Visible to the public Study on Systematic Ransomware Detection Techniques

TitleStudy on Systematic Ransomware Detection Techniques
Publication TypeConference Paper
Year of Publication2022
AuthorsLee, Sun-Jin, Shim, Hye-Yeon, Lee, Yu-Rim, Park, Tae-Rim, Park, So-Hyun, Lee, Il-Gu
Conference Name2022 24th International Conference on Advanced Communication Technology (ICACT)
KeywordsCommunications technology, composability, endpoint detection and response (EDR), feature extraction, Google rapid response, Government, Internet of Things, Linux, Metrics, Open Source hids SECurity (OSSEC), open-source EDR, osquery, pubcrawl, ransomware, ransomware detection, resilience, Resiliency, Systematics
AbstractCyberattacks have been progressed in the fields of Internet of Things, and artificial intelligence technologies using the advanced persistent threat (APT) method recently. The damage caused by ransomware is rapidly spreading among APT attacks, and the range of the damages of individuals, corporations, public institutions, and even governments are increasing. The seriousness of the problem has increased because ransomware has been evolving into an intelligent ransomware attack that spreads over the network to infect multiple users simultaneously. This study used open source endpoint detection and response tools to build and test a framework environment that enables systematic ransomware detection at the network and system level. Experimental results demonstrate that the use of EDR tools can quickly extract ransomware attack features and respond to attacks.
NotesISSN: 1738-9445
DOI10.23919/ICACT53585.2022.9728909
Citation Keylee_study_2022