arrow
返回

Applying staged event-driven access control to combat ransomware

delete2023-05-01
delete4
delete
OA
AI
T
Timothy R. McIntosh *
A
A. S. M. Kayes
Y
Yi‐Ping Phoebe Chen
A
Alex Ng
P
Paul Watters
DOI:10.1016/j.cose.2023.103160delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
The advancement of modern Operating Systems (OSs), and the popularity of personal computing devices with Internet connectivity, have facilitated the proliferation of ransomware attacks. Ransomware has evolved from executable programs encrypting user files, to novel attack vectors including fileless command scripts, information exfiltration and human-operated ransomware. Many anti-ransomware studies have been published, but many of them assumed newer ransomware variants only performed file encryption, were similar to existing variants, and often did not consider those novel attack vectors. We have defined an updated ransomware threat model to include those novel attack vectors, and redefined false positives and false negatives in the context of ransomware mitigation. We proposed to apply both program-centric and user-centric access control to combat ransomware, but only delegate access control decisions that users are capable of making to users, while enforcing non-negotiable access control decisions by OS and software developers. We have designed a Staged Event-Driven Access Control (SEDAC) approach to incorporate both program-centric and user-centric access control measures, and demonstrated a prototype on Windows OS. Our prototype was able to intercept more types of ransomware attack vectors than existing proposals. We hope to convince OS and software architects to incorporate our design to better combat ransomware.
Keyword:
Ransomware
Malware
Access control
Ransomware mitigation
Intrusion prevention
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

L
La Trobe University
学者数:
1.1W
论文数: 1.1W
被引数: 1.5W
引用论文

引用论文

err分享
err收藏
Ransomware Mitigation in the Modern Era: A Comprehensive Review, Research Challenges, and Future Directions
err2021-10-08
err45
PREAI
errMcIntosh, Timothy; Kayes, A. S. M.; Chen, Yi-Ping Phoebe; Ng, Alex; Watters, Paul
err分享
err收藏
Dynamic user-centric access control for detection of ransomware attacks
err2021-12-01
err13
PREAI
errMcIntosh, Timothy; Kayes, A. S. M.; Chen, Yi-Ping Phoebe; Ng, Alex; Watters, Paul
err分享
err收藏
Management of Spontaneous Cerebrospinal Fluid Otorrhea
err2009-01-02
err0
PREAI
errJoe Walter Kutz; Inna Athar Husain; Brandon Isaacson; Peter S. Roland
err分享
err收藏
On the effectiveness of system API-related information for Android ransomware detection关于系统API相关信息对Android勒索软件检测的有效性
err2019-09-01
err66
errOAAI
errScalas, Michele; Maiorca, Davide; Mercaldo, Francesco; Visaggio, Corrado Aaron; Martinelli, Fabio; Giacinto, Giorgio
err分享
err收藏
err分享
err收藏
R-Locker: Thwarting ransomware action through a honeyfile-based approach
err2018-03-01
err99
errOAAI
errGomez-Hernandez, J. A.; Alvarez-Gonzalez, L.; Garcia-Teodoro, P.
err分享
err收藏
学者 查看更多内容