首页> 外文OA文献 >Software-Defined Networking-based Crypto Ransomware Detection Using HTTP Traffic Characteristics
【2h】

Software-Defined Networking-based Crypto Ransomware Detection Using HTTP Traffic Characteristics

机译:使用HTTp进行软件定义的基于网络的加密勒索软件检测   交通特征

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Ransomware is currently the key threat for individual as well as corporateInternet users. Especially dangerous is crypto ransomware that encryptsimportant user data and it is only possible to recover it once a ransom hasbeen paid. Therefore devising efficient and effective countermeasures is arising necessity. In this paper we present a novel Software-Defined Networking(SDN) based detection approach that utilizes characteristics of ransomwarecommunication. Based on the observation of network communication of two cryptoransomware families, namely CryptoWall and Locky we conclude that analysis ofthe HTTP messages' sequences and their respective content sizes is enough todetect such threats. We show feasibility of our approach by designing andevaluating the proof-of-concept SDN-based detection system. Experimentalresults confirm that the proposed approach is feasible and efficient.
机译:勒索软件目前是个人和企业Internet用户的主要威胁。加密勒索软件特别危险,它会加密重要的用户数据,并且只有在支付了赎金后才可以恢复它。因此,有必要制定有效而有效的对策。在本文中,我们提出了一种新颖的基于软件定义网络(SDN)的检测方法,该方法利用了勒索软件通信的特征。基于对两个加密勒索软件系列CryptoWall和Locky的网络通信的观察,我们得出结论,对HTTP消息的序列及其各自的内容大小进行分析足以检测到此类威胁。通过设计和评估基于概念验证的SDN检测系统,我们证明了该方法的可行性。实验结果证实了该方法的可行性和有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号