恶意软件,可以加密用户的文件或锁定计算机系统,直到支付赎金。勒索蠕虫是一种恶意软件,它将勒索软件的有效载荷与计算机蠕虫的传播功能相结合。大多数基于主机的检测方法要求主机被感染,并且首先执行有效负载,以便能够识别异常并检测恶意软件。到感染时,可能为时已晚,因为系统的一些资产已经被恶意软件加密或泄露。相反,基于网络的方法可以是检测勒索病毒活动的关键手段之一,当它试图在执行有效载荷之前传播感染其他网络时。因此,对勒索病毒网络流量进行全面分析可能是早期检测的重要手段之一。本文以发起全球网络攻击的WannaCry和NotPetya为例,对勒索蠕虫网络流量进行了全面的行为分析。基于两个独立的流级别:基于会话和基于时间,提取两组相关特征。在每个集合之上,构建独立的分类器。此外,为了提高可靠性,多特征和多分类器的网络为基础的系统,MFMCNS,已被提出。MFMCNS采用多个分类器并行工作在不同的流层次上,然后采用一种联合收割机融合规则对多个分类器的决策进行融合。实验结果表明,MFMCNS是可靠的,具有较高的检测精度。
Ransomware is a type of advanced malware that can encrypt a user’s files or lock a computer system until a ransom has been paid. Ransomworm is a type of malware that combines the payload of ransomware with the propagation feature of a computer worm. Most host-based detection methods require the host to be infected and the payload to be executed first to be able to identify anomalies and detect the malware. By the time of infection, it might too late as some of the system’s assets would have been already encrypted or exfiltrated by the malware. On the contrary, the network-based methods can be one of the crucial means in detecting ransomworm activities when it attempts to spread to infect other networks before executing the payload. Therefore, a thorough analysis of ransomworm network traffic can be one of the essential means for early detection. This paper presents a comprehensive behavioral analysis of ransomworm network traffic, taking WannaCry, which launched a worldwide cyberattack, and NotPetya as a case study. Two sets of related features were extracted based on two independent flow levels: session-based and time-based. On top of each set, an independent classifier was built. Moreover, to improve the reliability, a multi-feature and multi-classifier network-based system, MFMCNS, has been proposed. MFMCNS employs these classifiers working in parallel on different flow levels, then it adopts a fusion rule to combine the classifiers’ decisions. The experimental results prove that MFMCNS is reliable and has high detection accuracy.
MaldomDetector:通过机器学习检测算法生成的域名的系统
DOI: 10.1016/j.cose.2020.101787
发表时间: 2020
期刊: Comput. Secur.
影响因子: --
作者:
Ahmad O. Almashhadani;M. Kaiiali;Domhnall Carlin;S. Sezer
通讯作者: S. Sezer
勒索软件对能源输送系统的威胁
DOI: 10.1109/msec.2021.3063678
发表时间: 2021
影响因子: 1.9
作者:
D. Nicol
通讯作者: D. Nicol
DNSxD:检测 DNS 上的数据泄露
DOI: 10.1109/nfv-sdn.2018.8725640
发表时间: 2018
期刊: 2018 IEEE Conference on Network Function Virtualization and Software Defined Networks (NFV-SDN)
影响因子: --
作者:
Jacob Steadman;Sandra Scott
通讯作者: Sandra Scott
考虑武器和漏洞分析 WannaCry 勒索软件
DOI: 10.23919/icact.2019.8702049
发表时间: 2019
期刊: 2019 21st International Conference on Advanced Communication Technology (ICACT)
影响因子: --
作者:
Da;Shou;R. Tso
通讯作者: R. Tso
DOI: 10.1109/access.2019.2907485
发表时间: 2019-01-01
期刊: IEEE ACCESS
影响因子: 3.9
作者:
Almashhadani, Ahmad O.;Kaiiali, Mustafa;O'Kane, Philip
通讯作者: O'Kane, Philip