{"id":"https://openalex.org/W4281620512","doi":"https://doi.org/10.1109/csr54599.2022.9850340","title":"Machine Learning-based Ransomware Detection Using Low-level Memory Access Patterns Obtained From Live-forensic Hypervisor","display_name":"Machine Learning-based Ransomware Detection Using Low-level Memory Access Patterns Obtained From Live-forensic Hypervisor","publication_year":2022,"publication_date":"2022-07-27","ids":{"openalex":"https://openalex.org/W4281620512","doi":"https://doi.org/10.1109/csr54599.2022.9850340"},"language":"en","primary_location":{"id":"doi:10.1109/csr54599.2022.9850340","is_oa":false,"landing_page_url":"https://doi.org/10.1109/csr54599.2022.9850340","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE International Conference on Cyber Security and Resilience (CSR)","raw_type":"proceedings-article"},"type":"preprint","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2205.13765","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5037753337","display_name":"Manabu Hirano","orcid":"https://orcid.org/0000-0001-9780-6454"},"institutions":[{"id":"https://openalex.org/I131361393","display_name":"National Institute of Technology, Toyota College","ror":"https://ror.org/01nw25822","country_code":"JP","type":"education","lineage":["https://openalex.org/I131361393"]}],"countries":["JP"],"is_corresponding":true,"raw_author_name":"Manabu Hirano","raw_affiliation_strings":["National Institute of Technology, Toyota College,Department of Information and Computer Engineering,Toyota,Japan","Department of Information and Computer Engineering, National Institute of Technology, Toyota College, Toyota, Japan"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"National Institute of Technology, Toyota College,Department of Information and Computer Engineering,Toyota,Japan","institution_ids":["https://openalex.org/I131361393"]},{"raw_affiliation_string":"Department of Information and Computer Engineering, National Institute of Technology, Toyota College, Toyota, Japan","institution_ids":["https://openalex.org/I131361393"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5101610974","display_name":"Ryotaro Kobayashi","orcid":"https://orcid.org/0000-0001-5956-3455"},"institutions":[{"id":"https://openalex.org/I116465919","display_name":"Kogakuin University","ror":"https://ror.org/01wc2tq75","country_code":"JP","type":"education","lineage":["https://openalex.org/I116465919"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Ryotaro Kobayashi","raw_affiliation_strings":["Kogakuin University,Faculty of Informatics,Tokyo,Japan","Faculty of Informatics, Kogakuin University, Tokyo, Japan"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Kogakuin University,Faculty of Informatics,Tokyo,Japan","institution_ids":["https://openalex.org/I116465919"]},{"raw_affiliation_string":"Faculty of Informatics, Kogakuin University, Tokyo, Japan","institution_ids":["https://openalex.org/I116465919"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5037753337"],"corresponding_institution_ids":["https://openalex.org/I131361393"],"apc_list":null,"apc_paid":null,"fwci":1.1886,"has_fulltext":false,"cited_by_count":9,"citation_normalized_percentile":{"value":0.77138089,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":94,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"323","last_page":"330"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.982699990272522,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/hypervisor","display_name":"Hypervisor","score":0.8728105425834656},{"id":"https://openalex.org/keywords/ransomware","display_name":"Ransomware","score":0.8688933849334717},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.8687431812286377},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7737406492233276},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.5789932012557983},{"id":"https://openalex.org/keywords/virtual-machine","display_name":"Virtual machine","score":0.5055546760559082},{"id":"https://openalex.org/keywords/digital-forensics","display_name":"Digital forensics","score":0.4128195643424988},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3900802731513977},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3731516897678375},{"id":"https://openalex.org/keywords/virtualization","display_name":"Virtualization","score":0.29599347710609436},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.16865882277488708}],"concepts":[{"id":"https://openalex.org/C112904061","wikidata":"https://www.wikidata.org/wiki/Q1077480","display_name":"Hypervisor","level":4,"score":0.8728105425834656},{"id":"https://openalex.org/C2777667771","wikidata":"https://www.wikidata.org/wiki/Q926331","display_name":"Ransomware","level":3,"score":0.8688933849334717},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.8687431812286377},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7737406492233276},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.5789932012557983},{"id":"https://openalex.org/C25344961","wikidata":"https://www.wikidata.org/wiki/Q192726","display_name":"Virtual