Machine learning could help companies react faster to ransomware

Exabeam uses machine learning, behavior analytics to help companies contain ransomware infections

File-encrypting ransomware programs have become one of the biggest threats to corporate networks worldwide and are constantly evolving by adding increasingly sophisticated detection-evasion and propagation techniques.

In a world where any self-respecting malware author makes sure that his creations bypass antivirus detection before releasing them, enterprise security teams are forced to focus on improving their response times to infections rather than trying to prevent them all, which is likely to be a losing game.

Exabeam, a provider of user and entity behavior analytics, believes that machine-learning algorithms can significantly improve ransomware detection and reaction time, preventing such programs from spreading inside the network and affecting a larger number of systems.

Because the decryption price asked by ransomware authors is calculated per system, isolating affected computers as soon as possible is critical. Only last week the University of Calgary announced that it paid 20,000 Canadian dollars (around US$15,600) to ransomware authors to get the decryption keys for multiple systems.

Exabeam's Analytics for Ransomware, a new product that was announced today, uses the company's existing behavior analytics technology to detect ransomware infections shortly after they occur.

The product uses data from a company's existing logs to build behavior profiles for computers and users. This allows it to detect previously unknown ransomware without pre-existing detection signatures by analyzing anomalies in the file and document behavior of employees.

To avoid false positive detections, the technology flags incidents as ransomware when the combined risk score of multiple suspicious activities that could indicate this type of threat reaches a certain threshold.

Exabeam's security research team is helping train the product in a laboratory by executing a very large number of ransomware samples on test computers and letting it observe their behavior in order to build threat models.

ransomware detection exabeam behaviour machine learning Exabeam

Exabeam builds a threat score based on behavioural anomalies.

The product does not have blocking capabilities itself and is intended to be used by a company's security analysts to quickly spot and respond to security incidents. It is available as an add-on to the company's larger analytics platform, which can already detect violations of internal company security policies.

Even though there's no built-in threat neutralization functionality, the platform can integrate with other security tools and allow analysts to create administrative scripts that are executed automatically when an incident is detected -- for example, to immediately isolate an infected computer from the rest of the network.

Ransomware is typically distributed through drive-by download attacks and phishing emails, which means that computers are affected one-by-one, based on users' actions. However, in a corporate setting, ransomware can easily spread beyond a single computer by affecting files on document-sharing servers and other collaboration services used by employees.

Recently, some ransomware programs even gained worm-like, self-spreading capabilities. Once such threat is called ZCrypt and it copies itself to external USB drives, from where it's executed via rogue autorun.inf files.

By running a very large number of ransomware samples in a laboratory environment, the Exabeam researchers have also observed some interesting trends: for example, a recent increase in the ransom price.

"Two or three months ago most ransom values were between 0.4 and 1 bitcoin," said Barry Shteiman, the head of threat research at Exabeam. "That changed over the past month, the price now being between 2 and 5 bitcoins."

This could also be driven by the fact that many ransomware authors are now focused on targeting businesses, and companies are willing and able to pay more than consumers in order to recover critical business files.

Another interesting observation is that no new ransomware installer remains functional for more than a day.

This indicates that "ransomware campaigns are changing every day," Shteiman said. "It's like their creators work in DevOps mode, releasing new code to their spamming partners every day."

Join the PC World newsletter!

Error: Please check your email address.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Cool Tech

Crucial Ballistix Elite 32GB Kit (4 x 8GB) DDR4-3000 UDIMM

Learn more >

Gadgets & Things

Lexar® Professional 1000x microSDHC™/microSDXC™ UHS-II cards

Learn more >

Family Friendly

Lexar® JumpDrive® S57 USB 3.0 flash drive 

Learn more >

Stocking Stuffer

Plox Star Wars Death Star Levitating Bluetooth Speaker

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

GGG Evaluation Team

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Steph Mundell

LIFEBOOK UH574

The Fujitsu LifeBook UH574 allowed for great mobility without being obnoxiously heavy or clunky. Its twelve hours of battery life did not disappoint.

Andrew Mitsi

STYLISTIC Q702

The screen was particularly good. It is bright and visible from most angles, however heat is an issue, particularly around the Windows button on the front, and on the back where the battery housing is located.

Simon Harriott

STYLISTIC Q702

My first impression after unboxing the Q702 is that it is a nice looking unit. Styling is somewhat minimalist but very effective. The tablet part, once detached, has a nice weight, and no buttons or switches are located in awkward or intrusive positions.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?