{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T16:12:47Z","timestamp":1783613567984,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":47,"publisher":"ACM","funder":[{"name":"Italian Ministry of University and Research","award":["SERICS PE00000014"],"award-info":[{"award-number":["SERICS PE00000014"]}]},{"DOI":"10.13039\/501100004271","name":"Sapienza Universit\u00e0 di Roma","doi-asserted-by":"publisher","award":["AutoAD: Using Active Defense to Defeat Cyber Adversaries RG1221816C839BF9"],"award-info":[{"award-number":["AutoAD: Using Active Defense to Defeat Cyber Adversaries RG1221816C839BF9"]}],"id":[{"id":"10.13039\/501100004271","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,8,25]]},"DOI":"10.1145\/3708821.3733867","type":"proceedings-article","created":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T06:30:56Z","timestamp":1755066656000},"page":"576-590","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Minerva: A File-Based Ransomware Detector"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5686-3831","authenticated-orcid":false,"given":"Dorjan","family":"Hitaj","sequence":"first","affiliation":[{"name":"Sapienza University of Rome, Rome, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4626-6045","authenticated-orcid":false,"given":"Giulio","family":"Pagnotta","sequence":"additional","affiliation":[{"name":"Sapienza University of Rome, Rome, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9718-1044","authenticated-orcid":false,"given":"Fabio","family":"De Gaspari","sequence":"additional","affiliation":[{"name":"Sapienza University of Rome, Rome, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0432-3686","authenticated-orcid":false,"given":"Lorenzo","family":"De Carli","sequence":"additional","affiliation":[{"name":"University of Calgary, Calgary, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4859-2191","authenticated-orcid":false,"given":"Luigi V.","family":"Mancini","sequence":"additional","affiliation":[{"name":"Sapienza University of Rome, Rome, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,8,24]]},"reference":[{"key":"e_1_3_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2018.00089"},{"key":"e_1_3_3_1_3_2","unstructured":"Alan Blinder and Nicole Perlroth. 2018. The New York Times A Cyberattack Hobbles Atlanta and Security Experts Shudder."},{"key":"e_1_3_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/3607199.3607200"},{"key":"e_1_3_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/2991079.2991110"},{"key":"e_1_3_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-70879-4_5"},{"key":"e_1_3_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-57878-7_13"},{"key":"e_1_3_3_1_8_2","doi-asserted-by":"crossref","unstructured":"Fabio De\u00a0Gaspari Dorjan Hitaj Giulio Pagnotta Lorenzo De\u00a0Carli and Luigi\u00a0V. Mancini. 2022. Evading Behavioral Classifiers: A Comprehensive Analysis on Evading Ransomware Detection Techniques. Neural Computing and Applications 34 14 (July 2022) 12077\u201312096.","DOI":"10.1007\/s00521-022-07096-6"},{"key":"e_1_3_3_1_9_2","doi-asserted-by":"crossref","unstructured":"Fabio De\u00a0Gaspari Dorjan Hitaj Giulio Pagnotta Lorenzo De\u00a0Carli and Luigi\u00a0V. Mancini. 2022. Reliable Detection of Compressed and Encrypted Data. Neural Computing and Applications 34 22 (Nov. 2022) 20379\u201320393.","DOI":"10.1007\/s00521-022-07586-7"},{"key":"e_1_3_3_1_10_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-88418-5_10"},{"key":"e_1_3_3_1_11_2","unstructured":"Derek Kortepeter. 2018. Shipping Giant COSCO Brutalized by Ransomware Attack. http:\/\/techgenix.com\/cosco-ransomware-attack\/."},{"key":"e_1_3_3_1_12_2","doi-asserted-by":"crossref","unstructured":"Abdulrahman\u00a0Abu Elkhail Nada Lachtar Duha Ibdah Rustam Aslam Hamza Khan Anys Bacha and Hafiz Malik. 