Back to Search
Start Over
Real-time system call-based ransomware detection.
- Source :
-
International Journal of Information Security . Jun2024, Vol. 23 Issue 3, p1839-1858. 20p. - Publication Year :
- 2024
-
Abstract
- Ransomware, particularly crypto ransomware, has emerged as the go-to malware for threat actors aiming to compromise data on Android devices as well as in general. In this paper, we present a ransomware detection technique based on behaviours observed in the system calls performed by the malware. We first describe our repeatable and extensible methodology for extracting the system call log and patterns. We then identify and present some common high-level system call behavioural patterns exhibited by crypto ransomware, and evaluate these patterns. We further describe the implementation of a streaming implementation that utilises regular expressions for modelling malware behaviours and finite state machines for detecting crypto ransomware behaviours in real time. The success of our proof of concept evaluation allows us to envision our proposed technique applied as part of a self-protection system on Android phones against malware. [ABSTRACT FROM AUTHOR]
- Subjects :
- *RANSOMWARE
*FINITE state machines
*MALWARE
Subjects
Details
- Language :
- English
- ISSN :
- 16155262
- Volume :
- 23
- Issue :
- 3
- Database :
- Academic Search Index
- Journal :
- International Journal of Information Security
- Publication Type :
- Academic Journal
- Accession number :
- 177464361
- Full Text :
- https://doi.org/10.1007/s10207-024-00819-x