{"id":{"repo_id":"waikato-masters","oai_identifier":"oai:researchcommons.waikato.ac.nz:10289/15958"},"canonical_url":"https://search.dev.ndltd.org/etd/waikato-masters/oai:researchcommons.waikato.ac.nz:10289/15958","repository":{"repo_id":"waikato-masters","name":"University Waikato","base_url":"https://researchcommons.waikato.ac.nz/server/oai/request"},"display":{"title":"Behaviour-based classification of encryption-type ransomware using system calls","abstract":"The malware landscape is ever-changing, with threat actors utilising more sophisticated techniques to compromise data. As the usage of smartphones increases, more threat actors will turn their attention to capitalise on the popularity. This thesis addresses this ongoing issue and focuses on encryption-type ransomware, which has been a rising malware threat in recent years, on the Android operating system. Many state-of-the-art anti-malware solutions have shifted away from static signature-based approaches as the techniques utilised by threat actors have become more advanced. Most newer solutions look towards the use of dynamic analysis to automatically identify malware. However, the large quantities of information required by dynamic analysis approaches often present a challenging task for developing robust automated anti-malware solutions and may be easily circumvented by future threat actors, which implies that more specialised automated solutions are required. In the work presented in this thesis, we observe encryption-type ransomware behavioural patterns at a system call-level. We describe the Android Applications dataset on which a large portion of this work is based. By utilising the created dataset and the behavioural patterns, this thesis presents solutions using Finite State Machines (FSM) and supervisor reduction to quickly detect Android encryption-type ransomware. Furthermore, the solutions are evaluated on Linux encryption-type ransomware to show its transferability and generalisability. We measured the success of our techniques by using the following accuracy metrics: true positive rates, false negative rates, true negative rates, false positive rates, and achieved an F1-score of up to 93.8%.","abstract_html":"The malware landscape is ever-changing, with threat actors utilising more sophisticated techniques to compromise data. As the usage of smartphones increases, more threat actors will turn their attention to capitalise on the popularity. This thesis addresses this ongoing issue and focuses on encryption-type ransomware, which has been a rising malware threat in recent years, on the Android operating system. Many state-of-the-art anti-malware solutions have shifted away from static signature-based approaches as the techniques utilised by threat actors have become more advanced. Most newer solutions look towards the use of dynamic analysis to automatically identify malware. However, the large quantities of information required by dynamic analysis approaches often present a challenging task for developing robust automated anti-malware solutions and may be easily circumvented by future threat actors, which implies that more specialised automated solutions are required. In the work presented in this thesis, we observe encryption-type ransomware behavioural patterns at a system call-level. We describe the Android Applications dataset on which a large portion of this work is based. By utilising the created dataset and the behavioural patterns, this thesis presents solutions using Finite State Machines (FSM) and supervisor reduction to quickly detect Android encryption-type ransomware. Furthermore, the solutions are evaluated on Linux encryption-type ransomware to show its transferability and generalisability. We measured the success of our techniques by using the following accuracy metrics: true positive rates, false negative rates, true negative rates, false positive rates, and achieved an F1-score of up to 93.8%.","abstract_has_math":false,"creators":["Chew, Christopher J.W."],"institution":"The University of Waikato","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":[],"advisors":["Kumar, Vimal","Malik, Robi","Patros, Panos"],"committee_chairs":[],"committee_members":[],"year":2023,"date_issued":"2023","date_published":"2023","updated_at":"2026-07-24T05:57:41Z","subjects":["Ransomware","System calls","Behavioural patterns","Malware detection","Finite-state automaton","Android"],"languages":[],"rights":["All items in Research Commons are provided for private study and research purposes and are protected by copyright with all rights reserved unless otherwise indicated."],"rights_urls":["https://researchcommons.waikato.ac.nz/bitstreams/d1e754d1-31ce-4dd7-a761-df7e1e20693a/download"],"identifier_entries":[]},"links":{"outbound_url":null,"outbound_label":null,"outbound_source":null},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Kumar, Vimal","Malik, Robi","Patros, Panos"]},{"key":"dc:creator","label":"Author","values":["Chew, Christopher J.W."]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.issued","label":"Date","values":["2023"]},{"key":"dc:publisher.institution","label":"Dc Publisher Institution","values":["The University of Waikato"]},{"key":"dc:relation.isreferencedby","label":"Dc Relation Isreferencedby","values":["https://hdl.handle.net/10289/15958"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Ransomware","System calls","Behavioural patterns","Malware detection","Finite-state automaton","Android"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["https://researchcommons.waikato.ac.nz/bitstreams/d1e754d1-31ce-4dd7-a761-df7e1e20693a/download","All items in Research Commons are provided for private study and research purposes and are protected by copyright with all rights reserved unless otherwise indicated."]