arXiv:2501.15084cs.CRcs.AI2025-01被引 1

通过概率加密特征分析,分层识别勒索软件加密行为。

Hierarchical Pattern Decryption Methodology for Ransomware Detection Using Probabilistic Cryptographic Footprints

  • 基于加密模式的统计特性,分层融合聚类与机器学习
  • 在多种勒索软件家族中实现高准确率与低误报率
  • 适合需要实时响应的网络安全防护场景

日益复杂的加密型勒索软件对检测与缓解提出了新挑战,本文提出一种基于概率密码学分析的分层框架。该方法聚焦加密模式的统计特征,结合先进聚类算法与机器学习,有效分离勒索软件引起的异常行为与正常操作,保持低误报率。通过跨多种勒索软件家族的全面测试,系统表现出优异性能。动态反馈机制使其适应不同加密复杂度与运行环境。基于熵的评估显示其对加密流程中微小偏差高度敏感,优于依赖静态签名或启发式规则的传统方法。计算基准测试验证了其可扩展性与效率,在高负载与复杂加密场景下仍保持稳定表现。实时聚类与异常评估支持快速响应,解决勒索软件检测中的关键延迟问题。与现有方法对比表明,其在应对长密钥及独特加密协议的高级勒索软件时检测效果显著提升。

原文摘要 · Abstract (English)

The increasing sophistication of encryption-based ransomware has demanded innovative approaches to detection and mitigation, prompting the development of a hierarchical framework grounded in probabilistic cryptographic analysis. By focusing on the statistical characteristics of encryption patterns, the proposed methodology introduces a layered approach that combines advanced clustering algorithms with machine learning to isolate ransomware-induced anomalies. Through comprehensive testing across diverse ransomware families, the framework demonstrated exceptional accuracy, effectively distinguishing malicious encryption operations from benign activities while maintaining low false positive rates. The system's design integrates dynamic feedback mechanisms, enabling adaptability to varying cryptographic complexities and operational environments. Detailed entropy-based evaluations revealed its sensitivity to subtle deviations in encryption workflows, offering a robust alternative to traditional detection methods reliant on static signatures or heuristics. Computational benchmarks confirmed its scalability and efficiency, achieving consistent performance even under high data loads and complex cryptographic scenarios. The inclusion of real-time clustering and anomaly evaluation ensures rapid response capabilities, addressing critical latency challenges in ransomware detection. Performance comparisons with established methods highlighted its improvements in detection efficacy, particularly against advanced ransomware employing extended key lengths and unique cryptographic protocols.

勒索软件检测概率分析异常检测机器学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。