Effective Ransomware Detection Using Entropy Estimation of Files for Cloud Services

A variety of data-based services such as cloud services and big data-based services have emerged in recent times. These services store data and derive the value of the data. The reliability and integrity of the data must be ensured. Unfortunately, attackers have taken valuable data as hostage for mo...

Full description

Bibliographic Details
Main Authors: Kyungroul Lee, Jaehyuk Lee, Sun-Young Lee, Kangbin Yim
Format: Article
Language:English
Published: MDPI AG 2023-03-01
Series:Sensors
Subjects:
Online Access:https://www.mdpi.com/1424-8220/23/6/3023
_version_ 1827747739099725824
author Kyungroul Lee
Jaehyuk Lee
Sun-Young Lee
Kangbin Yim
author_facet Kyungroul Lee
Jaehyuk Lee
Sun-Young Lee
Kangbin Yim
author_sort Kyungroul Lee
collection DOAJ
description A variety of data-based services such as cloud services and big data-based services have emerged in recent times. These services store data and derive the value of the data. The reliability and integrity of the data must be ensured. Unfortunately, attackers have taken valuable data as hostage for money in attacks called ransomware. It is difficult to recover original data from files in systems infected by ransomware because they are encrypted and cannot be accessed without keys. There are cloud services to backup data; however, encrypted files are synchronized with the cloud service. Therefore, the original file cannot be restored even from the cloud when the victim systems are infected. Therefore, in this paper, we propose a method to effectively detect ransomware for cloud services. The proposed method detects infected files by estimating the entropy to synchronize files based on uniformity, one of the characteristics of encrypted files. For the experiment, files containing sensitive user information and system files for system operation were selected. In this study, we detected 100% of the infected files in all file formats, with no false positives or false negatives. We demonstrate that our proposed ransomware detection method was very effective compared to other existing methods. Based on the results of this paper, we expect that this detection method will not synchronize with a cloud server by detecting infected files even if the victim systems are infected with ransomware. In addition, we expect to restore the original files by backing up the files stored on the cloud server.
first_indexed 2024-03-11T05:56:31Z
format Article
id doaj.art-b58c0b8284104649bf23f0db7de288e2
institution Directory Open Access Journal
issn 1424-8220
language English
last_indexed 2024-03-11T05:56:31Z
publishDate 2023-03-01
publisher MDPI AG
record_format Article
series Sensors
spelling doaj.art-b58c0b8284104649bf23f0db7de288e22023-11-17T13:44:48ZengMDPI AGSensors1424-82202023-03-01236302310.3390/s23063023Effective Ransomware Detection Using Entropy Estimation of Files for Cloud ServicesKyungroul Lee0Jaehyuk Lee1Sun-Young Lee2Kangbin Yim3Department of Information Security Engineering, Mokpo National University, Muan 58554, Republic of KoreaInterdisciplinary Program of Information & Protection, Mokpo National University, Muan 58554, Republic of KoreaDepartment of Information Security Engineering, Soonchunhyang University, Asan 31538, Republic of KoreaDepartment of Information Security Engineering, Soonchunhyang University, Asan 31538, Republic of KoreaA variety of data-based services such as cloud services and big data-based services have emerged in recent times. These services store data and derive the value of the data. The reliability and integrity of the data must be ensured. Unfortunately, attackers have taken valuable data as hostage for money in attacks called ransomware. It is difficult to recover original data from files in systems infected by ransomware because they are encrypted and cannot be accessed without keys. There are cloud services to backup data; however, encrypted files are synchronized with the cloud service. Therefore, the original file cannot be restored even from the cloud when the victim systems are infected. Therefore, in this paper, we propose a method to effectively detect ransomware for cloud services. The proposed method detects infected files by estimating the entropy to synchronize files based on uniformity, one of the characteristics of encrypted files. For the experiment, files containing sensitive user information and system files for system operation were selected. In this study, we detected 100% of the infected files in all file formats, with no false positives or false negatives. We demonstrate that our proposed ransomware detection method was very effective compared to other existing methods. Based on the results of this paper, we expect that this detection method will not synchronize with a cloud server by detecting infected files even if the victim systems are infected with ransomware. In addition, we expect to restore the original files by backing up the files stored on the cloud server.https://www.mdpi.com/1424-8220/23/6/3023cloud serviceentropymalicious coderansomware
spellingShingle Kyungroul Lee
Jaehyuk Lee
Sun-Young Lee
Kangbin Yim
Effective Ransomware Detection Using Entropy Estimation of Files for Cloud Services
Sensors
cloud service
entropy
malicious code
ransomware
title Effective Ransomware Detection Using Entropy Estimation of Files for Cloud Services
title_full Effective Ransomware Detection Using Entropy Estimation of Files for Cloud Services
title_fullStr Effective Ransomware Detection Using Entropy Estimation of Files for Cloud Services
title_full_unstemmed Effective Ransomware Detection Using Entropy Estimation of Files for Cloud Services
title_short Effective Ransomware Detection Using Entropy Estimation of Files for Cloud Services
title_sort effective ransomware detection using entropy estimation of files for cloud services
topic cloud service
entropy
malicious code
ransomware
url https://www.mdpi.com/1424-8220/23/6/3023
work_keys_str_mv AT kyungroullee effectiveransomwaredetectionusingentropyestimationoffilesforcloudservices
AT jaehyuklee effectiveransomwaredetectionusingentropyestimationoffilesforcloudservices
AT sunyounglee effectiveransomwaredetectionusingentropyestimationoffilesforcloudservices
AT kangbinyim effectiveransomwaredetectionusingentropyestimationoffilesforcloudservices