Machine Learning-based Ransomware Detection Using Low-level Memory Access Patterns Obtained From Live-forensic Hypervisor
Machine Learning-based Ransomware Detection Using Low-level Memory Access Patterns Obtained From Live-forensic Hypervisor
复制标题
使用从实时取证管理程序获得的低级内存访问模式进行基于机器学习的勒索软件检测
DOI:
10.1109/csr54599.2022.9850340
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
Kobayashi Ryotaro
中科院分区:
文献类型:
--
作者:
Hirano Manabu;Kobayashi Ryotaro
Since modern anti-virus software mainly depends on a signature-based static analysis, they are not suitable for coping with the rapid increase in malware variants. Moreover, even worse, many vulnerabilities of operating systems enable attackers to evade such protection mechanisms. We, therefore, developed a thin and lightweight live-forensic hypervisor to create an additional protection layer under a conventional protection layer of operating systems with supporting ransomware detection using dynamic behavioral features. The developed live-forensic hypervisor collects low-level memory access patterns instead of high-level information such as process IDs and API calls that modern Virtual Machine Introspection techniques have employed. We then created the low-level memory access patterns dataset of three ransomware samples, one wiper malware sample, and four benign applications. We confirmed that our best machine learning classifier using only low-level memory access patterns achieved an F1score of 0.95 in detecting ransomware and wiper malware.
登录
查看更多内容
影响因子:
3.1
作者:
Roee S. Leon;Michael Kiperberg;Anat Anatey Leon Zabag;N. Zaidenberg
通讯作者:
N. Zaidenberg
DOI:
--
发表时间:
--
期刊:
影响因子:
--
作者:
通讯作者:
--
影响因子:
3.9
作者:
Shaila Sharmeen;Yahye Abukar Ahmed;Shamsul Huda;B. Koçer;Mohammad Mehedi Hassan
通讯作者:
Mohammad Mehedi Hassan
DOI:
--
发表时间:
2019
期刊:
International Conference on Internet of Things: Systems, Management and Security
影响因子:
--
作者:
Manabu Hirano;R. Kobayashi
通讯作者:
R. Kobayashi