首页> 外文会议>International symposium on foundations and practice of security >Extinguishing Ransomware - A Hybrid Approach to Android Ransomware Detection
【24h】

Extinguishing Ransomware - A Hybrid Approach to Android Ransomware Detection

机译:熄灭勒索软件-Android勒索软件检测的混合方法

获取原文

摘要

Mobile ransomware is on the rise and effective defense from it is of utmost importance to guarantee security of mobile users' data. Current solutions provided by antimalware vendors are signature-based and thus ineffective in removing ransomware and restoring the infected devices and files. Also, current state-of-the art literature offers very few solutions to effectively detecting and blocking mobile ransomware. Starting from these considerations, we propose a hybrid method able to effectively counter ransomware. The proposed method first examines applications to be used on a device prior to their installation (static approach) and then observes their behavior at runtime and identifies if the system is under attack (dynamic approach). To detect ransomware, the static detection method uses the frequency of opcodes while the dynamic detection method considers CPU usage, memory usage, network usage and system call statistics. We evaluate the performance of our hybrid detection method on a dataset that contains both ransomware and legitimate applications. Additionally, we evaluate the performance of the static and dynamic stand-alone methods for comparison. Our results show that although both static and dynamic detection methods perform well in detecting ransomware, their combination in a form of a hybrid method performs best, being able to detect ransomware with 100% precision and having a false positive rate of less than 4%.
机译:移动勒索软件正在兴起,对其进行有效防御对于确保移动用户数据的安全至关重要。反恶意软件供应商提供的当前解决方案是基于签名的,因此在删除勒索软件和还原受感染的设备和文件方面无效。此外,当前最新的文献还很少提供有效检测和阻止移动勒索软件的解决方案。从这些考虑出发,我们提出一种能够有效对抗勒索软件的混合方法。所提出的方法首先在安装之前检查要在设备上使用的应用程序(静态方法),然后在运行时观察其行为并确定系统是否受到攻击(动态方法)。为了检测勒索软件,静态检测方法使用操作码的频率,而动态检测方法考虑CPU使用率,内存使用率,网络使用率和系统调用统计信息。我们在包含勒索软件和合法应用程序的数据集上评估混合检测方法的性能。此外,我们评估静态和动态独立方法的性能以进行比较。我们的结果表明,尽管静态和动态检测方法在检测勒索软件方面均表现出色,但以混合方法的形式将它们组合在一起的效果最佳,能够以100%的精度检测勒索软件,且误报率低于4%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号