首页> 外文会议>IEEE International Conference on Software Analysis, Evolution and Reengineering >UNVEIL: A large-scale, automated approach to detecting ransomware (keynote)
【24h】

UNVEIL: A large-scale, automated approach to detecting ransomware (keynote)

机译:推出:一种大规模,自动化的检测勒索软件(Keynote)

获取原文
获取外文期刊封面目录资料

摘要

Although the concept of ransomware is not new (i.e., such attacks date back at least as far as the 1980s), this type of malware has recently experienced a resurgence in popularity. In fact, in 2014 and 2015, a number of high-profile ransomware attacks were reported, such as the large-scale attack against Sony that prompted the company to delay the release of the film “The Interview”. Ransomware typically operates by locking the desktop of the victim to render the system inaccessible to the user, or by encrypting, overwriting, or deleting the user's files. However, while many generic malware detection systems have been proposed, none of these systems have attempted to specifically address the ransomware detection problem. In this keynote, I talk about some of the trends we are seeing in ransomware. Then, I present a novel dynamic analysis system called UNVEIL that is specifically designed to detect ransomware. The key insight of the analysis is that in order to mount a successful attack, ransomware must tamper with a user's files or desktop. UNVEIL automatically generates an artificial user environment, and detects when ransomware interacts with user data. In parallel, the approach tracks changes to the system's desktop that indicate ransomware-like behavior. Our evaluation shows that UNVEIL significantly improves the state of the art, and is able to identify previously unknown evasive ransomware that was not detected by the anti-malware industry.
机译:尽管勒索软件的概念并不新鲜(即,这种攻击可以追溯到至少就20世纪80年代),这种类型的恶意软件的最近经历普及死灰复燃。事实上,在2014年和2015年,一些知名度较高的勒索软件攻击的报道,如对索尼的大规模攻击,促使该公司推迟了电影“访谈”的释放。勒索通常通过锁定被害人的桌面导致系统无法访问用户操作,或通过加密,覆盖或删除用户的文件。然而,虽然许多普通的恶意软件检测系统已经被提出,所有这些系统都试图以专门满足勒索软件检测问题。在这个主题,我谈一些我们看到的勒索软件的发展趋势。然后,我提出称为揭开被专门用于检测勒索一种新颖的动态分析系统。分析的主要观点是,为了安装成功的攻击,勒索软件必须与用户的文件或桌面篡改。自动推出生成的人工用户环境,并检测当与用户数据勒索相互作用。同时,该方法的轨道更改系统的桌面指示勒索的行为。我们的评估显示,显著推出改进了该技术的状态,并且能够识别不是由反恶意软件行业检测先前未知的回避勒索。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号