Attributes | Values |
---|
type
| |
seeAlso
| |
sameAs
| |
http://www.loc.gov...erms/relators/EDT
| |
http://eprints.org/ontology/hasAccepted
| |
http://eprints.org/ontology/hasDocument
| |
dc:hasVersion
| |
Title
| - A Roadmap for Improving the Impact of Anti-Ransomware Research
|
described by
| |
Date
| |
Creator
| |
status
| |
Publisher
| |
abstract
| - Ransomware is a type of malware which restricts access to a victim’s computing resources and demands a ransom in order to restore access. This is a continually growing and costly threat across the globe, therefore efforts have been made both in academia and industry to develop techniques that can help to detect and recover from ransomware attacks. This paper aims to provide an overview of the current landscape of Windows-based anti-ransomware tools and techniques, using a clear, simple and consistent terminology in terms of Data Sources, Processing and Actions. We extensively analysed relevant literature so that, to the best of our knowledge, we had at the time covered all approaches taken to detect and recover from ransomware attacks. We grouped these techniques according to their main features as a way to understand the landscape. We then selected 15 existing anti-ransomware tools both to examine how they fit into this landscape and to compare them by aggregating their accuracy and overhead – two of the most important selection criteria of these tools – as reported by the tools’ respective authors. We were able to determine popular solutions and unexplored gaps that could lead to promising areas of anti-ransomware development. From there, we propose two novel detection techniques, namely serial byte correlation and edit distance. This paper serves as a much needed roadmap of knowledge and ideas to systematise the current landscape of anti-ransomware tools.
|
Is Part Of
| |
list of authors
| |
list of editors
| |
presented at
| |
volume
| |
is topic
of | |
is primary topic
of | |