Title :
Connection-monitor & connection-breaker: A novel approach for prevention and detection of high survivable ransomwares
Author :
Mohammad Mehdi Ahmadian;Hamid Reza Shahriari;Seyed Mohammad Ghaffarian
Author_Institution :
Department of Computer Engineering and Information Technology, Amirkabir University of technology, Tehran, Iran
Abstract :
Ransomwares have become a growing threat in recent years, and this situation continues to worsen. It rose awareness on a particular class of malwares which extort a ransom in exchange for a captive asset. Most widespread ransomwares make an intensive use of data encryption. Basically, they encrypt various files on victim´s hard drives, removable drives and mapped network shares before asking for a ransom to get the files decrypted. In this paper, at first we propose a comprehensive ransomware taxonomy. Then, based on this taxonomy and according to a principal feature which we discovered in high survivable ransomwares (HSR) in the key exchange protocol step, we present a novel approach for detecting high survivable ransomwares and preventing them from encrypting victim´s data. Experimental evaluation demonstrates that our framework can detect variants of recent dangerous ransomwares.
Keywords :
Decision support systems
Conference_Titel :
Information Security and Cryptology (ISCISC), 2015 12th International Iranian Society of Cryptology Conference on
DOI :
10.1109/ISCISC.2015.7387902