...
首页> 外文期刊>Soft computing: A fusion of foundations, methodologies and applications >Ransomware detection method based on context-aware entropy analysis
【24h】

Ransomware detection method based on context-aware entropy analysis

机译:基于上下文感知熵分析的赎金软件检测方法

获取原文
获取原文并翻译 | 示例

摘要

Numerous countermeasures have been proposed since the first appearance of ransomware. However, many ransomware mutants continue to be created, and the damage they cause has been continually increasing. Existing antivirus tools are signature-dependent and cannot easily detect ransomware attack patterns. If the database used by the antivirus program does not contain the signature of the new malicious behavior, it is not possible to detect the new malware. Thus, the need has emerged for a normal/abnormal behavior analysis technique via a context-aware method. Therefore, a multilateral context-aware-based ransomware detection and response system model is presented in this paper. The proposed model is designed to preemptively respond to ransomware, and post-detection management is performed. An evaluation was conducted to obtain evidence that the given files were altered by ransomware through analyses based on multiple-context awareness. Entropy information was then used to detect abnormal behavior.
机译:已经提出了许多对策以来勒索制品的第一次出现。但是,许多赎金软件突变体继续创造,他们造成的损失一直不断增加。现有的防病毒工具是依赖于签名的,不能轻易检测勒索软件攻击模式。如果防病毒程序使用的数据库不包含新的恶意行为的签名,则无法检测到新的恶意软件。因此,已经通过上下文感知方法出现了正常/异常行为分析技术。因此,本文提出了一种基于多边背景感知的赎制软件检测和响应系统模型。所提出的模型旨在先抢先响应勒索软件,并且执行后检测结果。进行了评估以获得证据表明,通过基于多语境意识的分析,赎金软件通过分析来改变给定文件。然后使用熵信息来检测异常行为。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号