arXiv:2501.12811cs.CRcs.AI2025-01被引 5

无需签名库,实时识别多种勒索软件行为

Unveiling Zero-Space Detection: A Novel Framework for Autonomous Ransomware Identification in High-Velocity Environments

  • 通过无监督聚类与深度学习捕捉隐蔽行为模式
  • 对LockBit等主流勒索软件检测率超98%,误报率低
  • 适合高并发、资源受限的实时安全系统部署

现代网络安全环境亟需能精准、自适应识别演化威胁的检测框架。本文提出零空间检测(Zero-Space Detection)框架,通过无监督聚类与先进深度学习技术动态识别潜在行为模式。该框架克服传统基于签名和启发式方法的局限,结合多阶段过滤与集成学习,在高吞吐环境下实现精细决策。实验表明,对LockBit、Conti、REvil、BlackMatter等多样化勒索软件家族均实现高检测率,同时保持低误报率与可扩展性能。平均处理时间极低,支持真实场景下的实时系统运行,即使在峰值负载下亦无瓶颈。框架对混淆、加密速度变化等对抗策略具有强鲁棒性,且在多种数据源、文件类型与操作环境中表现一致。综合检测概率、延迟与资源效率指标验证其在真实条件下的有效性。模块化设计使其可无缝集成现有安全架构,无需重大重构。结果证明该框架在动态、资源受限环境中具备显著鲁棒性与可扩展性,为勒索软件识别提供变革性范式。

原文摘要 · Abstract (English)

Modern cybersecurity landscapes increasingly demand sophisticated detection frameworks capable of identifying evolving threats with precision and adaptability. The proposed Zero-Space Detection framework introduces a novel approach that dynamically identifies latent behavioral patterns through unsupervised clustering and advanced deep learning techniques. Designed to address the limitations of signature-based and heuristic methods, it operates effectively in high-velocity environments by integrating multi-phase filtering and ensemble learning for refined decision-making. Experimental evaluation reveals high detection rates across diverse ransomware families, including LockBit, Conti, REvil, and BlackMatter, while maintaining low false positive rates and scalable performance. Computational overhead remains minimal, with average processing times ensuring compatibility with real-time systems even under peak operational loads. The framework demonstrates resilience against adversarial strategies such as obfuscation and encryption speed variability, which frequently challenge conventional detection systems. Analysis across multiple data sources highlights its versatility in handling diverse file types and operational contexts. Comprehensive metrics, including detection probability, latency, and resource efficiency, validate its efficacy under real-world conditions. Through its modular architecture, the framework achieves seamless integration with existing cybersecurity infrastructures without significant reconfiguration. The results demonstrate its robustness and scalability, offering a transformative paradigm for ransomware identification in dynamic and resource-constrained environments.

勒索软件检测无监督学习实时安全行为分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。