Computer and Modernization

    Next Articles

Homology Analysis of Ransomware Based on Sequence Alignment

  

  1. (School of Information Technology & Network Security, Peoples Public Security University of China, Beijing 100076, China)
  • Received:2017-08-07 Online:2018-03-08 Published:2018-03-09

Abstract: The number of ransomware is increasing rapidly while few belong to new family, most of them are mutations. A new homologous analysis approach based on API sequence of ransomware is proposed. The paper uses sandbox to extract ransomwares dynamic behavior for analyzing API category, and then encodes the feature as well as removes the repetition. Also, the sequence alignment algorithm is used to calculate the similarity between different ransomware. The dataset for the experiment contains 6 different families of ransomware and their variants. The result shows that proposed method performs well in analyzing the homology of ransomware which can be used to distinguish unknown software.

Key words: ransomware, dynamic detection, sandbox, API sequence, sequence alignment

CLC Number: