Real-Time Defense System using eBPF for Machine Learning-Based Ransomware Detection Method
Kosuke Higuchi, Ryotaro Kobayashi · 2023
Ransomware attacks targeting Linux, which is widely adopted in server environments, have been on the rise. Since countermeasures used in Windows cannot be applied directly to Linux due to system differences, Linux-specific countermeasures against ransomware have become important. Therefore, we study the behavior of Linux-specific cryptographic ransomware and propose a mechanism to prevent encryption without interfering with the operation of legitimate programs. Since file manipulation is a characteristic behavior of ransomware, we collect data on file read/write, deletion, and file renaming, and extract features from these data. Finally, machine learning is used for detection and classification. To support multiple Linux distributions, we employ the extended Berkeley Packet Filter (eBPF) to obtain file manipulation data. Prior research has studied ransomware detection, but none has focused on encrypted files. A notable novelty in our work is a protection feature to overcome the time lag of machine learning detection, where some or all of the files may be encrypted before detection. This proposal mechanism not only detects ransomware behavior, but also protects files in a specified set of directories. In this study, we constructed a decision system based on machine learning and executed the model in a real environment. Three experiments were conducted to evaluate the accuracy of machine learning, the file protection status, and the file protection status by changing the algorithm.