Vestnik of Astrakhan State Technical University. Series: Management, Computer Sciences and Informatics
RUS  ENG    JOURNALS   PEOPLE   ORGANISATIONS   CONFERENCES   SEMINARS   VIDEO LIBRARY   PACKAGE AMSBIB  
General information
Latest issue
Archive
Impact factor

Search papers
Search references

RSS
Latest issue
Current issues
Archive issues
What is RSS



Vestn. Astrakhan State Technical Univ. Ser. Management, Computer Sciences and Informatics:
Year:
Volume:
Issue:
Page:
Find






Personal entry:
Login:
Password:
Save password
Enter
Forgotten password?
Register


Vestnik of Astrakhan State Technical University. Series: Management, Computer Sciences and Informatics, 2020, Number 1, Pages 41–49
DOI: https://doi.org/10.24143/2072-9502-2020-1-41-49
(Mi vagtu614)
 

COMPUTER SOFTWARE AND COMPUTING EQUIPMENT

Method of detecting virus-encoders in computer system using analysis of their behavior

A. B. Kaliev, A. N. Marenkov

Astrakhan State University, Astrakhan, Russian Federation
References:
Abstract: The article considers the low efficiency of existing methods of ransomware fighting. The importance of developing new approaches to the ransomware identification in computer systems (CS) is substantiated. Heuristic analysis methods are considered as new approaches to ransomware detecting. A new technique for ransomware detecting is based on the analysis of changes in CS parameters. Using machine-learning methods there have been constructed models, which allow detecting ransomware attacks on the computer system. The aim of the experiment was to obtain a model that has the highest percentage of ransomware attacks detection and the least number of false triggering. The machine learning lgorithms used for research are the following: naive Bayes classifier, multilayer neural network, support vector machine, CatBoost gradient boosting algorithm. To build the models training datasets written in Python programming language were used. The raining datasets were collected as a result of experiments with the most popular virus-encoders. The following typical metrics were selected as key metrics for the effectiveness of machine learning models: precision, recall, F1-metric, accuracy, AUC. In the course of experiments, the values of the error matrices were formed and the main indicators of the model quality metrics were obtained. In addition to the classification efficiency metrics, the average time for performing classification operations for each of the models is given. During the process of model training and testing it was revealed that the best model for detecting ransomware is that built on the CatBoost algorithm. The conclusions were drawn about the possibility of applying the approach to detect the ransomware attacks on various computer systems.
Keywords: ransomware virus, virus detection, computer system, software, parameters, heuristic analysis methods, machine learning.
Received: 12.09.2019
Document Type: Article
UDC: 004.056.57
Language: Russian
Citation: A. B. Kaliev, A. N. Marenkov, “Method of detecting virus-encoders in computer system using analysis of their behavior”, Vestn. Astrakhan State Technical Univ. Ser. Management, Computer Sciences and Informatics, 2020, no. 1, 41–49
Citation in format AMSBIB
\Bibitem{KalMar20}
\by A.~B.~Kaliev, A.~N.~Marenkov
\paper Method of detecting virus-encoders in computer system using analysis of their behavior
\jour Vestn. Astrakhan State Technical Univ. Ser. Management, Computer Sciences and Informatics
\yr 2020
\issue 1
\pages 41--49
\mathnet{http://mi.mathnet.ru/vagtu614}
\crossref{https://doi.org/10.24143/2072-9502-2020-1-41-49}
Linking options:
  • https://www.mathnet.ru/eng/vagtu614
  • https://www.mathnet.ru/eng/vagtu/y2020/i1/p41
  • Citing articles in Google Scholar: Russian citations, English citations
    Related articles in Google Scholar: Russian articles, English articles
    Вестник Астраханского государственного технического университета. Серия: Управление, вычислительная техника и информатика
    Statistics & downloads:
    Abstract page:251
    Full-text PDF :229
    References:13
     
      Contact us:
     Terms of Use  Registration to the website  Logotypes © Steklov Mathematical Institute RAS, 2024