ScienceDirect The 2 nd International Workshop on Future Information Security , Privacy & Forensics for Complex Systems ( FISP 2016 ) Experimental Analysis of Ransomware on Windows and Android Platforms : Evolution and Characterization
ScienceDirect The 2 nd International Workshop on Future Information Security , Privacy & Forensics for Complex Systems ( FISP 2016 ) Experimental Analysis of Ransomware on Windows and Android Platforms : Evolution and Characterization
复制标题
ScienceDirect 第二届未来信息安全、隐私国际研讨会
DOI:
--
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
Dale Lindskog
中科院分区:
文献类型:
--
作者:
P. Zavarsky;Dale Lindskog
The focus of the paper is on providing insights on how ransomware have evolved from its starting till March 2016 by analyzing samples of selected ransomware variants from existing ransomware families in Windows and Android environments. Seventeen Windows and eight Android ransomware families were analyzed. For each ransomware family, at least, three variants belonging to the same family were compared. The analysis revealed that ransomware variants behave in a very similar manner, but use different payloads. Our analysis shows that there has been a significant improvement in encryption techniques used by ransomware. The experimental results in Windows environment demonstrate that detection of ransomware is possible by monitoring abnormal filesystem and registry activities. In Android environment, our analysis reveals that likelihood of ransomware attacks can be reduced by paying a closer attention to permissions requested by the Android applications. © 2016 The Authors. Published by Elsevier B.V. Peer-review under responsibility of the Conference Program Chairs.