中文版 | English
题名

RansomSpector: An introspection-based approach to detect crypto ransomware

作者
通讯作者Li,Jinku
发表日期
2020-10-01
DOI
发表期刊
ISSN
0167-4048
EISSN
1872-6208
卷号97
摘要

Crypto ransomware encrypts user files and then extorts a ransom for decryption, thus it brings a big threat to users. To address this problem, we propose RANSOMSPECTOR, an introspection-based approach to detect crypto ransomware. Compared to previous solutions, our approach makes progress in two aspects. First, RANSOMSPECTOR is based on the virtual machine introspection technique, and it resides in the hypervisor layer under the operating system (OS) where ransomware runs. Thus it is capable of analyzing OS-level ransomware and difficult to be bypassed by privilege escalation attacks. Second, RANSOMSPECTOR monitors both the filesystem and network activities for ransomware detection, thus it achieves a higher precision and earlier warning than the approaches that only leverage the filesystem activities as the detecting basis. To validate our approach, we have implemented a prototype of RANSOMSPECTOR, and collected 2,117 recent ransomware samples to evaluate it. The evaluation results indicate that our system effectively detects ransomware with a low performance overhead ( < 5% on average).

关键词
相关链接[Scopus记录]
收录类别
SCI ; EI
语种
英语
学校署名
其他
资助项目
Key R&D Program of Shaanxi Province of China[2019ZDLGY12-06] ; Project of China[201809168CX9jC10]
WOS研究方向
Computer Science
WOS类目
Computer Science, Information Systems
WOS记录号
WOS:000568739500004
出版者
EI入藏号
20203409065621
EI主题词
Virtual machine ; File organization ; Network security ; Cryptography
EI分类号
Computer Software, Data Handling and Applications:723 ; Computer Applications:723.5 ; Information Retrieval and Use:903.3
ESI学科分类
COMPUTER SCIENCE
Scopus记录号
2-s2.0-85089427257
来源库
Scopus
引用统计
被引频次[WOS]:27
成果类型期刊论文
条目标识符http://sustech.caswiz.com/handle/2SGJ60CL/153282
专题工学院_计算机科学与工程系
作者单位
1.School of Cyber Engineering,Xidian University,Xi'an,China
2.Department of Computer Science and Engineering,Southern University of Science and Technology,Shenzhen,China
推荐引用方式
GB/T 7714
Tang,Fei,Ma,Boyang,Li,Jinku,et al. RansomSpector: An introspection-based approach to detect crypto ransomware[J]. COMPUTERS & SECURITY,2020,97.
APA
Tang,Fei,Ma,Boyang,Li,Jinku,Zhang,Fengwei,Su,Jipeng,&Ma,Jianfeng.(2020).RansomSpector: An introspection-based approach to detect crypto ransomware.COMPUTERS & SECURITY,97.
MLA
Tang,Fei,et al."RansomSpector: An introspection-based approach to detect crypto ransomware".COMPUTERS & SECURITY 97(2020).
条目包含的文件
文件名称/大小 文献类型 版本类型 开放类型 使用许可 操作
RansomSpector An int(1090KB)----限制开放--
个性服务
原文链接
推荐该条目
保存到收藏夹
查看访问统计
导出为Endnote文件
导出为Excel格式
导出为Csv格式
Altmetrics Score
谷歌学术
谷歌学术中相似的文章
[Tang,Fei]的文章
[Ma,Boyang]的文章
[Li,Jinku]的文章
百度学术
百度学术中相似的文章
[Tang,Fei]的文章
[Ma,Boyang]的文章
[Li,Jinku]的文章
必应学术
必应学术中相似的文章
[Tang,Fei]的文章
[Ma,Boyang]的文章
[Li,Jinku]的文章
相关权益政策
暂无数据
收藏/分享
所有评论 (0)
[发表评论/异议/意见]
暂无评论

除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。