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://researchcommons.waikato.ac.nz/bitstreams/532ca0d9-8e9e-4b21-81e1-eba704bab2ad/download"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["The malware landscape is ever-changing, with threat actors utilising more sophisticated techniques to compromise data. As the usage of smartphones increases, more threat actors will turn their attention to capitalise on the popularity. This thesis addresses this ongoing issue and focuses on encryption-type ransomware, which has been a rising malware threat in recent years, on the Android operating system. Many state-of-the-art anti-malware solutions have shifted away from static signature-based approaches as the techniques utilised by threat actors have become more advanced. Most newer solutions look towards the use of dynamic analysis to automatically identify malware. However, the large quantities of information required by dynamic analysis approaches often present a challenging task for developing robust automated anti-malware solutions and may be easily circumvented by future threat actors, which implies that more specialised automated solutions are required. In the work presented in this thesis, we observe encryption-type ransomware behavioural patterns at a system call-level. We describe the Android Applications dataset on which a large portion of this work is based. By utilising the created dataset and the behavioural patterns, this thesis presents solutions using Finite State Machines (FSM) and supervisor reduction to quickly detect Android encryption-type ransomware. Furthermore, the solutions are evaluated on Linux encryption-type ransomware to show its transferability and generalisability. We measured the success of our techniques by using the following accuracy metrics: true positive rates, false negative rates, true negative rates, false positive rates, and achieved an F1-score of up to 93.8%."]},{"key":"dc:format.checksum.md5","label":"Dc Format Checksum Md5","values":["a0e45eb689c014f460784adf7e49760f","e14202ab27e47ddb00d33097327ba050","9b97b3d762952bac47b8d4f0ff2e2279"]},{"key":"dc:title","label":"Title","values":["Behaviour-based classification of encryption-type ransomware using system calls"]}]}],"canonical_facts":{"dc:contributor.advisor":["Kumar, Vimal","Malik, Robi","Patros, Panos"],"dc:creator":["Chew, Christopher J.W."],"dc:date.issued":["2023"],"dc:description.abstract":["The malware landscape is ever-changing, with threat actors utilising more sophisticated techniques to compromise data. As the usage of smartphones increases, more threat actors will turn their attention to capitalise on the popularity. This thesis addresses this ongoing issue and focuses on encryption-type ransomware, which has been a rising malware threat in recent years, on the Android operating system. Many state-of-the-art anti-malware solutions have shifted away from static signature-based approaches as the techniques utilised by threat actors have become more advanced. Most newer solutions look towards the use of dynamic analysis to automatically identify malware. However, the large quantities of information required by dynamic analysis approaches often present a challenging task for developing robust automated anti-malware solutions and may be easily circumvented by future threat actors, which implies that more specialised automated solutions are required. In the work presented in this thesis, we observe encryption-type ransomware behavioural patterns at a system call-level. We describe the Android Applications dataset on which a large portion of this work is based. By utilising the created dataset and the behavioural patterns, this thesis presents solutions using Finite State Machines (FSM) and supervisor reduction to quickly detect Android encryption-type ransomware. Furthermore, the solutions are evaluated on Linux encryption-type ransomware to show its transferability and generalisability. We measured the success of our techniques by using the following accuracy metrics: true positive rates, false negative rates, true negative rates, false positive rates, and achieved an F1-score of up to 93.8%."],"dc:format.checksum.md5":["a0e45eb689c014f460784adf7e49760f","e14202ab27e47ddb00d33097327ba050","9b97b3d762952bac47b8d4f0ff2e2279"],"dc:identifier.uri":["https://researchcommons.waikato.ac.nz/bitstreams/532ca0d9-8e9e-4b21-81e1-eba704bab2ad/download"],"dc:publisher.institution":["The University of Waikato"],"dc:relation.isreferencedby":["https://hdl.handle.net/10289/15958"],"dc:rights":["https://researchcommons.waikato.ac.nz/bitstreams/d1e754d1-31ce-4dd7-a761-df7e1e20693a/download","All items in Research Commons are provided for private study and research purposes and are protected by copyright with all rights reserved unless otherwise indicated."],"dc:subject":["Ransomware","System calls","Behavioural patterns","Malware detection","Finite-state automaton","Android"],"dc:title":["Behaviour-based classification of encryption-type ransomware using system calls"],"dc:type":["Thesis"]},"updated_at":"2026-07-24T05:57:41Z"}