Analysis and Detection of Ransomware Through Its Delivery Methods

Analysis and Detection of Ransomware Through Its Delivery Methods
复制标题

通过其传播方式分析和检测勒索软件

DOI:
--
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
A. Mohapatra
A. Mohapatra
中科院分区:
--
文献类型:
--
作者:
K. Gangwar;S. Mohanty;A. Mohapatra

文献摘要

被引文献

相似文献

网络犯罪分子正在利用多种方法从互联网用户和组织那里获取钱财。最近,一种名为勒索软件的恶意软件因其易于获取和传播的方式,在这项“工作”中变得非常容易得手。安全专家正在通过修复操作系统的漏洞来应对勒索软件攻击。在这项研究工作中,我们提出了一种通过其传播渠道(如漏洞利用工具包)在早期阶段预防勒索软件攻击的方法。我们分析了受害者计算机的爬行模式(文件路径列表、下载的文件、网络活动、勒索通知等)。这些模式已被用于提取特征,以便对恶意样本进行分类。我们使用了有监督的机器学习算法对恶意软件进行分类。实验结果表明,使用随机森林算法在紧密约束模式下可达到94%的准确率,而使用随机森林分类算法在中度约束模式下可达到91%的准确率。
Cyber criminals are utilizing diverse approaches to draw money from internet users and organizations. Recently, a malware called ransomware has become effectively accessible for this job due to its ease of availability and distribution methods. Security experts are working to counter ransomware attacks by fixing the vulnerabilities of operating system. In this research work, we have proposed a method to prevent the ransomware attack at its early stages through its delivery channels like Exploit Kits. We have analyzed the crawling patterns (listing of file path, dropped file, network activity, ransom note etc.) of victim’s computer. These patterns have been used to extract the features for classification of malicious samples. We have used supervised machine learning algorithms for classification of malwares. Experimental results shows that accuracy of 94% is achieved in tightly bound mode by using random forest algorithm. While, accuracy of 91% is achieved in moderate bound mode by using random forest classification algorithm.