针对企业共享存储的加密勒索软件,提出混合检测框架。
A Hybrid Framework For Crypto-Ransomware Detection In Enterprise Shared Storage

- 用区域兴趣分析网络流量,提取攻击线索。
- 机器学习模型检测精度达99.64%,零漏报。
- 适合安全团队在文件服务器环境部署使用。
多数企业限制敏感数据存储在终端设备上,导致勒索软件转向攻击网络驱动器和共享存储资源。传统终端检测机制难以发现此类攻击,因服务器自身行为未明显改变。本文提出一种混合检测框架,通过新方法‘区域兴趣(RoI)’分析网络流量,提取入侵指标(IoCs)。该指标库可增强EDR、IDS等现有安全工具;同时利用RoI特征训练机器学习模型,以识别高度隐蔽的勒索软件变种。研究涵盖更广泛的勒索软件家族,并基于领域知识筛选良性行为,避免误判常见用户操作。除签名式IoCs外,机器学习模块实现99.64%检测精度,假阴率0%,假阳性率极低。该方法可提前发现入侵,准确率达99.44%,有效防范重大损失。
原文摘要 · Abstract (English)
Most corporate workplace environments enforce policies and technical controls that limit the storage of sensitive data on client endpoints. Consequently, ransomware operators have evolved variants that expand their attack surface from local systems to network drives and shared storage resources. As traditional endpoint detection mechanisms focus primarily on local system behaviour, a compromised client can impact remote file servers, such as by encrypting shared data, without directly triggering behavioural changes on the servers themselves. In this paper, we propose a hybrid detection framework for detecting crypto-ransomware intrusion within integrated file server and client environments. The framework is based on a new technique referred to as Region of Interest (RoI) to analyse network traffic and extract Indicators of Compromise (IoCs). The IoC repository serves as an additional ruleset to enhance existing security tools such as EDRs and IDSs, while RoI-derived features are used to train an ML model to detect highly evasive variants. This study incorporates a broader set of ransomwares families and carefully selected benign behaviors based on domain expertise, ensuring coverage of common user actions that could interfere with ransomware detection. Beyond IoCs, which operate in a signature-based manner, our machine learning module achieves a detection precision of 99.64%, with a 0% false negative rate (FNR) and a minimal false positive rate (FPR). Furthermore, the proposed method enables early detection, identifying ransomware intrusions before significant damage occurs, achieving an accuracy of 99.44%.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。