DeepGuard: Deep Generative User-behavior Analytics for Ransomware Detection

Gaddisa Olani Ganfure, Chun Feng Wu, Yuan Hao Chang, Wei Kuan Shih

研究成果: Conference contribution同行評審

9 引文 斯高帕斯(Scopus)

摘要

In the last couple of years, the move to cyberspace provides a fertile environment for ransomware criminals like ever before. Notably, since the introduction of WannaCry, numerous ransomware detection solution has been proposed. However, the ransomware incidence report shows that most organizations impacted by ransomware are running state of the art ransomware detection tools. Hence, an alternative solution is an urgent requirement as the existing detection models are not sufficient to spot emerging ransomware treat. With this motivation, our work proposes "DeepGuard, "a novel concept of modeling user behavior for ransomware detection. The main idea is to log the file-interaction pattern of typical user activity and pass it through deep generative autoencoder architecture to recreate the input. With sufficient training data, the model can learn how to reconstruct typical user activity (or input) with minimal reconstruction error. Hence, by applying the three-sigma limit rule on the model's output, DeepGuard can distinguish the ransomware activity from the user activity. The experiment result shows that DeepGuard effectively detects a variant class of ransomware with minimal false-positive rates. Overall, modeling the attack detection with user-behavior permits the proposed strategy to have deep visibility of various ransomware families.

原文English
主出版物標題Proceedings - 2020 IEEE International Conference on Intelligence and Security Informatics, ISI 2020
發行者Institute of Electrical and Electronics Engineers Inc.
ISBN(電子)9781728188003
DOIs
出版狀態Published - 9 11月 2020
事件18th IEEE International Conference on Intelligence and Security Informatics, ISI 2020 - Virtual, Arlington, 美國
持續時間: 9 11月 202010 11月 2020

出版系列

名字Proceedings - 2020 IEEE International Conference on Intelligence and Security Informatics, ISI 2020

Conference

Conference18th IEEE International Conference on Intelligence and Security Informatics, ISI 2020
國家/地區美國
城市Virtual, Arlington
期間9/11/2010/11/20

指紋

深入研究「DeepGuard: Deep Generative User-behavior Analytics for Ransomware Detection」主題。共同形成了獨特的指紋。

引用此