遇见数据集

VERA: A Dual-Validated, Behaviorally-Verified Repository of 15,000+ Raw Windows Ransomware Binaries

收藏
Zenodo2026-04-13 更新2026-05-26 收录
官方服务:

资源简介:

Reliable ransomware detection research is hindered by a scarcity ofhigh-quality, reproducible data. Public repositories often suffer fromlabel noise where generic malware, benign files, or corrupted bina-ries are misclassified. We introduce VERA (Validated Execution-based Ransomware Analysis), a repository of behaviorally verifiedraw Windows ransomware constructed using a Dual-ValidationMethodology. We processed over 38,000 candidates with VirusTo-tal consensus and subjected them to dynamic verification in theCAPE Sandbox. This process revealed that 22,957 samples weredynamically silent due to defunct infrastructure or incompatibilitywith modern Windows environments. We segregated these into asecondary VERA-Silent dataset to preserve the comprehensivepool while cleaning the primary set.The primary VERA-Active dataset retains 15,324 samples thatexhibited verified destructive functionality including file encryptionand shadow copy deletion. Benchmarking demonstrates the highquality of VERA-Active. A standard XGBoost classifier achieves>99.9% specificity distinguishing VERA samples from the BOD-MAS general malware dataset, confirming the isolation of high-fidelity ransomware signatures distinct from general maliciousnoise. By releasing raw binaries and execution logs, VERA offers astandardized benchmark for reproducible research.

提供机构:
Zenodo
创建时间:
2026-03-13
二维码
社区交流群
二维码
科研交流群
商业服务