Automatically Traceback RDP-Based Targeted Ransomware Attacks

المؤلفون المشاركون

Tian, Zhihong
Qiu, Jing
Wang, ZiHan
Liu, ChaoGe
Cui, Xiang
Su, Shen

المصدر

Wireless Communications and Mobile Computing

العدد

المجلد 2018، العدد 2018 (31 ديسمبر/كانون الأول 2018)، ص ص. 1-13، 13ص.

الناشر

Hindawi Publishing Corporation

تاريخ النشر

2018-12-06

دولة النشر

مصر

عدد الصفحات

13

التخصصات الرئيسية

تكنولوجيا المعلومات وعلم الحاسوب

الملخص EN

While various ransomware defense systems have been proposed to deal with traditional randomly-spread ransomware attacks (based on their unique high-noisy behaviors at hosts and on networks), none of them considered ransomware attacks precisely aiming at specific hosts, e.g., using the common Remote Desktop Protocol (RDP).

To address this problem, we propose a systematic method to fight such specifically targeted ransomware by trapping attackers via a network deception environment and then using traceback techniques to identify attack sources.

In particular, we developed various monitors in the proposed deception environment to gather traceable clues about attackers, and we further design an analysis system that automatically extracts and analyze the collected clues.

Our evaluations show that the proposed method can trap the adversary in the deception environment and significantly improve the efficiency of clue analysis.

Furthermore, it also helps us trace back RDP-based ransomware attackers and ransomware makers in the practical applications.

نمط استشهاد جمعية علماء النفس الأمريكية (APA)

Wang, ZiHan& Liu, ChaoGe& Qiu, Jing& Tian, Zhihong& Cui, Xiang& Su, Shen. 2018. Automatically Traceback RDP-Based Targeted Ransomware Attacks. Wireless Communications and Mobile Computing،Vol. 2018, no. 2018, pp.1-13.
https://search.emarefa.net/detail/BIM-1216266

نمط استشهاد الجمعية الأمريكية للغات الحديثة (MLA)

Wang, ZiHan…[et al.]. Automatically Traceback RDP-Based Targeted Ransomware Attacks. Wireless Communications and Mobile Computing No. 2018 (2018), pp.1-13.
https://search.emarefa.net/detail/BIM-1216266

نمط استشهاد الجمعية الطبية الأمريكية (AMA)

Wang, ZiHan& Liu, ChaoGe& Qiu, Jing& Tian, Zhihong& Cui, Xiang& Su, Shen. Automatically Traceback RDP-Based Targeted Ransomware Attacks. Wireless Communications and Mobile Computing. 2018. Vol. 2018, no. 2018, pp.1-13.
https://search.emarefa.net/detail/BIM-1216266

نوع البيانات

مقالات

لغة النص

الإنجليزية

الملاحظات

Includes bibliographical references

رقم السجل

BIM-1216266