Ransomware, a fearsome and rapidly evolving cybersecurity threat, continues to inflict severe consequences on individuals and organizations worldwide. Traditional detection methods, reliant on static signatures and application behavioral patterns, are challenged by the dynamic nature of these threats. This paper introduces three primary contributions to address this challenge. First, we introduce a ransomware emulator. This tool is designed to safely mimic ransomware attacks without causing actual harm or spreading malware, making it a unique solution for studying ransomware behavior. Second, we demonstrate how we use this emulator to create storage I/O traces. These traces are then utilized to train machine-learning models. Our results show that these models are effective in detecting ransomware, highlighting the practical application of our emulator in developing responsible cybersecurity tools. Third, we show how our emulator can be used to mimic the I/O behavior of existing ransomware thereby enabling safe trace collection. Both the emulator and its application represent significant steps forward in ransomware detection in the era of machine-learning-driven cybersecurity.
翻译:勒索软件作为一种可怕且快速演变的网络安全威胁,持续对全球个人和组织造成严重后果。传统依赖静态签名和应用程序行为模式的检测方法,因这些威胁的动态性质而面临挑战。本文提出三项主要贡献以应对这一挑战。首先,我们介绍一种勒索软件模拟器。该工具旨在安全地模拟勒索软件攻击,而不会造成实际危害或传播恶意软件,使其成为研究勒索软件行为的独特解决方案。其次,我们展示如何利用该模拟器创建存储输入/输出(I/O)轨迹。这些轨迹随后用于训练机器学习模型。我们的结果表明,这些模型在检测勒索软件方面效果显著,凸显了模拟器在开发负责任的网络安全工具中的实际应用价值。第三,我们展示如何利用该模拟器模仿现有勒索软件的I/O行为,从而安全地收集轨迹。该模拟器及其应用均代表了在机器学习驱动的网络安全时代中勒索软件检测领域的重大进展。