Limits of I/O Based Ransomware Detection: An Imitation Based Attack
Chijin Zhou, Lihua Guo, Yiwei Hou, Zhenya Ma, Quan Zhang, Mingzhe Wang, Zhe Liu, Yu Jiang
摘要
By encrypting the data of infected hosts, cryptographic ransomware has caused billions of dollars in financial losses to a wide range of victims. Many detection techniques have been proposed to counter ransomware threats over the past decade. Their common approach is to monitor I/O behaviors from user space and apply custom heuristics to discriminate ransomware. These techniques implicitly assume that ransomware behaves very differently from benign programs in terms of heuristics. However, when we investigated the behavior of benign and ransomware programs, we found that the boundary between their behaviors was blurred. A ransomware program can still achieve its goal even though it follows the behavior patterns of benign programs. In this paper, we aim to explore the limits of ransomware detection techniques that based on I/O behaviors. To this end, we present Animagus, an imitation-based ransomware attack that imitates behaviors of benign programs to disguise its encryption tasks. It first learns behavior patterns from a benign program, and then spawns and orchestrates child processes to perform encryption tasks behaving the same as the benign program. We evaluate its effectiveness against six state-of-the-art detection techniques, and the results show that it can successfully evade these defenses. We investigate in detail why they are ineffective and how Animagus is different from existing ransomware samples. In the end, we discuss potential countermeasures and the benefits that detection tools can gain from our work.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- An Empirical Study of Data Disruption by Ransomware AttacksYiwei Hou, Lihua Guo, Chijin Zhou, Yiwen Xu 等ICSE 2024 · 被引用 10 次
- CanCal: Towards Real-time and Lightweight Ransomware Detection and Response in Industrial EnvironmentsShenao Wang, Feng Dong, Hangfeng Yang, Jingheng Xu 等CCS 2024 · 被引用 10 次
- Building Dynamic System Call Sandbox with Partial Order AnalysisQuan Zhang, Chijin Zhou, Yiwen Xu, Zijing Yin 等OOPSLA 2023 · 被引用 5 次
- MalwareTotal: Multi-Faceted and Sequence-Aware Bypass Tactics against Static Malware DetectionShuai He, Cai Fu, Hong Hu, Jiahe Chen 等ICSE 2024 · 被引用 3 次
- Janus: Detecting Rendering Bugs in Web Browsers via Visual Delta ConsistencyChijin Zhou, Quan Zhang, Bingzhou Qian, Yu JiangICSE 2025 · 被引用 2 次
它引用的顶会 Paper10
- Tracking Ransomware End-to-endDanny Yuxing Huang, Maxwell Matthaios Aliapoulios, Vector Guo Li, Luca Invernizzi 等S&P 2018 · 被引用 208 次
- Understanding Linux MalwareEmanuele Cozzi, Mariano Graziano, Yanick Fratantonio, Davide BalzarottiS&P 2018 · 被引用 203 次
- The Circle Of Life: A Large-Scale Study of The IoT Malware LifecycleOmar Alrawi, Charles Lever, Kevin Valakuzhy, Ryan Court 等USENIX Security 2021 · 被引用 109 次
- FlashGuard: Leveraging Intrinsic Flash Properties to Defend Against Encryption RansomwareJian Huang, Jun Xu, Xinyu Xing, Peng Liu 等CCS 2017 · 被引用 94 次
- A Lustrum of Malware Network Communication: Evolution and InsightsChaz Lever, Platon Kotzias, Davide Balzarotti, Juan Caballero 等S&P 2017 · 被引用 86 次
相关 Paper
- UNVEIL: A Large-Scale, Automated Approach to Detecting RansomwareAmin Kharraz, Sajjad Arshad, Collin Mulliner, William K. Robertson 等USENIX Security 2016
- ERW-Radar: An Adaptive Detection System against Evasive Ransomware by Contextual Behavior Detection and Fine-grained Content AnalysisLingbo Zhao, Yuhui Zhang, Zhilu Wang, Fengkai Yuan 等NDSS 2025
- Ransomware Detection through Temporal Correlation between Encryption and I/O BehaviorLihua Guo, Yiwei Hou, Chijin Zhou, Quan Zhang 等FSE 2025
- Cryptographic Function Detection in Obfuscated Binaries via Bit-Precise Symbolic Loop MappingDongpeng Xu, Jiang Ming, Dinghao WuS&P 2017 · 被引用 83 次
- BinSim: Trace-based Semantic Binary Diffing via System Call Sliced Segment Equivalence CheckingJiang Ming, Dongpeng Xu, Yufei Jiang, Dinghao WuUSENIX Security 2017 · 被引用 118 次
