Back to Search Start Over

RansomShield: A Visualization Approach to Defending Mobile Systems Against Ransomware.

Authors :
LACHTAR, NADA
IBDAH, DUHA
KHAN, HAMZA
BACHA, ANYS
Source :
ACM Transactions on Privacy & Security; Aug2023, Vol. 26 Issue 3, p1-30, 30p
Publication Year :
2023

Abstract

The unprecedented growth in mobile systems has transformed the way we approach everyday computing. Unfortunately, the emergence of a sophisticated type of malware known as ransomware poses a great threat to consumers of this technology. Traditional research on mobile malware detection has focused on approaches that rely on analyzing bytecode for uncovering malicious apps. However, cybercriminals can bypass such methods by embedding malware directly in native machine code, making traditional methods inadequate. Another challenge that detection solutions face is scalability. The sheer number of malware variants released every year makes it difficult for solutions to efficiently scale their coverage. To address these concerns, this work presents RansomShield, an energy-efficient solution that leverages CNNs to detect ransomware. We evaluate CNN architectures that have been known to perform well on computer vision tasks and examine their suitability for ransomware detection. We show that systematically converting native instructions from Android apps into images using space-filling curve visualization techniques enable CNNs to reliably detect ransomware with high accuracy. We characterize the robustness of this approach across ARM and x86 architectures and demonstrate the effectiveness of this solution across heterogeneous platforms including smartphones and chromebooks. We evaluate the suitability of different models for mobile systems by comparing their energy demands using different platforms. In addition, we present a CNN introspection framework that determines the important features that are needed for ransomware detection. Finally, we evaluate the robustness of this solution against adversarial machine learning (AML) attacks using state-of-the-art Android malware dataset. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
24712566
Volume :
26
Issue :
3
Database :
Complementary Index
Journal :
ACM Transactions on Privacy & Security
Publication Type :
Academic Journal
Accession number :
170017037
Full Text :
https://doi.org/10.1145/3579822