Crypto-Ransomware Detection Using Selective Hashing

Anas AlMajali, Ahmad Qaffaf, Natali Alkayid, Y. Wadhawan
{"title":"Crypto-Ransomware Detection Using Selective Hashing","authors":"Anas AlMajali, Ahmad Qaffaf, Natali Alkayid, Y. Wadhawan","doi":"10.1109/ICECTA57148.2022.9990424","DOIUrl":null,"url":null,"abstract":"Ransomware is a malicious software that attempts to encrypt the user’s files and demand a ransom in exchange for decrypting the files. This malware may have catastrophic impacts on the availability of data and consequently on the services provided by the infected organizations and institutes. Ransomware detection has been a challenge for researchers in the past few years. In this paper, we propose a behavioral ransomware detection method that utilizes fast selective hashing techniques. By selective we mean that only few selected blocks from a file are used for similarity comparison. Our experimental results demonstrate the efficacy of the proposed method in ransonware detection in terms of detection time. For 1000 files of a total size of 20GB and a detection threshold set to five files, our proposed system is able to detect a ransomware on average within 2.76 seconds saving 99.5% of the total files without taking much of the system resources and affecting user experience.","PeriodicalId":337798,"journal":{"name":"2022 International Conference on Electrical and Computing Technologies and Applications (ICECTA)","volume":"5 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-11-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 International Conference on Electrical and Computing Technologies and Applications (ICECTA)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICECTA57148.2022.9990424","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

Ransomware is a malicious software that attempts to encrypt the user’s files and demand a ransom in exchange for decrypting the files. This malware may have catastrophic impacts on the availability of data and consequently on the services provided by the infected organizations and institutes. Ransomware detection has been a challenge for researchers in the past few years. In this paper, we propose a behavioral ransomware detection method that utilizes fast selective hashing techniques. By selective we mean that only few selected blocks from a file are used for similarity comparison. Our experimental results demonstrate the efficacy of the proposed method in ransonware detection in terms of detection time. For 1000 files of a total size of 20GB and a detection threshold set to five files, our proposed system is able to detect a ransomware on average within 2.76 seconds saving 99.5% of the total files without taking much of the system resources and affecting user experience.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
使用选择性哈希的加密勒索软件检测
勒索软件是一种恶意软件,它试图加密用户的文件,并要求赎金来换取解密文件。此恶意软件可能对数据的可用性产生灾难性影响,从而影响受感染的组织和机构提供的服务。在过去的几年里,勒索软件检测一直是研究人员面临的一个挑战。在本文中,我们提出了一种利用快速选择性哈希技术的行为勒索软件检测方法。通过选择性,我们的意思是从文件中只有少数选定的块用于相似性比较。实验结果证明了该方法在检测时间方面的有效性。对于总大小为20GB的1000个文件,检测阈值设置为5个文件,我们提出的系统能够在2.76秒内平均检测到勒索软件,节省了总文件的99.5%,而不会占用太多系统资源并影响用户体验。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Centroid-Based Clustering Using Sentential Embedding Similarity Measure Moss-Based Biotechnological Air Purification Control System Studying the Effect of Face Masks in Identifying Speakers using LSTM Mental Stress Analysis using the Power Spectrum of fNIRS Signals RF LNA with Simultaneous Noise-Cancellation and Distortion-Cancellation for Wireless RF Systems
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1