Redemption: Real-Time Protection Against Ransomware at End-Hosts
WRITTEN BY: PRESENTED BY: AMIN KHARRAZ NICHOLAS BURTON ENGIN KIRDA
Redemption: Real-Time Protection Against Ransomware at End-Hosts - - PowerPoint PPT Presentation
Redemption: Real-Time Protection Against Ransomware at End-Hosts WRITTEN BY: PRESENTED BY: AMIN KHARRAZ NICHOLAS BURTON ENGIN KIRDA What is Ransomware? What is Ransomware? u Ransomware is malicious software that encrypts user data, and
WRITTEN BY: PRESENTED BY: AMIN KHARRAZ NICHOLAS BURTON ENGIN KIRDA
u Ransomware is malicious software that encrypts
u The easiest solution: keep a backup of your files.
u The easiest solution: keep a backup of your files. u If and when you system is compromised by
u CryptoDrop
u CryptoDrop u SheildFS
u CryptoDrop u SheildFS u PayBreak
u A characterization of ransomware behavior based on
u High performance and integrity mechanism to
u Content-based features u Behavior-based features
u Entropy Ratio of Data Blocks (Shannon Entropy)
u Entropy Ratio of Data Blocks (Shannon Entropy) u File Content Overwrite
u Entropy Ratio of Data Blocks (Shannon Entropy) u File Content Overwrite u Delete Operations
u Directory Traversal
u Directory Traversal u Converting Files to a Specific Type
u Directory Traversal u Converting Files to a Specific Type u Access Frequency
u Aggravating a user to the point were they turn off
u Selective content Overwrite u Low entropy payload u Periodic file destruction