Connection-Monitor & Connection-Breaker: A Novel Approach For Prevention And Detection Of High Survivable Ransomwares

2015 12TH INTERNATIONAL IRANIAN SOCIETY OF CRYPTOLOGY CONFERENCE ON INFORMATION SECURITY AND CRYPTOLOGY (ISCISC)(2015)

引用 59|浏览18
暂无评分
摘要
Ransomwares have become a growing threat in recent years, and this situation continues to worsen. It rose awareness on a particular class of malwares which extort a ransom in exchange for a captive asset. Most widespread ransomwares make an intensive use of data encryption. Basically, they encrypt various files on victim's hard drives, removable drives and mapped network shares before asking for a ransom to get the files decrypted. In this paper, at first we propose a comprehensive ransomware taxonomy. Then, based on this taxonomy and according to a principal feature which we discovered in high survivable ransomwares (HSR) in the key exchange protocol step, we present a novel approach for detecting high survivable ransomwares and preventing them from encrypting victim's data. Experimental evaluation demonstrates that our framework can detect variants of recent dangerous ransomwares.
更多
查看译文
关键词
component,ransomware,crytovirology,malare detection,malware prevention,high survivable ransomwares
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要