首页> 外文会议>IEEE Symposium Series on Computational Intelligence >Augmented YARA Rules Fused With Fuzzy Hashing in Ransomware Triaging
【24h】

Augmented YARA Rules Fused With Fuzzy Hashing in Ransomware Triaging

机译:在勒索软件分类中融合模糊散列的增强型YARA规则

获取原文

摘要

Triaging is an initial stage of malware analysis to assess whether a sample is malware or not and the degree of similarity it holds with known malware. It can be applied to any malware category such as ransomware, which is a type of malware that blocks access to a system or data, usually by encrypting it. It has become the main modus operandi for cybercriminals to extort monies from victims due to the growth of cryptocurrencies. Consequently, it severely affects all types of users whether they be from corporates or ordinary home users. Ransomware can be prevented in several different ways, however, the simple and initial step in prevention is its triaging without execution. Several triaging methods are in use such as fuzzy hashing, import hashing and YARA rules, amongst all, YARA rules are one of the most popular and widely used methods. Nonetheless, its success or failure is dependent on the quality of rules employed for malware triaging. This paper performs ransomware triaging using fuzzy hashing, import hashing and YARA rules and demonstrates how YARA rules can be improved using fuzzy hashing to obtain relatively better triaging results. Subsequently, it proposes the augmented YARA rules fused with fuzzy hashing to obtain improved triaging results and performance efficiency in comparison to all three triaging methods individually. Finally, the paper demonstrates how the use of the fused YARA rules can improve triaging results irrespective of the type of malware.
机译:分类是恶意软件分析的初始阶段,用于评估样本是否为恶意软件以及其与已知恶意软件的相似程度。它可以应用于任何恶意软件类别,例如勒索软件,这是一种通常通过加密来阻止对系统或数据访问的恶意软件。由于加密货币的增长,它已成为网络犯罪分子勒索受害者金钱的主要手段。因此,它严重影响了所有类型的用户,无论它们来自公司还是普通家庭用户。勒索软件可以通过几种不同的方式进行预防,但是,预防的简单而初始的步骤是对其进行分类而无需执行。使用了多种分类方法,例如模糊哈希,导入哈希和YARA规则,其中,YARA规则是最流行和使用最广泛的方法之一。但是,其成功与否取决于恶意软件分类所采用规则的质量。本文使用模糊哈希,导入哈希和YARA规则执行勒索软件分类,并演示了如何使用模糊哈希改进YARA规则以获得相对较好的分类结果。随后,提出了与模糊散列融合的增强型YARA规则,与单独使用所有三种分类方法相比,可获得改进的分类结果和性能效率。最后,本文演示了如何使用融合的YARA规则可以改善分类结果,而与恶意软件的类型无关。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号