首页> 外文会议>International Symposium on Research in Attacks, Intrusions, and Defenses >RWGuard: A Real-Time Detection System Against Cryptographic Ransomware
【24h】

RWGuard: A Real-Time Detection System Against Cryptographic Ransomware

机译:RWGUARD:针对加密勒索软件的实时检测系统

获取原文

摘要

Ransomware has recently (re)emerged as a popular malware that targets a wide range of victims - from individual users to corporate ones for monetary gain. Our key observation on the existing ransomware detection mechanisms is that they fail to provide an early warning in real-time which results in irreversible encryption of a significant number of files while the post-encryption techniques (e.g., key extraction, file restoration) suffer from several limitations. Also, the existing detection mechanisms result in high false positives being unable to determine the original intent of file changes, i.e., they fail to distinguish whether a significant change in a file is due to a ransomware encryption or due to a file operation by the user herself (e.g., benign encryption or compression). To address these challenges, in this paper, we introduce a ransomware detection mechanism, RWGuard, which is able to detect crypto-ransomware in real-time on a user's machine by (1) deploying decoy techniques, (2) carefully monitoring both the running processes and the file system for malicious activities, and (3) omitting benign file changes from being flagged through the learning of users' encryption behavior. We evaluate our system against samples from 14 most prevalent ransomware families to date. Our experiments show that RWGuard is effective in real-time detection of ransomware with zero false negative and negligible false positive (~0.1%) rates while incurring an overhead of only ~1.9%.
机译:Ransomware最近(RE)作为一个受欢迎的恶意软件,这些恶意软件是针对各种各样的受害者 - 从个别用户到公司的货币收益。我们对现有赎金软件检测机制的关键观察是它们未能在实时提供预警,这导致大量文件的不可逆加密,而加密技术(例如,密钥提取,文件恢复)遭受影响几个限制。此外,现有的检测机制导致高误报无法确定文件更改的原始目的,即,它们未能区分文件中的重大变化是由于勒索软件加密或由用户的文件操作引起的她自己(例如,良性加密或压缩)。为了解决这些挑战,在本文中,我们介绍了一个赎金软件检测机制,RwGuard,它能够在用户机器上实时检测加密 - 勒索软件(1)部署诱饵技术,(2)仔细监控运行流程和文件系统用于恶意活动,(3)通过学习用户加密行为来省略良性文件更改。我们迄今为止,我们评估了从14个最普遍的勒索瓶家庭的样本的系统。我们的实验表明,Rwguard在实时检测勒索沃特的实时检测,零假阴性和可忽略的假阳性(〜0.1%)速率,同时产生仅〜1.9%的开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号