Etd

Detecting Evasive Multiprocess Ransomware

Public

Downloadable Content

open in viewer

Recent work described techniques that could be used by ransomware to evade behavioral ransomware detectors by using multiple benign-looking processes to cooperatively encrypt files. We designed and evaluated two classifiers that each detect the presence of ransomware that uses those techniques with greater than 99 percent recall and with 100 percent precision. One of the classifiers can also determine which processes are part of the ransomware with greater than 95 percent recall but with a significant trade-off between precision and speed, achieving 92.4 percent precision after hundreds of files are encrypted. We prepared for a user study to collect a new dataset, developing the necessary client and server software.

Creator
Contributors
Degree
Unit
Publisher
Identifier
  • etd-20521
Keyword
Advisor
Defense date
Year
  • 2021
Date created
  • 2021-04-29
Resource type
Rights statement

Relations

In Collection:

Items

Items

Permanent link to this page: https://digital.wpi.edu/show/76537413p