首页> 外文会议>2018 1st International Conference on Data Intelligence and Security >Prevention of Ransomware Execution in Enterprise Environment on Windows OS: Assessment of Application Whitelisting Solutions
【24h】

Prevention of Ransomware Execution in Enterprise Environment on Windows OS: Assessment of Application Whitelisting Solutions

机译:在Windows OS上防止企业环境中的勒索软件执行:评估应用程序白名单解决方案

获取原文
获取原文并翻译 | 示例

摘要

Application whitelisting software allows only examined and trusted applications to run on user's machine. Since many malicious files don't require administrative privileges in order for them to be executed, whitelisting can be the only way to block the execution of unauthorized applications in enterprise environment and thus prevent infection or data breach. In order to assess the current state of such solutions, the access to three whitelisting solution licenses was obtained with the purpose to test their effectiveness against different modern types of ransomware found in the wild. To conduct this study a virtual environment was used with Windows Server and Enterprise editions installed. The objective of this paper is not to evaluate each vendor or make recommendations of purchasing specific software but rather to assess the ability of application control solutions to block execution of ransomware files, as well as assess the potential for future research. The results of the research show the promise and effectiveness of whitelisting solutions.
机译:应用程序白名单软件仅允许经过检查和信任的应用程序在用户的计算机上运行。由于许多恶意文件都不需要管理特权才能执行它们,因此白名单可能是阻止企业环境中未经授权的应用程序执行并防止感染或数据泄露的唯一方法。为了评估此类解决方案的当前状态,获得了三个白名单解决方案许可的访问权限,目的是测试它们针对野外发现的不同现代勒索软件的有效性。为了进行这项研究,使用了虚拟环境并安装了Windows Server和Enterprise版本。本文的目的不是评估每个供应商或对购买特定软件提出建议,而是评估应用程序控制解决方案阻止勒索软件文件执行的能力,以及评估未来研究的潜力。研究结果显示了将解决方案列入白名单的前景和有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号