题名 | RansomSpector: An introspection-based approach to detect crypto ransomware |
作者 | |
通讯作者 | Li,Jinku |
发表日期 | 2020-10-01
|
DOI | |
发表期刊 | |
ISSN | 0167-4048
|
EISSN | 1872-6208
|
卷号 | 97 |
摘要 | Crypto ransomware encrypts user files and then extorts a ransom for decryption, thus it brings a big threat to users. To address this problem, we propose RANSOMSPECTOR, an introspection-based approach to detect crypto ransomware. Compared to previous solutions, our approach makes progress in two aspects. First, RANSOMSPECTOR is based on the virtual machine introspection technique, and it resides in the hypervisor layer under the operating system (OS) where ransomware runs. Thus it is capable of analyzing OS-level ransomware and difficult to be bypassed by privilege escalation attacks. Second, RANSOMSPECTOR monitors both the filesystem and network activities for ransomware detection, thus it achieves a higher precision and earlier warning than the approaches that only leverage the filesystem activities as the detecting basis. To validate our approach, we have implemented a prototype of RANSOMSPECTOR, and collected 2,117 recent ransomware samples to evaluate it. The evaluation results indicate that our system effectively detects ransomware with a low performance overhead ( < 5% on average). |
关键词 | |
相关链接 | [Scopus记录] |
收录类别 | |
语种 | 英语
|
学校署名 | 其他
|
资助项目 | Key R&D Program of Shaanxi Province of China[2019ZDLGY12-06]
; Project of China[201809168CX9jC10]
|
WOS研究方向 | Computer Science
|
WOS类目 | Computer Science, Information Systems
|
WOS记录号 | WOS:000568739500004
|
出版者 | |
EI入藏号 | 20203409065621
|
EI主题词 | Virtual machine
; File organization
; Network security
; Cryptography
|
EI分类号 | Computer Software, Data Handling and Applications:723
; Computer Applications:723.5
; Information Retrieval and Use:903.3
|
ESI学科分类 | COMPUTER SCIENCE
|
Scopus记录号 | 2-s2.0-85089427257
|
来源库 | Scopus
|
引用统计 |
被引频次[WOS]:27
|
成果类型 | 期刊论文 |
条目标识符 | http://sustech.caswiz.com/handle/2SGJ60CL/153282 |
专题 | 工学院_计算机科学与工程系 |
作者单位 | 1.School of Cyber Engineering,Xidian University,Xi'an,China 2.Department of Computer Science and Engineering,Southern University of Science and Technology,Shenzhen,China |
推荐引用方式 GB/T 7714 |
Tang,Fei,Ma,Boyang,Li,Jinku,et al. RansomSpector: An introspection-based approach to detect crypto ransomware[J]. COMPUTERS & SECURITY,2020,97.
|
APA |
Tang,Fei,Ma,Boyang,Li,Jinku,Zhang,Fengwei,Su,Jipeng,&Ma,Jianfeng.(2020).RansomSpector: An introspection-based approach to detect crypto ransomware.COMPUTERS & SECURITY,97.
|
MLA |
Tang,Fei,et al."RansomSpector: An introspection-based approach to detect crypto ransomware".COMPUTERS & SECURITY 97(2020).
|
条目包含的文件 | ||||||
文件名称/大小 | 文献类型 | 版本类型 | 开放类型 | 使用许可 | 操作 | |
RansomSpector An int(1090KB) | -- | -- | 限制开放 | -- |
|
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。
修改评论