首页> 外文会议>International symposium on research in attacks, intrusions and defenses >RWGuard: A Real-Time Detection System Against Cryptographic Ransomware
【24h】

RWGuard: A Real-Time Detection System Against Cryptographic Ransomware

机译:RWGuard:针对加密勒索软件的实时检测系统

获取原文

摘要

Ransomware has recently (re)emerged as a popular malware that targets a wide range of victims - from individual users to corporate ones for monetary gain. Our key observation on the existing ransomware detection mechanisms is that they fail to provide an early warning in real-time which results in irreversible encryption of a significant number of files while the post-encryption techniques (e.g., key extraction, file restoration) suffer from several limitations. Also, the existing detection mechanisms result in high false positives being unable to determine the original intent of file changes, i.e., they fail to distinguish whether a significant change in a file is due to a ransomware encryption or due to a file operation by the user herself (e.g., benign encryption or compression). To address these challenges, in this paper, we introduce a ransomware detection mechanism, RWGuard, which is able to detect crypto-ransomware in real-time on a user's machine by (1) deploying decoy techniques, (2) carefully monitoring both the running processes and the file system for malicious activities, and (3) omitting benign file changes from being flagged through the learning of users' encryption behavior. We evaluate our system against samples from 14 most prevalent ransomware families to date. Our experiments show that RWGuard is effective in real-time detection of ransomware with zero false negative and negligible false positive (~0.1%) rates while incurring an overhead of only ~1.9%.
机译:勒索软件最近(重新)成为一种流行的恶意软件,它针对广泛的受害者-从个人用户到公司用户,以牟取金钱。我们对现有勒索软件检测机制的主要观察结果是,它们无法实时提供预警,这会导致对大量文件进行不可逆的加密,而后加密技术(例如,密钥提取,文件还原)会受到影响。几个限制。同样,现有的检测机制导致高误报率无法确定文件更改的原始意图,即,它们无法区分文件中的重大更改是由于勒索软件加密还是由于用户的文件操作她自己(例如,良性加密或压缩)。为了解决这些挑战,在本文中,我们介绍了一种勒索软件检测机制RWGuard,该机制能够通过(1)部署诱骗技术,(2)仔细监控这两种软件的运行情况,在用户的计算机上实时检测加密勒索软件。进程和文件系统中的恶意活动,以及(3)通过学习用户的加密行为,从标记中忽略良性文件更改。我们根据迄今为止14个最流行的勒索软件系列的样本评估了我们的系统。我们的实验表明,RWGuard在实时检测勒索软件方面是有效的,其误报率为零且误报率可以忽略不计(〜0.1%),而开销仅为1.9%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号