2.1 Malware Detection Based On Opcode Frequency (2016)

1 Malware Detection Based On Opcode Frequency (2016)

This research paper was presented by Abhijit Yewale & Maninder Singh of
Computer Science and Engineering Department Thapar University in International
Conference on Advanced Communication Control and Computing Technologies
This paper proposed a new method to detect malwares based on the frequency of
opcodes in the portable executable file. This research applied machine learning
algorithm to find false positives, false negatives, true positives and true negatives
for malwares. Success rate is 96.67%. It also had some challenges and drawbacks
like Signature based antivirus system is not useful for unknown malware detection
and they are facing difficulties because of polymorphic viruses and zero-day
attack. Signature based methods along with machine learning algorithm should be
developed for unknown malware. They classified portable executable(PE) file into
two categories only as goodware and malware. They should classify it further into
Torjan, Spyware, Backdoor etc.

2.2 Detecting Ransomware with Honeypot techniques (2016)

This research paper was presented by Chris Moore Computing and Media Services
University of St Mark & St John Plymouth, England in Cybersecurity and Cyber
forensics Conference & IEEE2016.
They researched on techniques to implement a honeypot to detect ransomware
activity. and selected two options, the File Screening service of the Microsoft File
Server Resource Manager feature and EventSentry to manipulate the Windows
Security logs. While it is possible to deploy honeypot type fake folders with
tripwire files for ransomware to interact with, the nature of the decoy folders is that
there is no guarantee the malware would attempt to invade these areas, and
therefore bypassing this defense. This limited view of a system is a disadvantage of
honeypots, as a honeypot free from attack alerts is not an indicator that other areas
are not being targeted.

2.3 Ransomware detection by mining API call usage (2016)

This research paper was presented by Shina Sheen, Ashwitha Yadav “Department
of Applied Mathematics and Computational Sciences” “PSG College of
Technology” Coimbatore, India in IEEE International.
In this research Application Programming Interface (API) calls are extracted from
the executables and the most discriminating API calls are used to train a classifier
to detect unknown ransomware. It is seen that Random forest with smote for class
imbalance has given a detection rate of over 98%. A large number of ransomware
samples have been analyzed and the discriminating API calls have been identified.
There were few drawbacks in dataset that was the number of ransomware samples
from virus share was very huge, the number of benign files became a minority
class which may lead to class imbalance problem. Features extracted through
dynamic analysis is also to be considered.

2.4 A Novel Method for Recovery from Crypto Ransomware Infections (2016)
This research paper was presented by Mattias Wecksten, Jan Frick, Andreas
Sjostrom, Eric Jarpe Halmstad University Sweden in 2nd IEEE International
Conference on Computer and Communications. In this research paper they used
crypto ransomware methods not only for prevention, but also focuses on how to
recreate the files. By renaming the system tool that handles shadow copies it is
possible to recover from infections from all four of the most common Crypto
Ransomwares. The solution is packaged in a single, easy to use script. The solution
presented in this paper should be implemented alongside other recommended
techniques, such as an updated antivirus, a properly configured firewall, updated
operating system and software, and a proper backup scheme.

2.5 Strategies for Ransomware Removal and Prevention (2018)

This research paper was presented by Smruti Saxena, Hemant Kumar Soni
Department of Computer Science and Engineering, Amity School of Engineering
and Technology, Amity University Madhya Pradesh, Gwalior in 4th International
Conference on Advances in Electrical, Electronics, Information, Communication
and Bio-Informatics (AEEICB-18).
This paper explores the various ransomware attack. In this paper they converse the
analysis of ransomware and the suggested action against ransomware attack. This
paper also discusses ransomware removal and preventional methodology. This
method has limited efficacy. This approach cannot trace modified ransomware
with new pattern. Hence an active instead of a passive prevention method is

2.6 Detection and Prevention of Crypto-Ransomware (2017)

This research paper was presented by Daniel Gonzalez Thaier Hayajneh Fordham
Center for Cybersecurity Fordham University, New York, NY, USA in IEEE 2017.
This research paper discusses ransomware methods of infection, technology behind
it and what can be done to help prevent becoming the next victim. The paper
investigates the most common types of crypto-ransomware, various payload
methods of infection, typical behavior of crypto ransomware. They don’t give any
specific technique for prevention or recovery. They have not used any specific
dataset or method but tested already existing methods without suggesting new
2.7 Ransomware detection using process mining and classification algorithms
This research paper was presented by Ala Bahrani, Amir Jalaly Bidgly Department
of computer engineering and IT University of Qom, Iran at 16th International ISC
Conference on Information Security and Cryptology (ISCISC).
The proposed method uses process mining to discover the process model from the
events logs, and then extracts features from this process model and using these
features and classification algorithms to classify ransomwares. This paper shows
that the use of classification algorithms along with the process mining can be
suitable to identify ransomware. It concludes that J48 and random forest
algorithms have the best accuracy to be used as the classifier in our proposed
method. The proposed method can be extended to identify other malware. The
proposed method can also be extended to various operating systems such as
Android, IOS etc.

2.8 An Intelligent Behavior-Based Ransomware Detection System for Android

Platform (2019)
This research paper was presented by Abdulrahman Alzahrani, Hani Alshahrani,
Ali Alshehri, and Huirong Fu Department of Computer Science and Engineering
Oakland University Rochester, Michigan 48309 at 2019 First IEEE International
Conference on Trust, Privacy and Security in Intelligent Systems and Applications
This paper introduces RanDetector, a new automated and lightweight system for
detecting ransomware applications in Android platform based on their behavior. In
particular, this detection system investigates the appearance of some information
that is related to ransomware operations in an inspected application before
integrating some supervised machine learning models to classify the application.
2.9 Triaging Ransomware using Fuzzy Hashing, Import Hashing and YARA
Rules (2019)
This research paper was presented by Nitin Naik & Paul Jenkins, Defence School
of Communications and Information Systems, U.K. Nick Savage: School of
Computing, University of Portsmouth, U.K., Longzhi Yang: Department of
Computer and Information Sciences, Northumbria University, U.K. at IEEE
Cyberthreat Hunting.
This paper presents an evaluation of fuzzy hashing, import hashing and YARA
rules, for triaging the four most pertinent ransomware categories WannaCry,
Locky, Cerber and CryptoWall. It evaluates their triaging performance and run-
time system performance, highlighting the limitations of each method.

2.10 Tracking Ransomware Threat Actors using Fuzzy Hashing and Fuzzy C-
Means Clustering (2019)
This research paper was presented by Nitin Naik & Paul Jenkins, Defence School
of Communications and Information Systems, U.K. Nick Savage: School of
Computing, University of Portsmouth, U.K., Longzhi Yang: Department of
Computer and Information Sciences, Northumbria University, U.K. at IEEE
Cyberthreat Hunting.
This paper proposes an efficient fuzzy analysis approach to cluster ransomware
samples based on the combination of two fuzzy techniques fuzzy hashing and
fuzzy c-means (FCM) clustering. The performance of the proposed fuzzy method
is compared against k-means clustering and the two fuzzy hashing methods
SSDEEP and SDHASH which are evaluated based on their FCM clustering results
to understand how the similarity score affects the clustering results.
