Inicio  /  Information  /  Vol: 15 Par: 1 (2024)  /  Artículo
ARTÍCULO
TITULO

A Holistic Approach to Ransomware Classification: Leveraging Static and Dynamic Analysis with Visualization

Bahaa Yamany    
Mahmoud Said Elsayed    
Anca D. Jurcut    
Nashwa Abdelbaki and Marianne A. Azer    

Resumen

Ransomware is a type of malicious software that encrypts a victim?s files and demands payment in exchange for the decryption key. It is a rapidly growing and evolving threat that has caused significant damage and disruption to individuals and organizations around the world. In this paper, we propose a comprehensive ransomware classification approach based on the comparison of similarity matrices derived from static, dynamic analysis, and visualization. Our approach involves the use of multiple analysis techniques to extract features from ransomware samples and to generate similarity matrices based on these features. These matrices are then compared using a variety of comparison algorithms to identify similarities and differences between the samples. The resulting similarity scores are then used to classify the samples into different categories, such as families, variants, and versions. We evaluate our approach using a dataset of ransomware samples and demonstrate that it can accurately classify the samples with a high degree of accuracy. One advantage of our approach is the use of visualization, which allows us to classify and cluster large datasets of ransomware in a more intuitive and effective way. In addition, static analysis has the advantage of being fast and accurate, while dynamic analysis allows us to classify and cluster packed ransomware samples. We also compare our approach to other classification approaches based on single analysis techniques and show that our approach outperforms these approaches in terms of classification accuracy. Overall, our study demonstrates the potential of using a comprehensive approach based on the comparison of multiple analysis techniques, including static analysis, dynamic analysis, and visualization, for the accurate and efficient classification of ransomware. It also highlights the importance of considering multiple analysis techniques in the development of effective ransomware classification methods, especially when dealing with large datasets and packed samples.

 Artículos similares

       
 
Zhidong Lu, Haichao Hong and Florian Holzapfel    
The advancement of electric vertical take-off and landing (eVTOL) aircraft has expanded the horizon of urban air mobility. However, the challenge of generating precise vertical take-off and landing (VTOL) trajectories that comply with airworthiness requi... ver más
Revista: Aerospace

 
Adil Redaoui, Amina Belalia and Kamel Belloulata    
Deep network-based hashing has gained significant popularity in recent years, particularly in the field of image retrieval. However, most existing methods only focus on extracting semantic information from the final layer, disregarding valuable structura... ver más
Revista: Information

 
Abdulaziz Aldoseri, Khalifa N. Al-Khalifa and Abdel Magid Hamouda    
In an era defined by technological disruption, the integration of artificial intelligence (AI) into business processes is both strategic and challenging. As AI continues to disrupt and reshape industries and revolutionize business processes, organization... ver más

 
Kaitano Dube    
Oceans play a vital role in socioeconomic and environmental development by supporting activities such as tourism, recreation, and food provision while providing important ecosystem services. However, concerns have been raised about the threat that climat... ver más

 
Yongyu Qu, Bo Song, Shubing Cai, Pinzeng Rao and Xichen Lin    
Recently, the Chinese government has implemented stringent water requirements based on the concept of ?Basing four aspects on water resources?. However, existing research has inadequately addressed the constraints of water resources on population, city b... ver más
Revista: Water