Ransomware detection and mitigation using software-defined networking: The case of WannaCry

被引:52
|
作者
Akbanov, Maxat [1 ]
Vassilakis, Vassilios G. [1 ]
Logothetis, Michael D. [2 ]
机构
[1] Univ York, Dept Comp Sci, York, N Yorkshire, England
[2] Univ Patras, Dept Elect & Comp Engn, Patras, Greece
关键词
WannaCry; Ransomware; Software-defined networking; OpenFlow; Malware analysis;
D O I
10.1016/j.compeleceng.2019.03.012
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Modern day ransomware families implement sophisticated encryption and propagation schemes, thus limiting chances to recover the data almost to zero. We investigate the use of software-defined networking (SDN) to detect and mitigate advanced ransomware threat. We present our ransomware analysis results and our developed SDN-based security framework. For the proof of concept, the infamous WannaCry ransomware was used. Based on the obtained results, we design an SDN detection and mitigation framework and develop a solution based on OpenFlow. The developed solution detects suspicious activities through network traffic monitoring and blocks infected hosts by adding flow table entries into OpenFlow switches in a real-time manner. Finally, our experiments with multiple samples of WannaCry show that the developed mechanism in all cases is able to promptly detect the infected machines and prevent WannaCry from spreading. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页码:111 / 121
页数:11
相关论文
共 50 条
  • [31] ENHANCING AVAILABILITY OF SERVICES USING SOFTWARE-DEFINED NETWORKING
    Klepac, Martin
    Hegr, Tomas
    Bohac, Leos
    ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING, 2015, 13 (05) : 529 - 535
  • [32] Simulating Resilient Server using Software-Defined Networking
    Winarno, Idris
    Ishida, Yoshiteru
    2016 INTERNATIONAL CONFERENCE ON ADVANCED INFORMATICS - CONCEPTS, THEORY AND APPLICATION (ICAICTA), 2016,
  • [33] An Extension Approach for Threat Detection and Defense of Software-Defined Networking
    Xu, Hui
    Wang, Chunzhi
    Chen, Hongwei
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2016, 10 (02): : 365 - 374
  • [34] Programmable Networks-From Software-Defined Radio to Software-Defined Networking
    Macedo, Daniel F.
    Guedes, Dorgival
    Vieira, Luiz F. M.
    Vieira, Marcos A. M.
    Nogueira, Michele
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2015, 17 (02): : 1102 - 1125
  • [35] Joint DDoS detection system based on software-defined networking
    Song Y.
    Yang H.
    Wu W.
    Hu A.
    Gao S.
    Qinghua Daxue Xuebao/Journal of Tsinghua University, 2019, 59 (01): : 28 - 35
  • [36] Software-Defined Networking (SDN) based VANET Architecture: Mitigation of Traffic Congestion
    Adbeb, Tesfanesh
    Di, Wu
    Ibrar, Muhammad
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (03) : 706 - 714
  • [37] FMD: A DoS mitigation scheme based on flow migration in software-defined networking
    Wu, Pengpeng
    Yao, Lin
    Lin, Chi
    Wu, Guowei
    Obaidat, Mohammad S.
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2018, 31 (09)
  • [38] A Survey of Multicast in Software-Defined Networking
    Gu, Weidong
    Zhang, Xinchang
    Gong, Bin
    Wang, Lu
    PROCEEDINGS OF THE 5TH INTERNATIONAL CONFERENCE ON INFORMATION ENGINEERING FOR MECHANICS AND MATERIALS, 2015, 21 : 1096 - 1100
  • [39] A Survey on Multicasting in Software-Defined Networking
    Islam, Salekul
    Muslim, Nasif
    Atwood, J. William
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2018, 20 (01): : 355 - 387
  • [40] Software-Defined Networking: On the Verge of a Breakthrough?
    Ortiz, Sixto, Jr.
    COMPUTER, 2013, 46 (07) : 10 - 12