arrow
返回

A Machine Learning-Based Ransomware Detection Method for Attackers' Neutralization Techniques Using Format-Preserving Encryption

delete2025-04-10
delete0
delete
OA
AI
J
Jaehyuk Lee
J
Jinwook Kim
H
Hanjo Jeong
K
Kyungroul Lee *
DOI:10.3390/s25082406delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Ransomware, a type of malware that first appeared in 1989, encrypts user files and demands money for decryption, causing increasing global damage. To reduce the impact of ransomware, various file-based detection technologies are being developed; however, these have limitations, such as difficulties in detecting ransomware that bypasses traditional methods like decoy files. A newer approach measures file entropy to detect infected files, but attackers counter this by using encoding algorithms like Base64 to bypass detection thresholds. Additionally, attackers can neutralize detection through format-preserving encryption (FPE), which allows files to be encrypted without changing their format, complicating detection. In this article, we present a machine learning-based method for detecting ransomware-infected files encrypted using FPE techniques. We employed various machine learning models, including K-Nearest Neighbors (KNN), Logistic Regression, and Decision Tree, and found that most trained models-except for Logistic Regression and Multi-Layer Perceptron (MLP)-effectively detected ransomware-infected files encrypted with FPE. In summary, to counter the ransomware neutralization attack using FPE and entropy manipulation, this paper proposes a machine learning-based method for detecting files infected with such manipulated ransomware entropy. The experimental results showed an average precision of 94.64% across various datasets, indicating that the proposed method effectively detects ransomware-infected files. Therefore, the findings of this study offer a solution to address new ransomware attacks that aim to bypass entropy-based detection techniques, contributing to the advancement of ransomware detection and the protection of users' files and systems.
Keyword:
FPE
ransomware detection and neutralization technologies
entropy
machine learning
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Sensors 封面图
Sensors
IF:
3.5
论文数:
7.2W
被引数:
20.9W

机构

M
Mokpo National University
学者数:
1.2K
论文数: 1.3K
被引数: 1.3K