Entropy Based Method for Malicious File Detection
TL;DR: In this article , the authors proposed an approach for test case generation by enhancing the entropy-based threat tree model, which would improve malicious file identification, and the test case was generated based on the entropy tree model.
read more
Abstract: Ransomware is by no means a recent invention, having existed as far back as 1989, yet it still poses a real threat in the 21st century. Given the increasing number of computer users in recent years, this threat will only continue to grow, affecting more victims as well as increasing the losses incurred towards the people and organizations impacted in a successful attack. In most cases, the only remaining courses of action open to victims of such attacks were the following: either pay the ransom or lose their data. One commonly shared behavior by all crypto ransomware strains is that there will be attempts to encrypt the victims’ files at a certain point during the ransomware execution. This paper demonstrates a technique that can identify when these encrypted files are being generated and is independent of the strain of the ransomware. Previous research has highlighted the difficulty in differentiating between compressed and encrypted files using Shannon entropy, as both file types exhibit similar values. Among the experiments described in this study, one showed a unique characteristic for the Shannon entropy of encrypted file header fragments, which was used to differentiate between encrypted files and other high entropy files such as archives. The Shannon entropy of encrypted file header fragments has a unique characteristic in one of the tests discussed in this study. This property was used to distinguish encrypted files from other files with high entropy, such as archives. To overcome this drawback, this study proposed an approach for test case generation by enhancing the entropy-based threat tree model, which would improve malicious file identification. The file identification was enhanced by combining three entropy algorithms, and the test case was generated based on the threat tree model. This approach was then evaluated using accuracy measurements: True Positive, True Negative, False Positive, False Negative. A promising result is expected. This method solves the challenge of leveraging file entropy to distinguish compressed and archived files from ransomware-encrypted files in a timely manner.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
References
Technical Guide to Information Security Testing and Assessment
Karen A. Scarfone,Murugiah Souppaya,Amanda Cody,Angela Orebaugh +3 more
- 30 Sep 2008
TL;DR: This Special Publication 800-series reports on ITL's research, guidance, and outreach efforts in computer security and its collaborative activities with industry, government, and academic organizations.
Using Entropy Analysis to Find Encrypted and Packed Malware
R. Lyda,J. Hamrock +1 more
- 01 Mar 2007
TL;DR: Entropy analysis examines the statistical variation in malware executables, enabling analysts to quickly and efficiently identify packed and encrypted samples.
411
Fileprints: identifying file types by n-gram analysis
Wei-Jen Li,Ke Wang,Salvatore J. Stolfo,B. Herzog +3 more
- 15 Jun 2005
TL;DR: A method to analyze files to categorize their type using efficient 1-gram analysis of their binary contents using a compact representation the authors call a fileprint, effectively a simple means of representing all members of the same file type by a set of statistical1-gram models.
Quantifying the financial impact of IT security breaches
TL;DR: The key takeaway for corporate IT decision makers is that IT security breaches are extremely costly, and that the stock market has already factored in some level of optimal IT security investment by companies.
297
An Entropy-Based Network Anomaly Detection Method
TL;DR: The main goal of the article is to prove that an entropy-based approach is suitable to detect modern botnet-like malware based on anomalous patterns in network.