Etd

Detecting Evasive Multiprocess Ransomware

Pubblico

Contenuto scaricabile

open in viewer

Recent work described techniques that could be used by ransomware to evade behavioral ransomware detectors by using multiple benign-looking processes to cooperatively encrypt files. We designed and evaluated two classifiers that each detect the presence of ransomware that uses those techniques with greater than 99 percent recall and with 100 percent precision. One of the classifiers can also determine which processes are part of the ransomware with greater than 95 percent recall but with a significant trade-off between precision and speed, achieving 92.4 percent precision after hundreds of files are encrypted. We prepared for a user study to collect a new dataset, developing the necessary client and server software.

Creator
Contributori
Degree
Unit
Publisher
Identifier
  • etd-20521
Parola chiave
Advisor
Defense date
Year
  • 2021
Date created
  • 2021-04-29
Resource type
Rights statement

Relazioni

In Collection:

Articoli

Elementi

Permanent link to this page: https://digital.wpi.edu/show/76537413p