machine","level":2,"score":0.5055546760559082},{"id":"https://openalex.org/C84418412","wikidata":"https://www.wikidata.org/wiki/Q3246940","display_name":"Digital forensics","level":2,"score":0.4128195643424988},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3900802731513977},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3731516897678375},{"id":"https://openalex.org/C513985346","wikidata":"https://www.wikidata.org/wiki/Q270471","display_name":"Virtualization","level":3,"score":0.29599347710609436},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.16865882277488708}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/csr54599.2022.9850340","is_oa":false,"landing_page_url":"https://doi.org/10.1109/csr54599.2022.9850340","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE International Conference on Cyber Security and Resilience (CSR)","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:2205.13765","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2205.13765","pdf_url":"https://arxiv.org/pdf/2205.13765","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2205.13765","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2205.13765","pdf_url":"https://arxiv.org/pdf/2205.13765","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.6800000071525574,"display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[{"id":"https://openalex.org/F4320334764","display_name":"Japan Society for the Promotion of Science","ror":"https://ror.org/00hhkn466"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":15,"referenced_works":["https://openalex.org/W1504084862","https://openalex.org/W1995875735","https://openalex.org/W2052412856","https://openalex.org/W2098367901","https://openalex.org/W2106869436","https://openalex.org/W2460736843","https://openalex.org/W2766465617","https://openalex.org/W2774226757","https://openalex.org/W2810079886","https://openalex.org/W2998708406","https://openalex.org/W3003433587","https://openalex.org/W3168458510","https://openalex.org/W3203444100","https://openalex.org/W4200030734","https://openalex.org/W6674556555"],"related_works":["https://openalex.org/W2976854232","https://openalex.org/W2321466224","https://openalex.org/W2743348030","https://openalex.org/W2622620488","https://openalex.org/W2075174112","https://openalex.org/W2145292010","https://openalex.org/W3179371161","https://openalex.org/W3035751361","https://openalex.org/W4307424580","https://openalex.org/W1555324927"],"abstract_inverted_index":{"Since":[0],"modern":[1,91],"anti-virus":[2],"software":[3],"mainly":[4],"depends":[5],"on":[6],"a":[7,42,55],"signature-based":[8],"static":[9],"analysis,":[10],"they":[11],"are":[12],"not":[13],"suitable":[14],"for":[15],"coping":[16],"with":[17,62],"the":[18,101],"rapid":[19],"increase":[20],"in":[21,142],"malware":[22,113],"variants.":[23],"Moreover,":[24],"even":[25],"worse,":[26],"many":[27],"vulnerabilities":[28],"of":[29,59,80,107,140],"operating":[30,60],"systems":[31,61],"enable":[32],"attackers":[33],"to":[34,48],"evade":[35],"such":[36,83],"protection":[37,52,57],"mechanisms.":[38],"We,":[39],"therefore,":[40],"developed":[41,71],"thin":[43],"and":[44,87,115,145],"lightweight":[45],"live-forensic":[46,72],"hypervisor":[47,73],"create":[49],"an":[50,134],"additional":[51],"layer":[53,58],"under":[54],"conventional":[56],"supporting":[63],"ransomware":[64,109,144],"detection":[65],"using":[66,127],"dynamic":[67],"behavioral":[68],"features.":[69],"The":[70],"collects":[74],"low-level":[75,102,129],"memory":[76,103,130],"access":[77,104,131],"patterns":[78,105,132],"instead":[79],"high-level":[81],"information":[82],"as":[84],"process":[85],"IDs":[86],"API":[88],"calls":[89],"that":[90,121],"Virtual":[92],"Machine":[93],"Introspection":[94],"techniques":[95],"have":[96],"employed.":[97],"We":[98,119],"then":[99],"created":[100],"dataset":[106],"three":[108],"samples,":[110],"one":[111],"wiper":[112,146],"sample,":[114],"four":[116],"benign":[117],"applications.":[118],"confirmed":[120],"our":[122],"best":[123],"machine":[124],"learning":[125],"classifier":[126],"only":[128],"achieved":[133],"F":[135],"<inf":[136],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[137],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">1</inf>":[138],"score":[139],"0.95":[141],"detecting":[143],"malware.":[147]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":3}],"updated_date":"2026-05-25T08:39:21.599409","created_date":"2025-10-10T00:00:00"}
