Toward A Network-Assisted Approach for Effective Ransomware Detection

Authors

  • Tianrou Xia Pennsylvania State University
  • Yuanyi Sun Pennsylvania State University
  • Sencun Zhu Pennsylvania State University
  • Zeeshan Rasheed Novateur Research Solutions (United States)
  • Khurram Shafique Novateur Research Solutions (United States)

DOI:

https://doi.org/10.4108/eai.28-1-2021.168506

Keywords:

ransomware detection, ant colony optimization algorithm, network security

Abstract

Ransomware is one kind of malware using cryptography to prevent victims from normal use of their computers. As a result, victims lose the access to their files and desktops unless they pay the ransom to the attackers. By the end of 2019, ransomware attack had caused more than 10 billion dollars of financial loss to enterprises and individuals. In this work, we propose a Network-Assisted Approach (NAA), which contains local detection and network-level detection, to help user determine whether a machine has been infected by ransomware. To evaluate its performance, we built 100 containers in Docker to simulate network scenarios. A hybrid ransomware sample which is close to real-world ransomware is deployed on stimulative infected machines. The experiment results show that our network-level detection mechanisms are separately applicable to WAN and LAN scenarios for ransomware detection.

Downloads

Published

28-01-2021

How to Cite

1.
Xia T, Sun Y, Zhu S, Rasheed Z, Shafique K. Toward A Network-Assisted Approach for Effective Ransomware Detection. EAI Endorsed Trans Sec Saf [Internet]. 2021 Jan. 28 [cited 2025 Nov. 22];7(24):e3. Available from: https://publications.eai.eu/index.php/sesa/article/view/98

Most read articles by the same author(s)