Trusted detection of ransomware in a private cloud using machine learning methods leveraging meta-features from volatile memory.

Expert Systems with Applications(2018)

引用 90|浏览65
暂无评分
摘要
•A solution for trusted detection of unknown ransomware in VMs is proposed.•Valuable data is extracted from the VM's memory dump using the Volatility framework.•General descriptive features are proposed and successfully leveraged by ML algorithms.•The solution was rigorously evaluated using notorious and professional ransomwares.•The Random Forest classifier successfully detected known and unknown ransomware.
更多
查看译文
关键词
Ransomware,Volatile memory,Forensics,Memory dumps,Virtual machine,Private cloud,Machine Learning,Detection,Malware
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要