Comparative analysis of various ransomware virii

Comparative analysis of various ransomware virii
复制标题

DOI:
10.1007/s11416-008-0092-2
复制
发表时间:
2010-02-01
期刊:
JOURNAL IN COMPUTER VIROLOGY AND HACKING TECHNIQUES
影响因子:
--
通讯作者:
Gazet, Alexandre
Gazet, Alexandre
中科院分区:
其他
文献类型:
--
作者:
Gazet, Alexandre

文献摘要

被引文献

相似文献

勒索软件这个词和相关现象大约出现在3年前,也就是2005年左右。它揭示了一类特定的恶意软件,这些恶意软件要求付费以换取被盗的功能。大多数广泛传播的勒索软件都大量使用文件加密作为勒索手段。基本上,他们加密受害者硬盘上的各种文件,然后索要赎金来解密文件。安全相关媒体和一些反病毒厂商迅速将这种“新型”病毒标榜为计算机世界的主要威胁。本文试图在现象之外探讨这些威胁的基础。为了更好地了解勒索软件,该研究依赖于对各种勒索软件病毒的比较分析。基于逆向工程而不关注分析方法,在不同的层次上进行技术审查:代码质量、恶意软件的功能和加密原语的分析(如果有的话)。我们的分析使我们对这一现象,特别是所使用的勒索手段的优缺点,得出了许多有趣的方法和结论。我们还利用我们的技术审查退后一步,分析与这些勒索软件相关的商业模式以及围绕它们进行的沟通。
The word ransomware and the associated phenomenon appeared something like 3 years ago, around the year 2005. It shed light on a specific class of malwares which demand a payment in exchange for a stolen functionality. Most widespread ransomwares make an intensive use of file encryption as an extortion mean. Basically, they encrypt various files on victim's hard drives before asking for a ransom to get the files decrypted. Security related media and some antivirus vendors quickly brandished this "new" type of virii as a major threat for computer world. This article tries to investigate the foundation of these threats beyond the phenomenon. In order to get a better understanding of ransomwares, the study relies on a comparative analysis of various ransomware virii. Based on reverse-engineering while not focused on analysis methodology, a technical review is done at different levels: quality of code, malwares' functionalities and analysis of cryptographic primitives if any. Our analysis leads us to many interesting approaches and conclusions concerning this phenomenon, and in particular the strength and weakness of used extortion means. We also take advantage of our technical review to stand back and to analyse both the business model associated to these ransomwares and the communication that has been made around them.