TY - JOUR
T1 - Zero-day aware decision fusion-based model for crypto-ransomware early detection
AU - Al-rimy, Bander Ali Saleh
AU - Maarof, Mohd Aizaini
AU - Prasetyo, Yuli Adam
AU - Shaid, Syed Zainudeen Mohd
AU - Ariffin, Aswami Fadillah Mohd
N1 - Publisher Copyright:
© Penerbit UTHM.
PY - 2018/11/25
Y1 - 2018/11/25
N2 - Crypto-ransomware employs the cryptography to lock user personal files and demands ransom to release them. By utilizing several technological utilities like cyber-currency and cloud-based developing platforms, crypto-ransomware has gained high popularity among adversaries. Motivated by the monetary revenue, crypto-ransomware developers continuously produce many variants of such malicious programs to evade the detection. Consequently, the rate of crypto-ransomware novel attacks is continuously increasing. As such, it is imperative for detection solutions to be able to discover these novel attacks, also called zero-day attacks. While anomaly detection-based solutions are able to deal with this problem, they suffer the high rate of false alarms. Thus, this paper puts forward a detection model that incorporates anomaly with behavioral detection approaches. In this model, two types of detection estimators were built. The first type is an ensemble of behavioral-based classifiers whereas the second type is an anomaly-based estimator. The decisions of both types of estimators were combined using fusion technique. The proposed model is able to detect the novel attack while maintaining low false alarms rate. By applying the proposed model, the detection rate was increased from 96% to 99% and the false positive rate was as low as 2.4 %.
AB - Crypto-ransomware employs the cryptography to lock user personal files and demands ransom to release them. By utilizing several technological utilities like cyber-currency and cloud-based developing platforms, crypto-ransomware has gained high popularity among adversaries. Motivated by the monetary revenue, crypto-ransomware developers continuously produce many variants of such malicious programs to evade the detection. Consequently, the rate of crypto-ransomware novel attacks is continuously increasing. As such, it is imperative for detection solutions to be able to discover these novel attacks, also called zero-day attacks. While anomaly detection-based solutions are able to deal with this problem, they suffer the high rate of false alarms. Thus, this paper puts forward a detection model that incorporates anomaly with behavioral detection approaches. In this model, two types of detection estimators were built. The first type is an ensemble of behavioral-based classifiers whereas the second type is an anomaly-based estimator. The decisions of both types of estimators were combined using fusion technique. The proposed model is able to detect the novel attack while maintaining low false alarms rate. By applying the proposed model, the detection rate was increased from 96% to 99% and the false positive rate was as low as 2.4 %.
KW - Anomaly detection
KW - Crypto-ransomware
KW - Cryptography
KW - Ensemble learning
KW - Malware
UR - http://www.scopus.com/inward/record.url?scp=85059324054&partnerID=8YFLogxK
U2 - 10.30880/ijie.2018.10.06.011
DO - 10.30880/ijie.2018.10.06.011
M3 - Article
AN - SCOPUS:85059324054
SN - 2229-838X
VL - 10
SP - 82
EP - 88
JO - International Journal of Integrated Engineering
JF - International Journal of Integrated Engineering
IS - 6
ER -