On the Effectiveness of Behavior-Based Ransomware Detection

On the Effectiveness of Behavior-Based Ransomware Detection
复制标题

基于行为的勒索软件检测的有效性

DOI:
10.1007/978-3-030-63095-9_7
复制
发表时间:
2020
期刊:
International Conference on Security and Privacy in Communication Systems
影响因子:
--
通讯作者:
Porter, Donald E
Porter, Donald E
中科院分区:
--
文献类型:
--
作者:
Han, Jaehyun;Lin, Zhiqiang;Porter, Donald E

文献摘要

参考文献

被引文献

相似文献

在过去的几年里,勒索软件对最终用户的威胁越来越大。作为回应,反勒索软件防御产品以及探索更先进的行为分析的研究原型也有一个蓬勃发展的市场。直观地说,勒索软件应该可以通过行为分析进行识别,因为勒索软件递归地遍历用户的文件并对其进行加密,覆盖或删除明文。本文从商业产品和学术建议两个方面对这些基于行为的勒索软件防御的有效性进行了研究。我们用一个非常简单的勒索软件推动了这项研究,并增加了一些直接的和新的规避技术。令人惊讶的是,我们的结果表明,大多数商业产品都非常无效。在没有任何规避技术的情况下,15种商业产品中有10种无法检测到我们的简单勒索软件;其余大多数都被规避,并能够通过一些简单技术的组合来勒索用户数据。只有一个工具似乎可以正确识别我们的勒索软件,但却出现了惊人的误报,包括在日常操作中将Windows资源管理器、Firefox和记事本标记为勒索软件。我们的论文确定了许多操纵熵以匹配原始文件的技术。这篇论文进一步表明,仅对文件数据的3%-5%进行部分加密就足以赎回大多数文件格式。最后,我们展示了这些技术的组合可以呈现远低于Linux内核编译的总恶意分数。总而言之,这些结果表明,勒索软件很有可能能够调整其行为,以适应预期的良性行为范围,从而避免被未来几代行为勒索软件检测器检测到。
Ransomware has been a growing threat to end-users in the past few years. In response, there is also a burgeoning market for anti-ransomware defense products, as well as research prototypes that explore more advanced, behavioral analyses. Intuitively, ransomware should be amenable to identification through behavioral analysis, since ransomware recursively walks a user’s files and encrypts them, overwriting or deleting the plaintext. This paper contributes a study of the effectiveness of these behavior-based ransomware defenses, from both commercial products and academic proposals. We drive the study with a dead simple ransomware, augmented with a number of both straightforward and new evasion techniques. Surprisingly, our results indicate that most commercial products are strikingly ineffective. Ten out of 15 commercial products could not detect our simple ransomware without any evasive techniques; most of the rest were evaded and able to ransom user data with some combination of simple techniques. Only one tool appears to correctly identify our ransomware, but suffers from staggering false positives, including flagging Windows Explorer, Firefox, and Notepad as ransomware during routine operation. Our paper identifies a number of techniques to manipulate entropy to match the original file. The paper further shows that partial encryption, of as little as 3–5% of a file’s data is sufficient to ransom most file formats. Finally, we show that a combination of these techniques can render an aggregate malice score that is well below that of a Linux kernel compile. In summary, these results indicate that it is highly likely that ransomware will be able to adapt its behavior to fit within the range of expected benign behaviors, avoiding detection even by future generations of behavioral ransomware detectors.
通过其传播方式分析和检测勒索软件
DOI: --
发表时间: 2017
期刊:
影响因子: --
作者:
K. Gangwar;S. Mohanty;A. Mohapatra
通讯作者: A. Mohapatra
了解勒索软件的演变:攻击结构的范式转变
DOI: 10.5815/ijcnis.2019.01.03
发表时间: 2019
影响因子: --
作者:
Aaron Zimba;Mumbi Chishimba
通讯作者: Mumbi Chishimba
DOI: 10.1049/iet-net.2017.0207
发表时间: 2018-08
期刊: IET Networks
影响因子: 1.4
作者:
Philip O'Kane;S. Sezer;Domhnall Carlin
通讯作者: Philip O'Kane;S. Sezer;Domhnall Carlin