AIセキュリティポータル K Program
Ransomware Detection Using Machine Learning in the Linux Kernel
Share
Abstract
Linux-based cloud environments have become lucrative targets for ransomware attacks, employing various encryption schemes at unprecedented speeds. Addressing the urgency for real-time ransomware protection, we propose leveraging the extended Berkeley Packet Filter (eBPF) to collect system call information regarding active processes and infer about the data directly at the kernel level. In this study, we implement two Machine Learning (ML) models in eBPF - a decision tree and a multilayer perceptron. Benchmarking latency and accuracy against their user space counterparts, our findings underscore the efficacy of this approach.
A survey on ransomware detection and mitigation techniques
Hasan, R. A., AlSudani, A. M., AlSudani, M. A.
Published: 2018
Ransomware detection using the dynamic analysis and machine learning: A survey and research directions
U. Urooj, B. A. S. Al-rimy, A. Zainal, F. A. Ghaleb, M. A. Rassam
Published: 2021
Ransomware network traffic analysis for pre-encryption alert
Moussaileb, R., Cuppens, N., Lanet, J.-L., Le Bouder, H.
Published: 2020
Intrusion and ransomware detection system
El-Kosairy, A., Azer, M. A.
Published: 2018
A multi-classifier network-based crypto ransomware detection system: A case study of locky ransomware
Almashhadani, A. O., Kaiiali, M., Sezer, S., O’Kane, P.
Published: 2019
Real-time defense system using ebpf for machine learning-based ransomware detection method
Higuchi, K., Kobayashi, R.
Published: 2023
High-performance intrusion detection system using ebpf with machine learning algorithms
Anand, N., Saifulla, M., Aakula, P. K.
Published: 2023
Share