The Experts below are selected from a list of 7014 Experts worldwide ranked by ideXlab platform
Mikel Izal - One of the best experts on this subject based on the ideXlab platform.
-
Ransomware early detection by the analysis of file sharing traffic
Journal of Network and Computer Applications, 2018Co-Authors: Daniel Morato, Eduardo Berrueta, Eduardo Magana, Mikel IzalAbstract:Crypto ransomware is a type of malware that locks access to user files by encrypting them and demands a ransom in order to obtain the decryption key. This type of malware has become a serious threat for most enterprises. In those cases where the Infected Computer has access to documents in network shared volumes, a single host can lock access to documents across several departments in the company. We propose an algorithm that can detect ransomware action and prevent further activity over shared documents. The algorithm is based on the analysis of passively monitored traffic by a network probe. 19 different ransomware families were used for testing the algorithm in action. The results show that it can detect ransomware activity in less than 20 s, before more than 10 files are lost. Recovery of even those files was also possible because their content was stored in the traffic monitored by the network probe. Several days of traffic from real corporate networks were used to validate a low rate of false alarms. This paper offers also analytical models for the probability of early detection and the probability of false alarms for an arbitrarily large population of users.
Eric Keller - One of the best experts on this subject based on the ideXlab platform.
-
machine learning based detection of ransomware using sdn
International Workshop on Security, 2018Co-Authors: Greg Cusack, Oliver Michel, Eric KellerAbstract:The growth of malware poses a major threat to internet users, governments, and businesses around the world. One of the major types of malware, ransomware, encrypts a user's sensitive information and only returns the original files to the user after a ransom is paid. As malware developers shift the delivery of their product from HTTP to HTTPS to protect themselves from payload inspection, we can no longer rely on deep packet inspection to extract features for malware identification. Toward this goal, we propose a solution leveraging a recent trend in networking hardware, that is programmable forwarding engines (PFEs). PFEs allow collection of per-packet, network monitoring data at high rates. We use this data to monitor the network traffic between an Infected Computer and the command and control (C&C) server. We extract high-level flow features from this traffic and use this data for ransomware classification. We write a stream processor and use a random forest, binary classifier to utilizes these rich flow records in fingerprinting malicious, network activity without the requirement of deep packet inspection. Our classification model achieves a detection rate in excess of 0.86, while maintaining a false negative rate under 0.11. Our results suggest that a flow-based fingerprinting method is feasible and accurate enough to catch ransomware before encryption.
Agraj Tripathi - One of the best experts on this subject based on the ideXlab platform.
-
modeling and analysis of the effects of antivirus software on an Infected Computer network
Applied Mathematics and Computation, 2014Co-Authors: Jyoti Shukla, Gaurav Singh, Poonam Shukla, Agraj TripathiAbstract:In this paper, a nonlinear mathematical model for cleaning an Infected Computer network by using antivirus software is proposed and analyzed. In the modeling process, the total number of nodes in the network are divided in three subclasses, namely, the number of susceptible nodes, number of Infected nodes and the number of protected nodes. A variable representing the number of antivirus softwares, assumed to be proportional to number of Infected nodes, is also considered in the model which interacts with other nodes bilinearly to conduct the cleaning process. The model is analyzed by using stability theory of differential equations and Computer simulation. The analysis shows that it is possible to clean the Computer network under certain condition which depend upon the inflow rate of Infected nodes in the Computer network, the rate of interaction of Infected nodes with susceptible nodes and their interactions with antivirus software, etc. It is found that the entire network can be cleaned eventually if the antivirus software is applied on the network, where a separate class of protected nodes is formed. The Computer simulation confirms the analytical results.
Daniel Morato - One of the best experts on this subject based on the ideXlab platform.
-
Ransomware early detection by the analysis of file sharing traffic
Journal of Network and Computer Applications, 2018Co-Authors: Daniel Morato, Eduardo Berrueta, Eduardo Magana, Mikel IzalAbstract:Crypto ransomware is a type of malware that locks access to user files by encrypting them and demands a ransom in order to obtain the decryption key. This type of malware has become a serious threat for most enterprises. In those cases where the Infected Computer has access to documents in network shared volumes, a single host can lock access to documents across several departments in the company. We propose an algorithm that can detect ransomware action and prevent further activity over shared documents. The algorithm is based on the analysis of passively monitored traffic by a network probe. 19 different ransomware families were used for testing the algorithm in action. The results show that it can detect ransomware activity in less than 20 s, before more than 10 files are lost. Recovery of even those files was also possible because their content was stored in the traffic monitored by the network probe. Several days of traffic from real corporate networks were used to validate a low rate of false alarms. This paper offers also analytical models for the probability of early detection and the probability of false alarms for an arbitrarily large population of users.
Lahcen Omari - One of the best experts on this subject based on the ideXlab platform.
-
deterministic and stochastic study for an Infected Computer network model powered by a system of antivirus programs
Discrete Dynamics in Nature and Society, 2017Co-Authors: Youness El Ansari, Ali El Myr, Lahcen OmariAbstract:We investigate the various conditions that control the extinction and stability of a nonlinear mathematical spread model with stochastic perturbations. This model describes the spread of viruses into an Infected Computer network which is powered by a system of antivirus software. The system is analyzed by using the stability theory of stochastic differential equations and the Computer simulations. First, we study the global stability of the virus-free equilibrium state and the virus-epidemic equilibrium state. Furthermore, we use the Ito formula and some other theoretical theorems of stochastic differential equation to discuss the extinction and the stationary distribution of our system. The analysis gives a sufficient condition for the infection to be extinct (i.e., the number of viruses tends exponentially to zero). The ergodicity of the solution and the stationary distribution can be obtained if the basic reproduction number is bigger than , and the intensities of stochastic fluctuations are small enough. Numerical simulations are carried out to illustrate the theoretical results.