Exploiting Ransomware Paranoia For Execution Prevention

Exploiting Ransomware Paranoia For Execution Prevention
复制标题

利用勒索软件偏执来预防执行

DOI:
10.1109/icc40277.2020.9149005
复制
发表时间:
2020
期刊:
ICC 2020 - 2020 IEEE International Conference on Communications (ICC)
影响因子:
--
通讯作者:
J. Crichigno
J. Crichigno
中科院分区:
--
文献类型:
--
作者:
Ali AlSabeh;H. Safa;E. Bou;J. Crichigno

文献摘要

被引文献

相似文献

勒索软件攻击使企业每年损失超过750亿美元,预计到2021年将损失6万亿美元。这些数字表明勒索软件对大量行业造成的破坏,并敦促安全研究人员解决它。在文献中,已经提出了几种勒索软件检测方法,这些方法在静态和动态分析之间进行交换。最近,勒索软件攻击被证明在攻击系统之前对执行环境进行指纹识别,以对抗动态分析。在本文中,我们利用当代勒索软件的行为来防止其对真实的系统的攻击,从而避免任何数据的丢失。我们探索了一组勒索软件生成的工件,这些工件被启动以嗅探周围环境。此外,我们设计,开发和评估一种方法,通过拦截调用的Windows API来监视程序的行为。因此,我们实时确定程序是否试图在攻击前检查其周围环境,并在启动任何恶意加密或锁定之前立即中止它。通过使用真实的和最近的勒索软件样本进行实证评估,我们研究了勒索软件和良性程序如何检查环境。此外,我们还演示了如何以较低的误报率防止勒索软件。我们通过GitHub将开发的方法提供给整个研究社区,以大力促进网络安全防御行动,并进行大规模的评估和增强。
Ransomware attacks cost businesses more than $75 billion/year, and it is predicted to cost $6 trillion/year by 2021. These numbers demonstrate the havoc produced by ransomware on a large number of sectors and urge security researches to tackle it. Several ransomware detection approaches have been proposed in the literature that interchange between static and dynamic analysis. Recently, ransomware attacks were shown to fingerprint the execution environment before they attack the system to counter dynamic analysis. In this paper, we exploit the behavior of contemporary ransomware to prevent its attack on real systems and thus avoid the loss of any data. We explore a set of ransomware-generated artifacts that are launched to sniff the surrounding. Furthermore, we design, develop, and evaluate an approach that monitors the behavior of a program by intercepting the called Windows APIs. Consequently, we determine in real-time if the program is trying to inspect its surrounding before the attack, and abort it immediately prior to the initiation of any malicious encryption or locking. Through empirical evaluations using real and recent ransomware samples, we study how ransomware and benign programs inspect the environment. Additionally, we demonstrate how to prevent ransomware with a low false positive rate. We make the developed approach available to the research community at large through GitHub to strongly promote cyber security defense operations and for wide-scale evaluations and enhancements.