2023. Seamlessly Safeguarding Data Against Ransomware Attacks. IEEE Transactions on Dependable and Secure Computing 20 1 (2023) 1\u201316.","DOI":"10.1109\/TDSC.2022.3214781"},{"key":"e_1_3_3_1_13_2","doi-asserted-by":"crossref","unstructured":"Gaddisa\u00a0Olani Ganfure Chun-Feng Wu Yuan-Hao Chang and Wei-Kuan Shih. 2023. RTrap: Trapping and Containing Ransomware With Machine Learning. IEEE Transactions on Information Forensics and Security 18 (2023).","DOI":"10.1109\/TIFS.2023.3240025"},{"key":"e_1_3_3_1_14_2","first-page":"219","volume-title":"International conference on detection of intrusions and malware, and vulnerability assessment","author":"Gen\u00e7 Ziya\u00a0Alper","year":"2019","unstructured":"Ziya\u00a0Alper Gen\u00e7, Gabriele Lenzini, and Daniele Sgandurra. 2019. On deception-based protection against cryptographic ransomware. In International conference on detection of intrusions and malware, and vulnerability assessment. Springer, 219\u2013239."},{"key":"e_1_3_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-03638-6_24"},{"key":"e_1_3_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66399-9_4"},{"key":"e_1_3_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/3607199.3607206"},{"key":"e_1_3_3_1_18_2","doi-asserted-by":"publisher","unstructured":"Dorjan Hitaj Briland Hitaj Sushil Jajodia and Luigi\u00a0V. Mancini. 2021. Capture the Bot: Using Adversarial Examples to Improve CAPTCHA Robustness to Bot Attacks. IEEE Intelligent Systems 36 5 (2021) 104\u2013112. 10.1109\/MIS.2020.3036156","DOI":"10.1109\/MIS.2020.3036156"},{"key":"e_1_3_3_1_19_2","doi-asserted-by":"crossref","unstructured":"Dorjan Hitaj Giulio Pagnotta Fabio De\u00a0Gaspari Sediola Ruko Briland Hitaj Luigi\u00a0V Mancini and Fernando Perez-Cruz. 2024. Do You Trust Your Model? Emerging Malware Threats in the Deep Learning Ecosystem. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2403.03593 (2024).","DOI":"10.1109\/TDSC.2025.3586703"},{"key":"e_1_3_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-17143-7_21"},{"key":"e_1_3_3_1_21_2","unstructured":"Weiwei Hu and Ying Tan. 2018. Black-box attacks against RNN based malware detection algorithms. (2018)."},{"key":"e_1_3_3_1_22_2","volume-title":"10th USENIX Workshop on Offensive Technologies (WOOT 16)","author":"Ispoglou Kyriakos\u00a0K","year":"2016","unstructured":"Kyriakos\u00a0K Ispoglou and Mathias Payer. 2016. { malWASH} : Washing Malware to Evade Dynamic Analysis. In 10th USENIX Workshop on Offensive Technologies (WOOT 16)."},{"key":"e_1_3_3_1_23_2","first-page":"757","volume-title":"25th USENIX Security Symposium (USENIX Security 16)","author":"Kharaz Amin","year":"2016","unstructured":"Amin Kharaz, Sajjad Arshad, Collin Mulliner, William Robertson, and Engin Kirda. 2016. UNVEIL: A Large-Scale, Automated Approach to Detecting Ransomware. In 25th USENIX Security Symposium (USENIX Security 16). USENIX Association, Austin, TX, 757\u2013772. https:\/\/www.usenix.org\/conference\/usenixsecurity16\/technical-sessions\/presentation\/kharaz"},{"key":"e_1_3_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66332-6_5"},{"key":"e_1_3_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.5555\/3295222.3295230"},{"key":"e_1_3_3_1_26_2","unstructured":"Malwarebytes. 2024. Malwarebytes Anti-Ransomware for Business. https:\/\/www.malwarebytes.com\/business\/solutions\/ransomware\/."},{"key":"e_1_3_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-48965-0_32"},{"key":"e_1_3_3_1_28_2","doi-asserted-by":"crossref","unstructured":"Shagufta Mehnaz and Elisa Bertino. 2021. A Fine-Grained Approach for Anomaly Detection in File System Accesses With Enhanced Temporal User Profiles. IEEE Transactions on Dependable and Secure Computing 18 6 (2021) 2535\u20132550.","DOI":"10.1109\/TDSC.2019.2954507"},{"key":"e_1_3_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_6"},{"key":"e_1_3_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/CCC.2016.14"},{"key":"e_1_3_3_1_31_2","unstructured":"Steve Morgan. 