Matches in SemOpenAlex for { <https://semopenalex.org/work/W3107251728> ?p ?o ?g. }
Showing items 1 to 82 of
82
with 100 items per page.
- W3107251728 abstract "Among many prevailing malware, crypto-ransomware poses a significant threat as it financially extorts affected users by creating denial of access via unauthorized encryption of their documents as well as holding their documents hostage and financially extorting them. This results in millions of dollars of annual losses worldwide. Multiple variants of ransomware are growing in number with capabilities of evasion from many anti-viruses and software-only malware detection schemes that rely on static execution signatures. In this paper, we propose a hardware-assisted scheme, called RanStop, for early detection of crypto-ransomware infection in commodity processors. RanStop leverages the information of hardware performance counters embedded in the performance monitoring unit in modern processors to observe micro-architectural event sets and detects known and unknown crypto-ransomware variants. In this paper, we train a recurrent neural network-based machine learning architecture using long short-term memory (LSTM) model for analyzing micro-architectural events in the hardware domain when executing multiple variants of ransomware as well as benign programs. We create timeseries to develop intrinsic statistical features using the information of related HPCs and improve the detection accuracy of RanStop and reduce noise by via LSTM and global average pooling. As an early detection scheme, RanStop can accurately and quickly identify ransomware within 2ms from the start of the program execution by analyzing HPC information collected for 20 timestamps each 100us apart. This detection time is too early for a ransomware to make any significant damage, if none. Moreover, validation against benign programs with behavioral (sub-routine-centric) similarity with that of a crypto-ransomware shows that RanStop can detect ransomware with an average of 97% accuracy for fifty random trials." @default.
- W3107251728 created "2020-12-07" @default.
- W3107251728 creator A5016637403 @default.
- W3107251728 creator A5073054890 @default.
- W3107251728 creator A5074761519 @default.
- W3107251728 date "2020-11-24" @default.
- W3107251728 modified "2023-09-27" @default.
- W3107251728 title "RanStop: A Hardware-assisted Runtime Crypto-Ransomware Detection Technique." @default.
- W3107251728 cites W1550189296 @default.
- W3107251728 cites W1570448133 @default.
- W3107251728 cites W2064675550 @default.
- W3107251728 cites W2147568880 @default.
- W3107251728 cites W2166844173 @default.
- W3107251728 cites W2296579688 @default.
- W3107251728 cites W2461373307 @default.
- W3107251728 cites W2483568499 @default.
- W3107251728 cites W2513529237 @default.
- W3107251728 cites W2885096636 @default.
- W3107251728 cites W2113261561 @default.
- W3107251728 hasPublicationYear "2020" @default.
- W3107251728 type Work @default.
- W3107251728 sameAs 3107251728 @default.
- W3107251728 citedByCount "0" @default.
- W3107251728 crossrefType "posted-content" @default.
- W3107251728 hasAuthorship W3107251728A5016637403 @default.
- W3107251728 hasAuthorship W3107251728A5073054890 @default.
- W3107251728 hasAuthorship W3107251728A5074761519 @default.
- W3107251728 hasConcept C134306372 @default.
- W3107251728 hasConcept C148730421 @default.
- W3107251728 hasConcept C149635348 @default.
- W3107251728 hasConcept C178489894 @default.
- W3107251728 hasConcept C203014093 @default.
- W3107251728 hasConcept C2777667771 @default.
- W3107251728 hasConcept C2781251061 @default.
- W3107251728 hasConcept C33923547 @default.
- W3107251728 hasConcept C38652104 @default.
- W3107251728 hasConcept C41008148 @default.
- W3107251728 hasConcept C541664917 @default.
- W3107251728 hasConcept C77618280 @default.
- W3107251728 hasConcept C86803240 @default.
- W3107251728 hasConcept C8891405 @default.
- W3107251728 hasConceptScore W3107251728C134306372 @default.
- W3107251728 hasConceptScore W3107251728C148730421 @default.
- W3107251728 hasConceptScore W3107251728C149635348 @default.
- W3107251728 hasConceptScore W3107251728C178489894 @default.
- W3107251728 hasConceptScore W3107251728C203014093 @default.
- W3107251728 hasConceptScore W3107251728C2777667771 @default.
- W3107251728 hasConceptScore W3107251728C2781251061 @default.
- W3107251728 hasConceptScore W3107251728C33923547 @default.
- W3107251728 hasConceptScore W3107251728C38652104 @default.
- W3107251728 hasConceptScore W3107251728C41008148 @default.
- W3107251728 hasConceptScore W3107251728C541664917 @default.
- W3107251728 hasConceptScore W3107251728C77618280 @default.
- W3107251728 hasConceptScore W3107251728C86803240 @default.
- W3107251728 hasConceptScore W3107251728C8891405 @default.
- W3107251728 hasLocation W31072517281 @default.
- W3107251728 hasOpenAccess W3107251728 @default.
- W3107251728 hasPrimaryLocation W31072517281 @default.
- W3107251728 hasRelatedWork W1939231653 @default.
- W3107251728 hasRelatedWork W2034053858 @default.
- W3107251728 hasRelatedWork W2787931603 @default.
- W3107251728 hasRelatedWork W2792599578 @default.
- W3107251728 hasRelatedWork W2793829161 @default.
- W3107251728 hasRelatedWork W2793941832 @default.
- W3107251728 hasRelatedWork W2794482868 @default.
- W3107251728 hasRelatedWork W2800557391 @default.
- W3107251728 hasRelatedWork W2803498500 @default.
- W3107251728 hasRelatedWork W2890196927 @default.
- W3107251728 hasRelatedWork W2944012984 @default.
- W3107251728 hasRelatedWork W2968309075 @default.
- W3107251728 hasRelatedWork W2989404085 @default.
- W3107251728 hasRelatedWork W3010934630 @default.
- W3107251728 hasRelatedWork W3046012722 @default.
- W3107251728 hasRelatedWork W3047892252 @default.
- W3107251728 hasRelatedWork W3086358340 @default.
- W3107251728 hasRelatedWork W3129851363 @default.
- W3107251728 hasRelatedWork W3167818199 @default.
- W3107251728 hasRelatedWork W3211805103 @default.
- W3107251728 isParatext "false" @default.
- W3107251728 isRetracted "false" @default.
- W3107251728 magId "3107251728" @default.
- W3107251728 workType "article" @default.