首页> 外文会议>IEEE International Conference on Electro/Information Technology >RanDroid: Structural Similarity Approach for Detecting Ransomware Applications in Android Platform
【24h】

RanDroid: Structural Similarity Approach for Detecting Ransomware Applications in Android Platform

机译:RanDroid:在Android平台中检测勒索软件应用程序的结构相似性方法

获取原文

摘要

The worldwide epidemic of ransomware monetary gains has grown astonishingly. This crimeware form is emerged to extort innocent users under the threat of locking their devices and/or encrypting their files. To mitigate the growth of ransomware attacks, cybersecurity researchers have proposed various solutions based on the functionalities of those attacks. However, this polymorphic type is kept refined to increase the appearance of new families and survive against mitigation approaches. This paper introduces RanDroid, a new automated lightweight approach for detecting ransomware variants in Android platform by measuring the structural similarity between a set of collected information from an inspected application and a set of predefined threatening information collected from known ransomware variants. Furthermore, RanDroid performs a linguistic analysis on the app's code as well as image textural strings to enhance further revelation. RanDroid was evaluated using 950 ransomware samples. In addition, this approach is capable of extracting threatening messages from samples that use evasion techniques such as sophisticated codes or dynamic payloads.
机译:勒索软件货币收益在全球范围内的流行已惊人地增加。出现这种犯罪软件的形式是在锁定其设备和/或加密其文件的威胁下勒索无辜的用户。为了减轻勒索软件攻击的增长,网络安全研究人员已基于这些攻击的功能提出了各种解决方案。但是,此多态类型会不断完善,以增加新家族的外观并在缓解措施中生存。本文介绍了RanDroid,这是一种用于检测Android平台中勒索软件变体的新型自动化轻量级方法,它通过测量从受检查的应用程序收集的一组信息与从已知勒索软件变体收集的一组预定义威胁信息之间的结构相似性来进行检测。此外,RanDroid对应用程序的代码以及图像纹理字符串执行语言分析,以增强启示性。使用950个勒索软件样本对RanDroid进行了评估。此外,这种方法能够从使用规避技术(例如复杂代码或动态有效载荷)的样本中提取威胁消息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号