2019. 2019 Official Annual Cybercrime Report."},{"key":"e_1_3_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/3230833.3234691"},{"key":"e_1_3_3_1_33_2","doi-asserted-by":"crossref","unstructured":"Routa Moussaileb Nora Cuppens Jean-Louis Lanet and H\u00e9l\u00e8ne\u00a0Le Bouder. 2021. A Survey on Windows-Based Ransomware Taxonomy and Detection Mechanisms. ACM Comput. Surv. 54 6 (2021).","DOI":"10.1145\/3453153"},{"key":"e_1_3_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN53405.2022.00035"},{"key":"e_1_3_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-70290-2_12"},{"key":"e_1_3_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/VLSID60093.2024.00081"},{"key":"e_1_3_3_1_37_2","volume-title":"13th USENIX Workshop on Offensive Technologies (WOOT 19)","author":"Pavithran Jithin","year":"2019","unstructured":"Jithin Pavithran, Milan Patnaik, and Chester Rebeiro. 2019. { D-TIME} : Distributed Threadless Independent Malware Execution for Runtime Obfuscation. In 13th USENIX Workshop on Offensive Technologies (WOOT 19)."},{"key":"e_1_3_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453101"},{"key":"e_1_3_3_1_39_2","unstructured":"Ishai Rosenberg Asaf Shabtai Yuval Elovici and Lior Rokach. 2018. Query-Efficient GAN Based Black-Box Attack Against Sequence Based Machine and Deep Learning Classifiers. arXiv:https:\/\/arXiv.org\/abs\/1804.08778 [cs] (April 2018). http:\/\/arxiv.org\/abs\/1804.08778"},{"key":"e_1_3_3_1_40_2","doi-asserted-by":"crossref","unstructured":"Ishai Rosenberg Asaf Shabtai Yuval Elovici and Lior Rokach. 2021. Adversarial machine learning attacks and defense methods in the cyber security domain. ACM Computing Surveys (CSUR) 54 5 (2021) 1\u201336.","DOI":"10.1145\/3453158"},{"key":"e_1_3_3_1_41_2","doi-asserted-by":"publisher","DOI":"10.5555\/2432156"},{"key":"e_1_3_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2016.46"},{"key":"e_1_3_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICACCI.2018.8554938"},{"key":"e_1_3_3_1_44_2","unstructured":"Splunk. 2022. An Empirically Comparative Analysis of Ransomware Binaries. https:\/\/www.splunk.com\/en_us\/form\/an-empirically-comparative-analysis-of-ransomware-binaries.html."},{"key":"e_1_3_3_1_45_2","unstructured":"Cybersecurity Ventures. 2023. Global Ransomware Damage Costs Predicted To Exceed 265 Billion By 2031. https:\/\/cybersecurityventures.com\/global-ransomware-damage-costs-predicted-to-reach-250-billion-usd-by-2031\/. Accessed: 2024-04-01."},{"key":"e_1_3_3_1_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/3607199.3607207"},{"key":"e_1_3_3_1_47_2","doi-asserted-by":"publisher","unstructured":"Alian Yu Jian Kang Joshua Morris Elisa Bertino and Dan Lin. 2024. Fight Malware Like Malware: A New Defense Method Against Crypto Ransomware. IEEE Transactions on Dependable and Secure Computing (2024) 1\u201313. 10.1109\/TDSC.2024.3364209","DOI":"10.1109\/TDSC.2024.3364209"},{"key":"e_1_3_3_1_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179372"}],"event":{"name":"ASIA CCS '25: 20th ACM Asia Conference on Computer and Communications Security","location":"Hanoi Vietnam","acronym":"ASIA CCS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 20th ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3708821.3733867","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T07:31:25Z","timestamp":1755070285000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3708821.3733867"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,24]]},"references-count":47,"alternative-id":["10.1145\/3708821.3733867","10.1145\/3708821"],"URL":"https:\/\/doi.org\/10.1145\/3708821.3733867","relation":{},"subject":[],"published":{"date-parts":[[2025,8,24]]},"assertion":[{"value":"2025-08-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}