Back to Search Start Over

Real-time system call-based ransomware detection.

Authors :
Chew, Christopher Jun Wen
Kumar, Vimal
Patros, Panos
Malik, Robi
Source :
International Journal of Information Security. Jun2024, Vol. 23 Issue 3, p1839-1858. 20p.
Publication Year :
2024

Abstract

Ransomware, particularly crypto ransomware, has emerged as the go-to malware for threat actors aiming to compromise data on Android devices as well as in general. In this paper, we present a ransomware detection technique based on behaviours observed in the system calls performed by the malware. We first describe our repeatable and extensible methodology for extracting the system call log and patterns. We then identify and present some common high-level system call behavioural patterns exhibited by crypto ransomware, and evaluate these patterns. We further describe the implementation of a streaming implementation that utilises regular expressions for modelling malware behaviours and finite state machines for detecting crypto ransomware behaviours in real time. The success of our proof of concept evaluation allows us to envision our proposed technique applied as part of a self-protection system on Android phones against malware. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
16155262
Volume :
23
Issue :
3
Database :
Academic Search Index
Journal :
International Journal of Information Security
Publication Type :
Academic Journal
Accession number :
177464361
Full Text :
https://doi.org/10.1007/s10207-024-00819-x