Deep learning LSTM based ransomware detection

Sumith Maniath, Aravind Ashok, Prabaharan Poornachandran, V. G. Sujadevi, A. Sankar, Srinath Jan · 2017

There is a growing interest in academia and industry to employ dynamic analysis for automating malwares analysis. In dynamic analysis, Application Programming Interface (API) calls made by the executable is a promising source to identify the behavior of an application. The list of API calls made by a process can be considered as a word sequence. This work aims to detect ransomware behavior by employing Long-Short Term Memory (LSTM) networks for binary sequence classification of API calls. We present an automated approach to extract API calls from the log of modified sandbox environment and detect ransomware behavior. The proposed approach is expected to improve the automated analysis of large volume of malwares samples.

Read the paper · More papers on PaperTik