Ransomware behavioural analysis on windows platforms

Ransomware behavioural analysis on windows platforms
复制标题

DOI:
10.1016/j.jisa.2018.02.008
复制
发表时间:
2018-06-01
影响因子:
5.6
通讯作者:
Zeadally, Sherali
Zeadally, Sherali
中科院分区:
计算机科学3区
文献类型:
--
作者:
Hampton, Nikolai;Baig, Zubair;Zeadally, Sherali

文献摘要

被引文献

相似文献

最近,勒索软件感染呈指数级增长,对包括政府在内的一系列行业的运营造成重大干扰。通过这项研究,我们对感染 Windows 平台的 14 种勒索软件进行了分析,并将通过勒索软件进程进行的 Windows 应用程序编程接口 (API) 调用与正常操作系统行为的基线进行了比较。该研究通过 API 调用频率识别并报告勒索软件的显着特征。 (C) 2018 Elsevier Ltd. 保留所有权利。
Ransomware infections have grown exponentially during the recent past to cause major disruption in operations across a range of industries including the government. Through this research, we present an analysis of 14 strains of ransomware that infect Windows platforms, and we do a comparison of Windows Application Programming Interface (API) calls made through ransomware processes with baselines of normal operating system behaviour. The study identifies and reports salient features of ransomware as referred through the frequencies of API calls. (C) 2018 Elsevier Ltd. All rights reserved.