首页> 外文期刊>International Journal of Information Security >Cryptoviral extortion using Microsoft's Crypto API
【24h】

Cryptoviral extortion using Microsoft's Crypto API

机译:使用Microsoft的Crypto API进行勒索病毒勒索

获取原文
获取原文并翻译 | 示例
           

摘要

This paper presents the experimental results that were obtained by implementing the payload of a cryptovirus on the Microsoft Windows platform. The attack is based entirely on the Microsoft Cryptographic API and the needed API calls are covered in detail. More specifically, it is shown that by using eight types of API calls and 72 lines of C code, the payload can hybrid encrypt sensitive data and hold it hostage. Benchmarks are also given. A novel countermeasure against cryptoviral extortion attacks is shown that forces the API caller to demonstrate that an authorized party can recover the asymmetrically encrypted data.
机译:本文介绍了通过在Microsoft Windows平台上实施加密病毒的有效负载而获得的实验结果。该攻击完全基于Microsoft加密API,并且详细介绍了所需的API调用。更具体地说,它表明,通过使用八种类型的API调用和72行C代码,有效负载可以混合加密敏感数据并将其作为人质。还给出了基准。展示了一种针对密码病毒勒索攻击的新颖对策,该对策迫使API调用者证明授权方可以恢复非对称加密的数据。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号