Reference : On Deception-Based Protection Against Cryptographic Ransomware
Scientific congresses, symposiums and conference proceedings : Paper published in a book
Engineering, computing & technology : Computer science
Security, Reliability and Trust
http://hdl.handle.net/10993/40579
On Deception-Based Protection Against Cryptographic Ransomware
English
Genç, Ziya Alper mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > >]
Lenzini, Gabriele [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > >]
Sgandurra, Daniele []
2019
Proceedings of the 16th Conference on Detection of Intrusions and Malware & Vulnerability Assessment
Springer
219-239
Yes
No
International
978-3-030-22037-2
Cham
Switzerland
16th Conference on Detection of Intrusions and Malware & Vulnerability Assessment (DIMVA 2019)
June 19-20, 2019
University of Gothenburg
Chalmers University of Technology
Gothenburg
Sweden
[en] Ransomware ; Cryptographic ; Malware ; Deception ; Decoy
[en] In order to detect malicious file system activity, some commercial and academic anti-ransomware solutions implement deception-based techniques, specifically by placing decoy files among user files. While this approach raises the bar against current ransomware, as any access to a decoy file is a sign of malicious activity, the robustness of decoy strategies has not been formally analyzed and fully tested. In this paper, we analyze existing decoy strategies and discuss how they are effective in countering current ransomware by defining a set of metrics to measure their robustness. To demonstrate how ransomware can identify existing deception-based detection strategies, we have implemented a proof-of-concept anti-decoy ransomware that successfully bypasses decoys by using a decision engine with few rules. Finally, we discuss existing issues in decoy-based strategies and propose practical solutions to mitigate them.
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > Applied Security and Information Assurance Group (APSIA)
Fonds National de la Recherche - FnR ; EU's Horizon 2020 Research and Innovation Programme
Researchers ; Professionals ; Students ; General public
http://hdl.handle.net/10993/40579
10.1007/978-3-030-22038-9_11
https://link.springer.com/chapter/10.1007/978-3-030-22038-9_11
The prototype designed in this paper is available at https://github.com/ziyagenc/decoy-updater.
H2020 ; 779391 - FutureTPM - Future Proofing the Connected World: A Quantum-Resistant Trusted Platform Module
FnR ; FNR13234766 > Gabriele Lenzini > NoCry PoC > No More Cryptographic Ransomware, Proof of Concept > 01/11/2018 > 31/10/2020 > 2018

File(s) associated to this reference

Fulltext file(s):

FileCommentaryVersionSizeAccess
Open access
dimva2019_GLS.pdfAuthor postprint496.44 kBView/Open

Bookmark and Share SFX Query

All documents in ORBilu are protected by a user license.