Rcryptect: Real-time detection of cryptographic function in the user-space filesystem

Cited 7 time in webofscience Cited 0 time in scopus
  • Hit : 250
  • Download : 0
DC FieldValueLanguage
dc.contributor.authorLee, Seungkwangko
dc.contributor.authorJho, Nam-suko
dc.contributor.authorChung, Doyoungko
dc.contributor.authorKang, Yousungko
dc.contributor.authorKim, Myungchulko
dc.date.accessioned2021-12-07T06:40:42Z-
dc.date.available2021-12-07T06:40:42Z-
dc.date.created2021-12-07-
dc.date.created2021-12-07-
dc.date.created2021-12-07-
dc.date.issued2022-01-
dc.identifier.citationCOMPUTERS & SECURITY, v.112-
dc.identifier.issn0167-4048-
dc.identifier.urihttp://hdl.handle.net/10203/290093-
dc.description.abstractThe existing methods of ransomware detection have limitations. To be specific, static analysis is not effective to obfuscated binaries, while dynamic analysis is usually restricted to a certain platform and often takes tens of minutes. In this paper, we propose a block level monitoring system to detect potentially malicious cryptographic operations. We carry out statistical analysis to find heuristic rules to distinguish between normal and encrypted blocks. In order to apply the heuristic rule to the filesystem without kernel modification, we adopt Filesystem in Userspace (FUSE) and define our filesystem Rcryptect for real-time detection of cryptographic function. We demonstrate the protection of well-known ransomware and show that various cryptographic functions can be detected with about 13% overhead. (c) 2021 The Authors. Published by Elsevier Ltd. This is an open access article under the CC BY-NC-ND license ( http://creativecommons.org/licenses/by-nc-nd/4.0/ )-
dc.languageEnglish-
dc.publisherELSEVIER ADVANCED TECHNOLOGY-
dc.titleRcryptect: Real-time detection of cryptographic function in the user-space filesystem-
dc.typeArticle-
dc.identifier.wosid000721360300012-
dc.identifier.scopusid2-s2.0-85118573876-
dc.type.rimsART-
dc.citation.volume112-
dc.citation.publicationnameCOMPUTERS & SECURITY-
dc.identifier.doi10.1016/j.cose.2021.102512-
dc.contributor.localauthorKim, Myungchul-
dc.contributor.nonIdAuthorJho, Nam-su-
dc.contributor.nonIdAuthorKang, Yousung-
dc.description.isOpenAccessN-
dc.type.journalArticleArticle-
dc.subject.keywordAuthorDevice security-
dc.subject.keywordAuthorRansomware-
dc.subject.keywordAuthorCryptographic function detection-
dc.subject.keywordAuthorEntropy-
dc.subject.keywordAuthorFUSE-
dc.subject.keywordPlusSOFTWARE-DEFINED NETWORKING-
Appears in Collection
CS-Journal Papers(저널논문)
Files in This Item
There are no files associated with this item.
This item is cited by other documents in WoS
⊙ Detail Information in WoSⓡ Click to see webofscience_button
⊙ Cited 7 items in WoS Click to see citing articles in records_button

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0