用时间关联图识别勒索软件行为,实时区分恶意与正常操作。
Algorithmic Segmentation and Behavioral Profiling for Ransomware Detection Using Temporal-Correlation Graphs
- 构建时间关联图捕捉恶意活动的时序模式和关系
- 对多种勒索软件家族检测准确率高,尤其擅长识别新型变种
- 适合需要实时防御复杂攻击的企业安全团队
快速演化的网络威胁已超越传统检测方法,亟需能应对现代攻击者自适应、复杂行为的新方案。本文提出一种新框架,利用时间关联图建模恶意操作中的复杂关系与时间模式,动态捕捉行为异常,实现对真实场景中良性与恶意活动的可靠区分。大量实验表明,该框架在多种勒索软件家族上均表现出高精度、高召回率和整体检测准确率。对比评估显示,其性能优于传统的基于签名和启发式的方法,尤其在处理多态性及未知勒索软件变种方面表现更优。架构设计注重可扩展性与模块化,适用于企业级环境且资源效率高。对加密速度、异常模式和时间相关性的分析,深入揭示了勒索软件的运作策略,验证了框架对演化威胁的适应能力。研究推动了网络安全技术发展,融合动态图分析与机器学习,为未来威胁检测创新提供支持。结果表明,该方法有望变革组织应对复杂网络攻击的方式。
原文摘要 · Abstract (English)
The rapid evolution of cyber threats has outpaced traditional detection methodologies, necessitating innovative approaches capable of addressing the adaptive and complex behaviors of modern adversaries. A novel framework was introduced, leveraging Temporal-Correlation Graphs to model the intricate relationships and temporal patterns inherent in malicious operations. The approach dynamically captured behavioral anomalies, offering a robust mechanism for distinguishing between benign and malicious activities in real-time scenarios. Extensive experiments demonstrated the framework's effectiveness across diverse ransomware families, with consistently high precision, recall, and overall detection accuracy. Comparative evaluations highlighted its better performance over traditional signature-based and heuristic methods, particularly in handling polymorphic and previously unseen ransomware variants. The architecture was designed with scalability and modularity in mind, ensuring compatibility with enterprise-scale environments while maintaining resource efficiency. Analysis of encryption speeds, anomaly patterns, and temporal correlations provided deeper insights into the operational strategies of ransomware, validating the framework's adaptability to evolving threats. The research contributes to advancing cybersecurity technologies by integrating dynamic graph analytics and machine learning for future innovations in threat detection. Results from this study underline the potential for transforming the way organizations detect and mitigate complex cyberattacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。