Matches in SemOpenAlex for { <https://semopenalex.org/work/W4364382428> ?p ?o ?g. }
- W4364382428 endingPage "120017" @default.
- W4364382428 startingPage "120017" @default.
- W4364382428 abstract "Ransomware has been largely exploited by cybercriminals to target individuals and organizations. In response to the increasing number and magnitude of ransomware attacks, it is important to consider the following problems when designing a ransomware fingerprinting solution: (i) how to make the solution portable to different hardware platforms and different dynamic analysis reports, (ii) how to design a solution that considers real-world use-cases, and (iii) how to evaluate the solution under realistic and challenging evaluation scenarios. To deal with these problems, we propose SwiftR, a novel portable framework for cross-platform ransomware detection and fingerprinting. SwiftR provides an accurate ransomware detection capability that relies on raw hybrid features along with advanced deep learning techniques. SwiftR is cross-platform as it is agnostic to architectures and operating systems by leveraging two novel types of features: (1) the assembly code Intermediate Representation (IR) features that are derived from static analysis, and (2) word-based features that are derived from the behavioral analysis reports, which are produced during dynamic analysis. SwiftR is supervised, and consists of two novel components: (a) Static SwiftR that proposes a novel architecture, called Hierarchical Neural Network (HNN), and (b) Dynamic SwiftR that applies LSTM on word embedding sequences when the Static SwiftR provides a low probability confidence. SwiftR aims to address the limitations of previous works by considering real-world use cases and challenging evaluation scenarios, i.e., time-resiliency, unknown family resiliency, and production evaluation scenarios. In addition, we extensively evaluate SwiftR on a dataset of 40.3K samples, which is the largest one compared to previous works. An F1-score of 98%, 96%, and 94% is achieved for ransomware detection, segregation between ransomware and other malware, and ransomware family attribution respectively. Furthermore, SwiftR maintains its high performance when deployed in a production environment where it processes 183K samples." @default.
- W4364382428 created "2023-04-12" @default.
- W4364382428 creator A5028605138 @default.
- W4364382428 creator A5064834866 @default.
- W4364382428 creator A5081909889 @default.
- W4364382428 date "2023-09-01" @default.
- W4364382428 modified "2023-10-17" @default.
- W4364382428 title "SwiftR: Cross-platform ransomware fingerprinting using hierarchical neural networks on hybrid features" @default.
- W4364382428 cites W1832693441 @default.
- W4364382428 cites W2064675550 @default.
- W4364382428 cites W2111038628 @default.
- W4364382428 cites W2250539671 @default.
- W4364382428 cites W2558619741 @default.
- W4364382428 cites W2559964890 @default.
- W4364382428 cites W2601591992 @default.
- W4364382428 cites W2724134549 @default.
- W4364382428 cites W2750688159 @default.
- W4364382428 cites W2765713146 @default.
- W4364382428 cites W2766662076 @default.
- W4364382428 cites W2775582065 @default.
- W4364382428 cites W2780577826 @default.
- W4364382428 cites W2784113120 @default.
- W4364382428 cites W2789983203 @default.
- W4364382428 cites W2807312247 @default.
- W4364382428 cites W2887506070 @default.
- W4364382428 cites W2887954984 @default.
- W4364382428 cites W2893176864 @default.
- W4364382428 cites W2900633536 @default.
- W4364382428 cites W2928980918 @default.
- W4364382428 cites W2953056235 @default.
- W4364382428 cites W2962912862 @default.
- W4364382428 cites W2972552958 @default.
- W4364382428 cites W2988533489 @default.
- W4364382428 cites W3000953536 @default.
- W4364382428 cites W3070581385 @default.
- W4364382428 cites W3080622597 @default.
- W4364382428 cites W3099702369 @default.
- W4364382428 cites W3100777112 @default.
- W4364382428 cites W3119994573 @default.
- W4364382428 cites W3122507336 @default.
- W4364382428 cites W3183350623 @default.
- W4364382428 cites W3196064684 @default.
- W4364382428 cites W3196515948 @default.
- W4364382428 cites W3205163562 @default.
- W4364382428 cites W4200569302 @default.
- W4364382428 cites W4242193627 @default.
- W4364382428 cites W4242460247 @default.
- W4364382428 cites W4283275666 @default.
- W4364382428 cites W4285495947 @default.
- W4364382428 cites W4293106276 @default.
- W4364382428 cites W4293581639 @default.
- W4364382428 cites W4297477879 @default.
- W4364382428 cites W4307454796 @default.
- W4364382428 cites W4311773726 @default.
- W4364382428 cites W4318407315 @default.
- W4364382428 cites W4320179452 @default.
- W4364382428 cites W4321365946 @default.
- W4364382428 doi "https://doi.org/10.1016/j.eswa.2023.120017" @default.
- W4364382428 hasPublicationYear "2023" @default.
- W4364382428 type Work @default.
- W4364382428 citedByCount "1" @default.
- W4364382428 countsByYear W43643824282023 @default.
- W4364382428 crossrefType "journal-article" @default.
- W4364382428 hasAuthorship W4364382428A5028605138 @default.
- W4364382428 hasAuthorship W4364382428A5064834866 @default.
- W4364382428 hasAuthorship W4364382428A5081909889 @default.
- W4364382428 hasConcept C119857082 @default.
- W4364382428 hasConcept C124101348 @default.
- W4364382428 hasConcept C138885662 @default.
- W4364382428 hasConcept C154945302 @default.
- W4364382428 hasConcept C177264268 @default.
- W4364382428 hasConcept C199360897 @default.
- W4364382428 hasConcept C2776760102 @default.
- W4364382428 hasConcept C2777667771 @default.
- W4364382428 hasConcept C38652104 @default.
- W4364382428 hasConcept C41008148 @default.
- W4364382428 hasConcept C41895202 @default.
- W4364382428 hasConcept C50644808 @default.
- W4364382428 hasConcept C541664917 @default.
- W4364382428 hasConcept C90805587 @default.
- W4364382428 hasConcept C97686452 @default.
- W4364382428 hasConceptScore W4364382428C119857082 @default.
- W4364382428 hasConceptScore W4364382428C124101348 @default.
- W4364382428 hasConceptScore W4364382428C138885662 @default.
- W4364382428 hasConceptScore W4364382428C154945302 @default.
- W4364382428 hasConceptScore W4364382428C177264268 @default.
- W4364382428 hasConceptScore W4364382428C199360897 @default.
- W4364382428 hasConceptScore W4364382428C2776760102 @default.
- W4364382428 hasConceptScore W4364382428C2777667771 @default.
- W4364382428 hasConceptScore W4364382428C38652104 @default.
- W4364382428 hasConceptScore W4364382428C41008148 @default.
- W4364382428 hasConceptScore W4364382428C41895202 @default.
- W4364382428 hasConceptScore W4364382428C50644808 @default.
- W4364382428 hasConceptScore W4364382428C541664917 @default.
- W4364382428 hasConceptScore W4364382428C90805587 @default.
- W4364382428 hasConceptScore W4364382428C97686452 @default.
- W4364382428 hasLocation W43643824281 @default.
- W4364382428 hasOpenAccess W4364382428 @default.