Ransomware Network Traffic Analysis for Pre-Encryption Alert - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2019

Ransomware Network Traffic Analysis for Pre-Encryption Alert

Résumé

Cyber Security researchers are in an ongoing battle against ransomware attacks. Some exploits begin with social engineering methods to install payloads on victims' computers , followed by a communication with command and control servers for data exchange. To scale down these attacks, scientists should shed light on the danger of those rising intrusions to prevent permanent data loss. To join this arm race against malware, we propose in this paper an analysis of various ransomware families based on the collected system and network logs from a computer. We delve into malicious network traffic generated by these samples to perform a packet level detection. Our goal is to reconstruct ransomware's full activity to check if its network communication is distinguishable from benign traffic. Then, we examine if the first packet sent occurs before data's encryption to alert the administrators or afterwards. We aim to define the first occurrence of the alert raised by malicious network traffic and where it takes place in a ransomware workflow. Logs collected are available at http://serveur2.seres.rennes.telecom-bretagne.eu/data/RansomwareData/.
Fichier principal
Vignette du fichier
paper_19.pdf (648.62 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-02313656 , version 1 (03-03-2020)

Identifiants

Citer

Routa Moussaileb, Nora Cuppens, Jean-Louis Lanet, Hélène Le Bouder. Ransomware Network Traffic Analysis for Pre-Encryption Alert. FPS 2019: 12th International Symposium on Foundations & Practice of Security, Nov 2019, Toulouse, France. ⟨10.1007/978-3-030-45371-8_2⟩. ⟨hal-02313656⟩
478 Consultations
1982 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More