计算机与现代化

• 网络与通信 •    下一篇

基于序列比对的勒索病毒同源性分析

  

  1. (中国人民公安大学信息技术和网络安全学院,北京100076)
  • 收稿日期:2017-08-07 出版日期:2018-03-08 发布日期:2018-03-09
  • 作者简介:龚琪(1993-),女,湖南怀化人,中国人民公安大学信息技术和网络安全学院硕士研究生,研究方向:网络安全; 曹金璇(1968-),女,研究方向:网络安全; 芦天亮(1985-),男,讲师,研究方向:网络攻防,恶意代码。
  • 基金资助:
    国家重点研发计划“网络空间安全”重点专项(2017YFB0802804); 国家自然科学基金资助项目(61602489); 赛尔网络下一代互联网技术创新项目(NGII20160405)

Homology Analysis of Ransomware Based on Sequence Alignment

  1. (School of Information Technology & Network Security, Peoples Public Security University of China, Beijing 100076, China)
  • Received:2017-08-07 Online:2018-03-08 Published:2018-03-09

摘要: 勒索病毒近年来数量呈爆发式增长,但其中真正的新型家族并不多,多数为已有家族变种。通过研究恶意代码行为特征,提出一种基于序列比对的同源性分析方法。使用沙箱提取勒索病毒动态行为特征,抽取API调用类别,并进行编码、去重,结合序列比对算法计算不同恶意代码之间的相似性,从而分析同源性。数据集选取6类勒索家族及其变种。实验结果表明该方法能较好地分析勒索病毒同源性,并能很好地区分正常软件和勒索病毒。

关键词: 勒索软件, 动态检测, 沙箱, API序列, 序列比对

Abstract: The number of ransomware is increasing rapidly while few belong to new family, most of them are mutations. A new homologous analysis approach based on API sequence of ransomware is proposed. The paper uses sandbox to extract ransomwares dynamic behavior for analyzing API category, and then encodes the feature as well as removes the repetition. Also, the sequence alignment algorithm is used to calculate the similarity between different ransomware. The dataset for the experiment contains 6 different families of ransomware and their variants. The result shows that proposed method performs well in analyzing the homology of ransomware which can be used to distinguish unknown software.

Key words: ransomware, dynamic detection, sandbox, API sequence, sequence alignment

中图分类号: