Ran$Net: An Anti-Ransomware Methodology based on Cache Monitoring and Deep Learning
Ran$Net: An Anti-Ransomware Methodology based on Cache Monitoring and Deep Learning
复制标题
Ran$Net:基于缓存监控和深度学习的反勒索软件方法
DOI:
10.1145/3526241.3530830
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
Fei, Yunsi
中科院分区:
文献类型:
--
作者:
Zhang, Xiang;Zhang, Ziyue;Ding, Ruyi;Gongye, Cheng;Ding, Aidong Adam;Fei, Yunsi
Ransomware has become a serious threat in the cyberspace. Existing software pattern-based malware detectors are specific for certain ransomware and may not capture new variants. Recognizing a common essential behavior of ransomware - employing local cryptographic software for malicious encryption and therefore leaving footprints on the victim machine's caches, this work proposes an anti-ransomware methodology, Ran$Net, based on hardware activities. It consists of a passive cache monitor to log suspicious cache activities, and a follow-on non-profiled deep learning analysis strategy to retrieve the secret cryptographic key from the timing traces generated by the monitor. We implement the first of its kind tool to combat an open-source ransomware and successfully recover the secret key.
登录
查看更多内容
DOI:
--
发表时间:
2012
期刊:
International Conference on Malicious and Unwanted Software
影响因子:
--
作者:
Jonghoon Kwon;Heejo Lee
通讯作者:
Heejo Lee
DOI:
--
发表时间:
2009
期刊:
2009 3rd International Conference on Anti-counterfeiting, Security, and Identification in Communication
影响因子:
--
作者:
Kaiming Huang;Yanfang Ye;Qinshan Jiang
通讯作者:
Qinshan Jiang
影响因子:
2.3
作者:
Ugarte-Pedrero, Xabier;Graziano, Mariano;Balzarotti, Davide
通讯作者:
Balzarotti, Davide
DOI:
--
发表时间:
2012
期刊:
World Congress on Internet Security
影响因子:
--
作者:
P. R. Lakshmi Eswari;N. Sarat;Chandra Babu
通讯作者:
Chandra Babu