论文标题

及时检测勒索软件执行

Detecting Ransomware Execution in a Timely Manner

论文作者

Melaragno, Anthony, Casey, William

论文摘要

自1990年代初以来,勒索软件一直是一个持续的问题。最近,勒索软件已从传统的计算资源传播到网络物理系统和工业控制。我们设计了一系列实验,其中虚拟实例感染了勒索软件。我们在各种指标(CPU,内存,磁盘实用程序)上掌握了实例,并收集了资源利用数据。我们设计了一种用于识别勒索软件执行的变更点检测和学习方法。最后,我们评估并证明了其在最小样本集中训练时及时及时检测勒索软件的能力。我们的结果代表了防御的一步,我们以进一步的讲话对前进的道路进行了总结。

Ransomware has been an ongoing issue since the early 1990s. In recent times ransomware has spread from traditional computational resources to cyber-physical systems and industrial controls. We devised a series of experiments in which virtual instances are infected with ransomware. We instrumented the instances and collected resource utilization data across a variety of metrics (CPU, Memory, Disk Utility). We design a change point detection and learning method for identifying ransomware execution. Finally we evaluate and demonstrate its ability to detect ransomware efficiently in a timely manner when trained on a minimal set of samples. Our results represent a step forward for defense, and we conclude with further remarks for the path forward.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源