arXiv:2501.18131cs.CRcs.AI2025-01被引 2

用熵同步神经哈希检测勒索软件,抗混淆和逃逸能力强。

Entropy-Synchronized Neural Hashing for Unsupervised Ransomware Detection

  • 基于文件熵特征生成动态哈希,与神经网络同步优化。
  • 对新型勒索软件检测率高,误报率低,跨家族分类稳定。
  • 适合研究恶意软件检测、安全防护系统的开发者参考。

基于熵的检测方法因能分析可执行文件中的结构异常,在识别采用高级混淆技术的恶意软件方面受到广泛关注。本文提出熵同步神经哈希(ESNH)框架,通过将熵特征与神经网络架构同步,生成鲁棒且唯一的哈希值,即使面对多态和变种攻击也保持稳定。相比传统方法,该模型在识别新威胁时表现更优,显著降低误报率,并在多种勒索软件家族间实现一致分类。自调节哈希收敛机制确保了哈希值在不同执行中不变,减少了因动态修改导致的分类不一致。实验表明,该模型对主流勒索软件样本具有高检测率,能有效抵御加密逃逸、代码注入和反射加载等常见规避手段。该框架无需依赖静态签名或启发式规则,具备捕捉可执行文件熵异常的内在能力,为应对传统方法的局限性提供了新思路。

原文摘要 · Abstract (English)

Entropy-based detection methodologies have gained significant attention due to their ability to analyze structural irregularities within executable files, particularly in the identification of malicious software employing advanced obfuscation techniques. The Entropy-Synchronized Neural Hashing (ESNH) framework introduces a novel approach that leverages entropy-driven hash representations to classify software binaries based on their underlying entropy characteristics. Through the synchronization of entropy profiles with neural network architectures, the model generates robust and unique hash values that maintain stability even when faced with polymorphic and metamorphic transformations. Comparative analysis against traditional detection approaches revealed superior performance in identifying novel threats, reducing false-positive rates, and achieving consistent classification across diverse ransomware families. The incorporation of a self-regulating hash convergence mechanism further ensured that entropy-synchronized hashes remained invariant across executions, minimizing classification inconsistencies that often arise due to dynamic modifications in ransomware payloads. Experimental results demonstrated high detection rates across contemporary ransomware strains, with the model exhibiting resilience against encryption-based evasion mechanisms, code injection strategies, and reflective loading techniques. Unlike conventional detection mechanisms that rely on static signatures and heuristic analysis, the proposed entropy-aware classification framework adapts to emerging threats through an inherent ability to capture entropy anomalies within executable structures. The findings reinforce the potential of entropy-based detection in addressing the limitations of traditional methodologies while enhancing detection robustness against obfuscation and adversarial evasion techniques.

勒索软件检测神经哈希熵分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。