首页> 外文会议>International conference on cryptology and network security >An Efficient Approach to Detect TorrentLocker Ransomware in Computer Systems
【24h】

An Efficient Approach to Detect TorrentLocker Ransomware in Computer Systems

机译:一种检测计算机系统中TorrentLocker勒索软件的有效方法

获取原文

摘要

TorrentLocker is a ransomware that encrypts sensitive data located on infected computer systems. Its creators aim to ransom the victims, if they want to retrieve their data. Unfortunately, antiviruses have difficulties to detect such polymorphic malware. In this paper, we propose a novel approach to detect online suspicious processes accessing a large number of files and encrypting them. Such a behavior corresponds to the classical scenario of a malicious ransomware. We show that the Kullback-Liebler divergence can be used to detect with high effectiveness whether a process transforms structured input files (such as JPEG files) into unstructured encrypted files, or not. We focus mainly on JPEG files since irreplaceable pictures represent in many cases the most valuable data on personal computers or smartphones.
机译:TorrentLocker是一种勒索软件,可以对位于受感染计算机系统上的敏感数据进行加密。它的创建者旨在赎回受害者,如果他们想检索他们的数据。不幸的是,防病毒软件很难检测到这种多态恶意软件。在本文中,我们提出了一种新颖的方法来检测访问大量文件并对其进行加密的在线可疑进程。这种行为与恶意勒索软件的经典情形相对应。我们证明了Kullback-Liebler散度可用于高效检测过程是否将结构化的输入文件(例如JPEG文件)转换为非结构化的加密文件。我们主要关注JPEG文件,因为在许多情况下,不可替代的图片代表了个人计算机或智能手机上最有价值的数据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号