RanSAP: An open dataset of ransomware storage access patterns for training machine learning models

RanSAP: An open dataset of ransomware storage access patterns for training machine learning models
复制标题

DOI:
10.1016/j.fsidi.2021.301314
复制
发表时间:
2021-12-16
影响因子:
2
通讯作者:
Kobayashi, Ryotaro
Kobayashi, Ryotaro
中科院分区:
医学3区
文献类型:
--
作者:
Hirano, Manabu;Hodota, Ryo;Kobayashi, Ryotaro

文献摘要

被引文献

相似文献

勒索软件是一种通过加密用户文件来索要赎金的恶意软件,是最常见、最持久的威胁之一。在反病毒软件供应商更新了他们的签名(例如,从二进制文件中获得的静态特征)数据库后不久,网络罪犯就会创建新的勒索软件变体来逃避保护。因此,除了静态特征之外,今天许多勒索软件检测系统开始使用行为特征或动态特征。然而,即使使用动态特征的勒索软件检测可以处理勒索软件变体,它也有以下限制:(1)它需要执行勒索软件,(2)勒索软件在与受控环境不同的真实环境中可能表现不同,以及(3)当命令和控制(C&C)服务器被关闭时,勒索软件样本可能会被停用;因此,它们使得在相同条件下比较研究人员提出的多个检测系统变得不可能。为了解决这些限制,我们提出了RANSAP,这是我们新的勒索软件存储访问模式的开放数据集。数据集目前在公共存储库中可用。据我们所知,该数据集是为数不多的包含勒索软件动态特征的开放数据集之一。我们新的开放数据集包括7个重要勒索软件样本和5个流行的良性软件样本在不同类型和条件的存储设备上的存储访问模式。此外,该数据集还提供了勒索软件变体的访问模式,这些变体在不同版本的操作系统上,以及在启用了完整驱动器加密功能的存储设备上。我们首先提出了一个基于管理程序的存储访问模式监控系统,然后设计和实现了用于勒索软件检测的特征提取器和机器学习模型。接下来,对我们的数据集进行详细的分析和评估。最后,介绍了新数据集的局限性、与其他动态分析方法的比较、最新的勒索软件检测以及未来的研究方向。(C) 2021作者。Elsevier Ltd.出版。
Ransomware, the malicious software that encrypts user files to demand a ransom payment, is one of the most common and persistent threats. Cyber-criminals create new ransomware variants to evade protections shortly after anti-virus software vendors updated their signature (e.g., static feature obtained from binaries) database. Therefore, many ransomware detection systems today begin to employ behavioral features, or dynamic features, in addition to static features. However, even though ransom ware detection using dynamic features can deal with ransomware variants, it has the following limitations: (1) it requires the ransomware to be executed, (2) ransomware may behave differently in a real environment that differs from the controlled environment, and (3) a ransomware sample can become deactivated when command and control (C&C) servers are taken down; hence, they make it impossible to compare multiple detection systems proposed by researchers under identical conditions.To address the limitations, we present RANSAP, our new open dataset of ransomware storage access patterns. The dataset is currently available in a public repository. To our best knowledge, the dataset is one of the few open datasets consisting of dynamic features of ransomware.Our new open dataset includes storage access patterns of 7 significant ransomware samples and 5 popular benign software samples on various types and conditions of storage devices. Moreover, the dataset provides access patterns of ransomware variants, those on a different version of an operating system, and those on storage devices with a full drive encryption function enabled. We first present a hypervisor-based monitoring system of storage access patterns followed by a design and an implementation of a feature extractor and machine learning models for ransomware detection. Next, a detailed analysis and evaluation of our dataset are presented. Finally, limitations of our new dataset, comparison with other dynamic analysis methods, state-of-the-art ransomware detection, and future research direction are presented. (C) 2021 The Authors. Published by Elsevier Ltd.