DocumentCode :
3734120
Title :
Connection-monitor & connection-breaker: A novel approach for prevention and detection of high survivable ransomwares
Author :
Mohammad Mehdi Ahmadian;Hamid Reza Shahriari;Seyed Mohammad Ghaffarian
Author_Institution :
Department of Computer Engineering and Information Technology, Amirkabir University of technology, Tehran, Iran
fYear :
2015
Firstpage :
79
Lastpage :
84
Abstract :
Ransomwares have become a growing threat in recent years, and this situation continues to worsen. It rose awareness on a particular class of malwares which extort a ransom in exchange for a captive asset. Most widespread ransomwares make an intensive use of data encryption. Basically, they encrypt various files on victim´s hard drives, removable drives and mapped network shares before asking for a ransom to get the files decrypted. In this paper, at first we propose a comprehensive ransomware taxonomy. Then, based on this taxonomy and according to a principal feature which we discovered in high survivable ransomwares (HSR) in the key exchange protocol step, we present a novel approach for detecting high survivable ransomwares and preventing them from encrypting victim´s data. Experimental evaluation demonstrates that our framework can detect variants of recent dangerous ransomwares.
Keywords :
Decision support systems
Publisher :
ieee
Conference_Titel :
Information Security and Cryptology (ISCISC), 2015 12th International Iranian Society of Cryptology Conference on
Type :
conf
DOI :
10.1109/ISCISC.2015.7387902
Filename :
7387902
Link To Document :
بازگشت