CryptoLock (and Drop It): Stopping Ransomware Attacks on User Data

被引:251
作者
Scaife, Nolen [1 ]
Carter, Henry [2 ]
Traynor, Patrick [1 ]
Butler, Kevin R. B. [1 ]
机构
[1] Univ Florida, Gainesville, FL 32611 USA
[2] Villanova Univ, Villanova, PA 19085 USA
来源
PROCEEDINGS 2016 IEEE 36TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS ICDCS 2016 | 2016年
基金
美国国家科学基金会;
关键词
D O I
10.1109/ICDCS.2016.46
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Ransomware is a growing threat that encrypts a user's files and holds the decryption key until a ransom is paid by the victim. This type of malware is responsible for tens of millions of dollars in extortion annually. Worse still, developing new variants is trivial, facilitating the evasion of many antivirus and intrusion detection systems. In this work, we present CryptoDrop, an early-warning detection system that alerts a user during suspicious file activity. Using a set of behavior indicators, CryptoDrop can halt a process that appears to be tampering with a large amount of the user's data. Furthermore, by combining a set of indicators common to ransomware, the system can be parameterized for rapid detection with low false positives. Our experimental analysis of CryptoDrop stops ransomware from executing with a median loss of only 10 files (out of nearly 5,100 available files). Our results show that careful analysis of ransomware behavior can produce an effective detection system that significantly mitigates the amount of victim data loss.
引用
收藏
页码:303 / 312
页数:10
相关论文
共 48 条
[1]  
Agrawal N., 2007, ACM T STORAGE TOS
[2]  
Andronio N., 2015, P INT S RES ATTACKS
[3]  
[Anonymous], USENIX SEC S
[4]  
[Anonymous], P ACM C COMP COMM SE
[5]  
[Anonymous], COMPUTER NETWORKS
[6]  
[Anonymous], 2007, P USENIX SEC S
[7]  
ARNOLD E., 2014, TENNESSEE SHERIFF PA
[8]  
Axelsson S., 1999, P ACM C COMP COMM SE
[9]  
Carrigan D., 2015, POLICE DEP HIT RANSO
[10]  
Chakradeo S., 2013, P 6 ACM C SEC PRIV W, P13, DOI DOI 10.1145/2462096.2462100