MFMCNS: a multi-feature and multi-classifier network-based system for ransomworm detection

恶意软件 计算机科学 勒索软件 分类器(UML) 有效载荷(计算) 僵尸网络 数据挖掘 加密 寄主(生物学) 人工智能 计算机安全 互联网 操作系统 网络数据包 生态学 生物
作者
Ahmad O. Almashhadani,Domhnall Carlin,Mustafa Kaiiali,Sakir Sezer
出处
期刊:Computers & Security [Elsevier BV]
卷期号:121: 102860-102860 被引量:21
标识
DOI:10.1016/j.cose.2022.102860
摘要

Ransomware is a type of advanced malware that can encrypt a user's files or lock a computer system until a ransom has been paid. Ransomworm is a type of malware that combines the payload of ransomware with the propagation feature of a computer worm. Most host-based detection methods require the host to be infected and the payload to be executed first to be able to identify anomalies and detect the malware. By the time of infection, it might too late as some of the system's assets would have been already encrypted or exfiltrated by the malware. On the contrary, the network-based methods can be one of the crucial means in detecting ransomworm activities when it attempts to spread to infect other networks before executing the payload. Therefore, a thorough analysis of ransomworm network traffic can be one of the essential means for early detection. This paper presents a comprehensive behavioral analysis of ransomworm network traffic, taking WannaCry, which launched a worldwide cyberattack, and NotPetya as a case study. Two sets of related features were extracted based on two independent flow levels: session-based and time-based. On top of each set, an independent classifier was built. Moreover, to improve the reliability, a multi-feature and multi-classifier network-based system, MFMCNS, has been proposed. MFMCNS employs these classifiers working in parallel on different flow levels, then it adopts a fusion rule to combine the classifiers' decisions. The experimental results prove that MFMCNS is reliable and has high detection accuracy.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
刚刚
呜呜呜啦完成签到,获得积分10
2秒前
可爱的函函应助王炸采纳,获得10
2秒前
Planet_Rabbit完成签到 ,获得积分10
4秒前
4秒前
不爱有机完成签到,获得积分10
5秒前
优美卿关注了科研通微信公众号
5秒前
5秒前
6秒前
Jasper应助Zzy采纳,获得10
6秒前
风犬少年完成签到,获得积分10
7秒前
cdercder应助狐狸小姐采纳,获得10
7秒前
7秒前
无限凝芙发布了新的文献求助10
8秒前
9秒前
業業完成签到,获得积分10
9秒前
蓝天发布了新的文献求助10
11秒前
11秒前
凤凰山发布了新的文献求助10
13秒前
我我我发布了新的文献求助10
14秒前
Floy应助harmy采纳,获得10
14秒前
16秒前
寄翠完成签到,获得积分10
16秒前
刘成完成签到,获得积分10
17秒前
17秒前
kong完成签到,获得积分10
17秒前
18秒前
无限凝芙完成签到,获得积分10
18秒前
max完成签到,获得积分10
18秒前
19秒前
广广逛光咣完成签到,获得积分10
19秒前
19秒前
小狮子完成签到 ,获得积分10
20秒前
司佳雨发布了新的文献求助10
20秒前
优美卿发布了新的文献求助10
20秒前
fu完成签到,获得积分10
20秒前
Hello应助木卫二采纳,获得10
21秒前
李思超发布了新的文献求助280
22秒前
科研通AI6.1应助Echo采纳,获得10
23秒前
高分求助中
The Graphene Handbook (2019 Edition) 800
IEST-RP-CC018: Cleanroom Cleaning and Sanitization: Operating and Monitoring Procedures 600
Fundamentals of Pharmaceutical and Biologics Regulations: A Global Perspective, Second Edition 600
久松真一著作集〈第5巻〉禅と芸術 500
Fundamentals of Modern Mathematics: A Practical Review (Dover Books on Mathematics) 500
Cold War Transcended: Australia's China Policy, 1949-1990 470
Comprehensive Organic Synthesis 400
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6596612
求助须知:如何正确求助?哪些是违规求助? 8366591
关于积分的说明 17909352
捐赠科研通 5749165
什么是DOI,文献DOI怎么找? 2953130
邀请新用户注册赠送积分活动 1928440
关于科研通互助平台的介绍 1822223