A 0-day aware crypto-ransomware early behavioral detection framework

Bander Ali Saleh Al-rimy*, Mohd Aizaini Maarof, Syed Zainuddin Mohd Shaid

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Crypto-Ransomware exploits cryptography to hijack personal files and documents and hold them to ransom. Utilizing such technological leap, crypto-ransomware targets a wide range of systems, and platforms. Although many users, whether individuals or organizations, practice proactive security procedures like regular backup, advanced crypto-ransomware can bypass these countermeasures rendering the valuable data vulnerable to such extortion attack. Due to the irreversible nature of its damage, thwarting crypto-ransomware becomes challenging. Although several studies have been conducted to tackle crypto-ransomware detection problem, most of them dealt with it from malware perspective. Such approach has deemed ineffective given the unique characteristics that distinguish this attack which necessitate the early discovery before encryption takes place. To this end, this paper puts forward an efficient and effective framework for building crypto-ransomware early detection models that protect users, whether individuals or organizations, of being victimized by such attack.

Original languageEnglish
Title of host publicationRecent Trends in Information and Communication Technology
Subtitle of host publicationProceedings of the 2nd International Conference of Reliable Information and Communication Technology (IRICT 2017)
EditorsFaisal Saeed, Nadhmi Gazem, Srikanta Patnaik, Ali Saleh Saed Balaid, Fathey Mohammed
PublisherSpringer Science and Business Media Deutschland GmbH
Pages758-766
Number of pages9
ISBN (Electronic)9783319594279
ISBN (Print)9783319594262
DOIs
Publication statusPublished - 27 May 2017
Event2nd International Conference of Reliable Information and Communication Technology 2017 (IRICT 2017) - Johor, Malaysia
Duration: 23 Apr 201724 Apr 2017

Publication series

NameLecture Notes on Data Engineering and Communications Technologies
Volume5
ISSN (Print)2367-4512
ISSN (Electronic)2367-4520

Conference

Conference2nd International Conference of Reliable Information and Communication Technology 2017 (IRICT 2017)
Country/TerritoryMalaysia
CityJohor
Period23/04/1724/04/17

Keywords

  • Bitcoin
  • Crypto-ransomware
  • Cryptography
  • Cybercurrency
  • Early detection
  • Locker-ransomware
  • Malware
  • Scareware

Fingerprint

Dive into the research topics of 'A 0-day aware crypto-ransomware early behavioral detection framework'. Together they form a unique fingerprint.

Cite this