Authors
Jian Huang, Jun Xu, Xinyu Xing, Peng Liu, Moinuddin K Qureshi
Publication date
2017/10/30
Book
Proceedings of the 2017 ACM SIGSAC conference on computer and communications security
Pages
2231-2244
Description
Encryption ransomware is a malicious software that stealthily encrypts user files and demands a ransom to provide access to these files. Several prior studies have developed systems to detect ransomware by monitoring the activities that typically occur during a ransomware attack. Unfortunately, by the time the ransomware is detected, some files already undergo encryption and the user is still required to pay a ransom to access those files. Furthermore, ransomware variants can obtain kernel privilege, which allows them to terminate software-based defense systems, such as anti-virus. While periodic backups have been explored as a means to mitigate ransomware, such backups incur storage overheads and are still vulnerable as ransomware can obtain kernel privilege to stop or destroy backups. Ideally, we would like to defend against ransomware without relying on software-based solutions and without incurring …
Total citations
20182019202020212022202320241116121119164
Scholar articles
J Huang, J Xu, X Xing, P Liu, MK Qureshi - Proceedings of the 2017 ACM SIGSAC conference on …, 2017