DEFEAT:拼接碎片化文件I/O上下文以实现早期勒索软件检测
DEFEAT: Stitching Fragmented File I/O Contexts for Early Ransomware Detection
浏览论文内容
中文总结 AI 辅助
针对勒索软件碎片化文件操作逃避检测的问题,提出DEFEAT框架,通过构建文件事件小工具重建上下文,利用图神经网络聚类,在首个文件加密时实现99.2%准确率的早期检测,并减少94%标注工作量。
中文摘要 AI 辅助
勒索软件日益将其文件操作分散在临时文件和中间文件中,将单个I/O事件与整体加密活动联系起来的语义上下文散布开来。这种碎片化使现有基于孤立文件流推理的检测器失效——无论是匹配刚性事件序列的模式方法,还是需要跨多个文件积累统计证据的学习方法。我们提出DEFEAT,一个通过将因果相关的文件事件分组为文件事件小工具(FEGs)来重建这种碎片化、分散上下文的框架,FEGs是语义连贯的单元,捕获跨越多个动态创建文件的文件操作序列背后的完整意图。与溯源图(记录整个系统中所有操作系统实体(如进程、文件、套接字和注册表键)之间关系的系统范围因果图)不同,FEGs限定于单个用户资产的文件操作上下文,无需全系统插桩即可实现轻量级、针对性分析。每个FEG被建模为属性控制流图(ACFG),并通过图神经网络嵌入以进行无监督聚类,使分析人员能够标记整个行为簇而非单个样本,将标注工作量减少94%。在包含97,816,471个文件I/O事件、涵盖67个勒索软件家族的数据集上评估,DEFEAT实现了99.2%的检测准确率,并比最先进方法(包括UNVEIL、RWGuard和Peeler)高出6.57%至7.56%。该框架以单个文件加密为粒度运行:由于每个ACFG恰好代表一个FEG(一个用户资产上下文),一旦第一个文件操作完成即可分配簇标签,从而在第一个加密文件时实现检测。
英文摘要
Ransomware increasingly fragments its file operations across temporary and intermediate files, scattering the semantic context that links individual I/O events to an overarching encryption campaign. This fragmentation defeats existing detectors that reason over isolated file streams -- whether pattern-based methods that match rigid event sequences or learning-based methods that require accumulating statistical evidence across many files. We present DEFEAT, a framework that reconstructs this fragmented, scattered context by grouping causally related file events into File Event Gadgets (FEGs), semantically coherent units that capture the full intent behind sequences of file operations spanning multiple dynamically created files. Unlike provenance graphs (system-wide causal graphs that record relationships among all OS entities, such as processes, files, sockets, and registry keys, across the entire system), FEGs are scoped to the file-operation context of a single user asset, enabling lightweight, targeted analysis without whole-system instrumentation. Each FEG is modelled as an attributed control flow graph (ACFG) and embedded via a graph neural network for unsupervised clustering, enabling analysts to label entire behavioural clusters rather than individual samples, reducing annotation effort by 94%. Evaluated on a corpus of 97,816,471 file I/O events spanning 67 ransomware families, DEFEAT achieves 99.2% detection accuracy and outperforms state-of-the-art methods including UNVEIL, RWGuard, and Peeler by 6.57 to 7.56%. The framework operates at the granularity of a single file encryption: because each ACFG represents exactly one FEG (one user asset context), a cluster label can be assigned as soon as the first file operation completes, enabling detection at the first encrypted file.
发表机构
- CSIRO Technology(澳大利亚联邦科学与工业研究组织)
- Sungkyunkwan University(成均馆大学)
- Hankuk University of Foreign Studies(韩国外国语大学)
- Qatar University(卡塔尔大学)
机构由 AI 辅助整理,请以论文原文为准。