ERW-Radar: An Adaptive Detection System against Evasive Ransomware by Contextual Behavior Detection and Fine-grained Content Analysis
Lingbo Zhao, Yuhui Zhang, Zhilu Wang, Fengkai Yuan, Rui Hou
Abstract
—To evade existing antivirus software and detection systems, ransomware authors tend to obscure behavior differences with benign programs by imitating them or by weakening malicious behaviors during encryption. Existing defense solutions have limited effects on defending against evasive ransomware. Fortunately, through extensive observation, we find I/O behaviors of evasive ransomware exhibit a unique repetitiveness during encryption. This is rarely observed in benign programs. Besides, the χ 2 test and the probability distribution of byte streams can effectively distinguish encrypted files from benignly modified files. Inspired by these, we first propose ERW-Radar, a detection system, to detect evasive ransomware accurately and efficiently. We make three breakthroughs: 1) a contextual Correlation mechanism to detect malicious behaviors; 2) a fine-grained content Analysis mechanism to identify encrypted files; and 3) adaptive mechanisms to achieve a better trade-off between accuracy and efficiency. Experiments show that ERW-Radar detects evasive ransomware with an accuracy of 96.18% while maintaining a FPR of 5.36%. The average overhead of ERW-Radar is 5.09% in CPU utilization and 3.80% in memory utilization.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9d4a3930-c907-475f-82e9-ae4f7c24fb7dBuilds on9
- Perceiver: General Perception with Iterative AttentionAndrew Jaegle, Felix Gimeno, Andy Brock, Oriol Vinyals et al.ICML 2021 · 1,399 citations
- Long Short-Term Transformer for Online Action DetectionMingze Xu, Yuanjun Xiong, Hao Chen, Xinyu Li et al.NeurIPS 2021 · 196 citations
- Shreds: Fine-Grained Execution Units with Private MemoryYaohui Chen, Sebassujeen Reymondjohnson, Zhichuang Sun, Long LuS&P 2016 · 116 citations
- FlashGuard: Leveraging Intrinsic Flash Properties to Defend Against Encryption RansomwareJian Huang, Jun Xu, Xinyu Xing, Peng Liu et al.CCS 2017 · 94 citations
- RSSD: defend against ransomware with hardware-isolated network-storage codesign and post-attack analysisBenjamin Reidys, Peng Liu, Jian HuangASPLOS 2022 · 28 citations
Related papers
- Ransomware Detection through Temporal Correlation between Encryption and I/O BehaviorLihua Guo, Yiwei Hou, Chijin Zhou, Quan Zhang et al.FSE 2025
- Limits of I/O Based Ransomware Detection: An Imitation Based AttackChijin Zhou, Lihua Guo, Yiwei Hou, Zhenya Ma et al.S&P 2023
- UNVEIL: A Large-Scale, Automated Approach to Detecting RansomwareAmin Kharraz, Sajjad Arshad, Collin Mulliner, William K. Robertson et al.USENIX Security 2016
- An Empirical Study of Data Disruption by Ransomware AttacksYiwei Hou, Lihua Guo, Chijin Zhou, Yiwen Xu et al.ICSE 2024 · 10 citations
- Preventing Disruption of System Backup against Ransomware AttacksYiwei Hou, Lihua Guo, Chijin Zhou, Quan Zhang et al.ISSTA 2025 · 1 citation
