OutletGuarder: Detecting DarkSide Ransomware by Power Factor Correction Signals in an Electrical Outlet

Shan Zou,Juchuan Zhang,Shui Jiang,Yushi Cheng,Xiaoyu Ji,Wenyuan Xu
DOI: https://doi.org/10.1109/icpads56603.2022.00061
2023-01-01
Abstract:Ransomware is a kind of computer malware that has spread widely in recent years, such as DarkSide, which spread around the world recently. It’s reported that DarkSide extorted ${\$}$ 90 million in nine months. It extorts ransom from users by encrypting user files and other methods, causing huge economic losses to users, including commercial organizations and individuals. Existing ransomware detection methods include the hostbased methods and the network-based methods. However, these methods are either hard to deploy or have the possibility to be evaded. In this paper, we propose OutletGuarder, a non-intrusive detection method against DarkSide ransomware based on the signal generated by the Power Factor Correction module of the host computer’s power supply in electrical outlets, which carries the power consumption information of the host computer during the execution of DarkSide. By utilizing the power consumption variation among different programs, especially the power consumption caused by frequent encryption and I/O operations during the execution of DarkSide, OutletGuarder achieves a detection F1 Score of 97.50%. The impact of classification models and untrained programs, as well as the model transferability and robustness are evaluated.
What problem does this paper attempt to address?