返回
Applying staged event-driven access control to combat ransomware
DOI:10.1016/j.cose.2023.103160.png)
摘要
En 中文
The advancement of modern Operating Systems (OSs), and the popularity of personal computing devices with Internet connectivity, have facilitated the proliferation of ransomware attacks. Ransomware has evolved from executable programs encrypting user files, to novel attack vectors including fileless command scripts, information exfiltration and human-operated ransomware. Many anti-ransomware studies have been published, but many of them assumed newer ransomware variants only performed file encryption, were similar to existing variants, and often did not consider those novel attack vectors. We have defined an updated ransomware threat model to include those novel attack vectors, and redefined false positives and false negatives in the context of ransomware mitigation. We proposed to apply both program-centric and user-centric access control to combat ransomware, but only delegate access control decisions that users are capable of making to users, while enforcing non-negotiable access control decisions by OS and software developers. We have designed a Staged Event-Driven Access Control (SEDAC) approach to incorporate both program-centric and user-centric access control measures, and demonstrated a prototype on Windows OS. Our prototype was able to intercept more types of ransomware attack vectors than existing proposals. We hope to convince OS and software architects to incorporate our design to better combat ransomware.
Keyword:
Ransomware
Malware
Access control
Ransomware mitigation
Intrusion prevention
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
引用论文
On the economic significance of ransomware campaigns: A Bitcoin transactions perspective关于勒索软件活动的经济意义: 比特币交易视角
COMPUTERS & SECURITY
IF5.4
On the effectiveness of system API-related information for Android ransomware detection关于系统API相关信息对Android勒索软件检测的有效性
COMPUTERS & SECURITY
IF5.4

