Visible to the public Using Software-Defined Networking for Ransomware Mitigation: The Case of CryptoWall

TitleUsing Software-Defined Networking for Ransomware Mitigation: The Case of CryptoWall
Publication TypeJournal Article
Year of Publication2016
AuthorsCabaj, K., Mazurczyk, W.
JournalIEEE Network
Volume30
Pagination14–20
ISSN0890-8044
Keywordscomposability, computer network security, cryptography, CryptoWall case, Encryption, Forensics, Human Behavior, Internet, IP networks, Malware, Metrics, Network security, OpenFlow, pubcrawl, Public key, ransomware, ransomware mitigation, real-time mitigation method, Resiliency, SDN-based system design, Servers, software defined networking, surveillance, user data encryption
Abstract

Currently, different forms of ransomware are increasingly threatening Internet users. Modern ransomware encrypts important user data, and it is only possible to recover it once a ransom has been paid. In this article we show how software-defined networking can be utilized to improve ransomware mitigation. In more detail, we analyze the behavior of popular ransomware - CryptoWall - and, based on this knowledge, propose two real-time mitigation methods. Then we describe the design of an SDN-based system, implemented using OpenFlow, that facilitates a timely reaction to this threat, and is a crucial factor in the case of crypto ransomware. What is important is that such a design does not significantly affect overall network performance. Experimental results confirm that the proposed approach is feasible and efficient.

URLhttp://ieeexplore.ieee.org/document/7764294/
DOI10.1109/MNET.2016.1600110NM
Citation Keycabaj_using_2016