A New Scheme for Ransomware Classification and Clustering Using Static Features
2022; Multidisciplinary Digital Publishing Institute; Volume: 11; Issue: 20 Linguagem: Inglês
10.3390/electronics11203307
ISSN2079-9292
AutoresBahaa Yamany, Mahmoud Said Elsayed, Anca Delia Jurcut, Nashwa Abdelbaki, Marianne A. Azer,
Tópico(s)Spam and Phishing Detection
ResumoRansomware is a strain of malware that disables access to the user’s resources after infiltrating a victim’s system. Ransomware is one of the most dangerous malware organizations face by blocking data access or publishing private data over the internet. The major challenge of any entity is how to decrypt the files encrypted by ransomware. Ransomware’s binary analysis can provide a means to characterize the relationships between different features used by ransomware families to track the ransomware encryption mechanism routine. In this paper, we compare the different ransomware detection approaches and techniques. We investigate the criteria, parameters, and tools used in the ransomware detection ecosystem. We present the main recommendations and best practices for ransomware mitigation. In addition, we propose an efficient ransomware indexing system that provides search functionalities, similarity checking, sample classification, and clustering. The new system scheme mainly targets native ransomware binaries, and the indexing engine depends on hybrid data from the static analyzer system. Our scheme tracks and classifies ransomware based on static features to find the similarity between different ransomware samples. This is done by calculating the absolute Jaccard index. Results have shown that Import Address Table (IAT) feature can be used to classify different ransomware more accurately than the Strings feature.
Referência(s)