We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

cs

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Cryptography and Security

Title: Machine Learning-based Ransomware Detection Using Low-level Memory Access Patterns Obtained From Live-forensic Hypervisor

Abstract: Since modern anti-virus software mainly depends on a signature-based static analysis, they are not suitable for coping with the rapid increase in malware variants. Moreover, even worse, many vulnerabilities of operating systems enable attackers to evade such protection mechanisms. We, therefore, developed a thin and lightweight live-forensic hypervisor to create an additional protection layer under a conventional protection layer of operating systems with supporting ransomware detection using dynamic behavioral features. The developed live-forensic hypervisor collects low-level memory access patterns instead of high-level information such as process IDs and API calls that modern Virtual Machine Introspection techniques have employed. We then created the low-level memory access patterns dataset of three ransomware samples, one wiper malware sample, and four benign applications. We confirmed that our best machine learning classifier using only low-level memory access patterns achieved an $F_1$ score of 0.95 in detecting ransomware and wiper malware.
Comments: 8 pages
Subjects: Cryptography and Security (cs.CR)
Journal reference: 2022 IEEE International Conference on Cyber Security and Resilience (CSR), 2022, pp. 323-330
DOI: 10.1109/CSR54599.2022.9850340
Cite as: arXiv:2205.13765 [cs.CR]
  (or arXiv:2205.13765v2 [cs.CR] for this version)

Submission history

From: Manabu Hirano [view email]
[v1] Fri, 27 May 2022 05:50:16 GMT (787kb,D)
[v2] Thu, 18 Aug 2022 06:05:20 GMT (787kb,D)

Link back to: arXiv, form interface, contact.