Universiti Teknologi Malaysia Institutional Repository

A proposed adaptive pre-encryption crypto-ransomware early detection model

Urooj, U. and Maarof, M. A. and Al-rimy, B. A. S. (2021) A proposed adaptive pre-encryption crypto-ransomware early detection model. In: 3rd International Cyber Resilience Conference, CRC 2021, 29 January 2021 - 31 January 2021, Virtual, Langkawi Island.

[img]
Preview
PDF
667kB

Official URL: http://dx.doi.org/10.1109/CRC50527.2021.9392548

Abstract

Crypto-ransomware is a malware that uses the system's cryptography functions to encrypt user data. The irreversible effect of crypto-ransomware makes it challenging to survive the attack compared to other malware categories. When a crypto-ransomware attack encrypts user files, it becomes difficult to access these files without having the decryption key. Due to the availability of ransomware development tool kits like Ransomware as a Service (RaaS), many ransomware variants are being developed. This contributes to the rise of ransomware attacks witnessed nowadays. However, the conventional approaches employed by malware detection solutions are not suitable to detect ransomware. This is because ransomware needs to be detected as early as before the encryption takes place. These attacks can effectively be handled only if detected during the pre-encryption phase. Early detection of ransomware attacks is challenging due to the limited amount of data available before encryption. An adaptive pre-encryption model is proposed in this paper which is expected to deal with the population concept drift of crypto-ransomware given the limited amount of data collected during the pre-encryption phase of the attack lifecycle. With such adaptability, the model can maintain up-to-date knowledge about the attack behavior and identify the polymorphic ransomware that continuously changes its behavior.

Item Type:Conference or Workshop Item (Paper)
Uncontrolled Keywords:crypto-ransomware, detection, pre-encryption
Subjects:Q Science > QA Mathematics > QA75 Electronic computers. Computer science
Divisions:Computing
ID Code:96028
Deposited By: Narimah Nawil
Deposited On:01 Jul 2022 08:48
Last Modified:01 Jul 2022 08:48

Repository Staff Only: item control page