ESCAPADE: Encryption-type-ransomeware: system call based pattern detection

dc.contributor.authorChew, Christopher J.W.en_NZ
dc.contributor.authorKumar, Vimalen_NZ
dc.contributor.authorPatros, Panosen_NZ
dc.contributor.authorMalik, Robien_NZ
dc.contributor.editorKutylowski, M.en_NZ
dc.contributor.editorZhang, J.en_NZ
dc.contributor.editorChen, C.en_NZ
dc.coverage.spatialVirtual, Melbourne, Australiaen_NZ
dc.date.accessioned2021-02-26T03:00:35Z
dc.date.available2021-02-26T03:00:35Z
dc.date.issued2020en_NZ
dc.description.abstractEncryption-type ransomware has risen in prominence lately as the go-to malware for threat actors aiming to compromise Android devices. In this paper, we present a ransomware detection technique based on behaviours observed in the system calls performed by the malware. We identify and present some common high-level system call behavioural patterns targeted at encryption-type ransomware and evaluate these patterns. We further present our repeatable and extensible methodology for extracting the system call log and patterns.
dc.format.mimetypeapplication/pdf
dc.identifier.citationChew, C., Kumar, V., Patros, P., & Malik, R. (2020). ESCAPADE: Encryption-type-ransomeware: system call based pattern detection. In M. Kutylowski, J. Zhang, & C. Chen (Eds.), Proceedings of 14th International Conference on Network and System Security (NSS 2020), LNCS 12570 (pp. 388–407). Virtual, Melbourne, Australia: Springer. https://doi.org/10.1007/978-3-030-65745-1_23en
dc.identifier.doi10.1007/978-3-030-65745-1_23en_NZ
dc.identifier.urihttps://hdl.handle.net/10289/14133
dc.language.isoen
dc.publisherSpringer
dc.relation.isPartOfProceedings of 14th International Conference on Network and System Security (NSS 2020), LNCS 12570en_NZ
dc.rightsThis is a post-peer-review, pre-copyedit version of an article published in Proceedings of 14th International Conference on Network and System Security (NSS 2020), LNCS 12570. The final authenticated version is available online at: http://dx.doi.org/10.1007/978-3-030-65745-1_23. © Springer Nature Switzerland AG 2020.
dc.sourceNSS 2020en_NZ
dc.titleESCAPADE: Encryption-type-ransomeware: system call based pattern detectionen_NZ
dc.typeConference Contribution
dspace.entity.typePublication
pubs.begin-page388
pubs.end-page407
pubs.finish-date2020-11-27en_NZ
pubs.publication-statusPublisheden_NZ
pubs.start-date2020-11-25en_NZ

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
ESCAPADE_accepted_ver.pdf
Size:
346.46 KB
Format:
Adobe Portable Document Format
Description:
Accepted version

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Research Commons Deposit Agreement 2017.pdf
Size:
188.11 KB
Format:
Adobe Portable Document Format
Description: