Machine Learning-based Ransomware Detection Using Low-level Memory Access Patterns Obtained From Live-forensic Hypervisor

Machine Learning-based Ransomware Detection Using Low-level Memory Access Patterns Obtained From Live-forensic Hypervisor
复制标题

使用从实时取证管理程序获得的低级内存访问模式进行基于机器学习的勒索软件检测

DOI:
10.1109/csr54599.2022.9850340
复制
发表时间:
2022
期刊:
2022 IEEE International Conference on Cyber Security and Resilience (CSR)
影响因子:
--
通讯作者:
Kobayashi Ryotaro
Kobayashi Ryotaro
中科院分区:
--
文献类型:
--
作者:
Hirano Manabu;Kobayashi Ryotaro

文献摘要

参考文献

被引文献

相似文献

由于现代反病毒软件主要依赖于基于签名的静态分析,它们不适合应对恶意软件变体的快速增加。此外,更糟糕的是,操作系统的许多漏洞使攻击者能够逃避这种保护机制。因此,我们开发了一个轻薄的实时取证管理程序,以在传统的操作系统保护层下创建一个额外的保护层,并使用动态行为功能支持勒索软件检测。开发的实时取证管理程序收集低级内存访问模式,而不是现代虚拟机自检技术所采用的高级信息,如进程ID和API调用。然后,我们创建了包含三个勒索软件样本、一个雨刷恶意软件样本和四个良性应用程序的低级内存访问模式数据集。我们证实,我们最好的机器学习分类器只使用低级内存访问模式,在检测勒索软件和雨刷恶意软件方面达到了0.95的F1分数。
Since modern anti-virus software mainly depends on a signature-based static analysis, they are not suitable for coping with the rapid increase in malware variants. Moreover, even worse, many vulnerabilities of operating systems enable attackers to evade such protection mechanisms. We, therefore, developed a thin and lightweight live-forensic hypervisor to create an additional protection layer under a conventional protection layer of operating systems with supporting ransomware detection using dynamic behavioral features. The developed live-forensic hypervisor collects low-level memory access patterns instead of high-level information such as process IDs and API calls that modern Virtual Machine Introspection techniques have employed. We then created the low-level memory access patterns dataset of three ransomware samples, one wiper malware sample, and four benign applications. We confirmed that our best machine learning classifier using only low-level memory access patterns achieved an F1score of 0.95 in detecting ransomware and wiper malware.
管理程序辅助的动态恶意软件分析
DOI: --
发表时间: 2021
期刊: Cybersecurity
影响因子: 3.1
作者:
Roee S. Leon;Michael Kiperberg;Anat Anatey Leon Zabag;N. Zaidenberg
通讯作者: N. Zaidenberg
勒索软件存储访问模式的开放数据集
DOI: --
发表时间: --
期刊:
影响因子: --
作者:
通讯作者: --
使用基于深度学习的自适应方法,通过针对勒索软件威胁的强大保护,避免未来的数字勒索
DOI: 10.1109/access.2020.2970466
发表时间: 2020
期刊: IEEE Access
影响因子: 3.9
作者:
Shaila Sharmeen;Yahye Abukar Ahmed;Shamsul Huda;B. Koçer;Mohammad Mehedi Hassan
通讯作者: Mohammad Mehedi Hassan
使用从实时取证管理程序获得的存储访问模式进行基于机器学习的勒索软件检测
DOI: --
发表时间: 2019
期刊: International Conference on Internet of Things: Systems, Management and Security
影响因子: --
作者:
Manabu Hirano;R. Kobayashi
通讯作者: R. Kobayashi