勒索软件
计算机科学
熵(时间箭头)
人工智能
特征提取
数据挖掘
互联网
可视化
机器学习
恶意软件
计算机安全
操作系统
量子力学
物理
作者
XiZhen Deng,Ming Jiang,Mingcan Cen
标识
DOI:10.1109/iucc-cit-dsci-smartcns57392.2022.00015
摘要
With the rapid development and popularization of internet technologies such as AI and 5G, more and more organizations and individuals have suffered a dramatic increase in the number of ransomware attacks, which has brought substantial economic losses to them. Ransomware is an illegal act that blackmails victims into paying a ransom by locking their devices or encrypting files. Achieving fast and effective ransomware classification, attack intent and pattern analysis can improve the efficiency of security analysts and discover ransomware variants earlier. Therefore, we propose a new ransomware classification method, which uses the entropy map extracted from the ransomware binary file for classification. The entropy map retains more fine-grained features in the ransomware family, which can improve the classification result. Aiming at the problem of data imbalance among ransomware families, we propose a data augmentation method based on the Cycle-GAN network, which combines the fine-tuning technology in transfer learning to improve the classification result of the framework further. At the same time, the attention mechanism is introduced into VGG-16. It is used to enhance the ability of feature extraction of the network. The experimental results show that the proposed method achieves the best performance on 14 ransomware families, and the accuracy rate can reach 97.16%, which is better than other traditional ransomware visualization classification methods. Our proposed method still has the best classification performance compared with other neural networks.
科研通智能强力驱动
Strongly Powered by AbleSci AI