R - Killer: An Email Based Ransomware Protection Tool

Bathiya Lokuketagoda, Medhavi Prathibha Weerakoon, Udara M. Kuruppu, A. Senarathne, Kavinga Yapa Abeywardena
{"title":"R - Killer: An Email Based Ransomware Protection Tool","authors":"Bathiya Lokuketagoda, Medhavi Prathibha Weerakoon, Udara M. Kuruppu, A. Senarathne, Kavinga Yapa Abeywardena","doi":"10.1109/ICCSE.2018.8468807","DOIUrl":null,"url":null,"abstract":"Ransomware has become a common threat in past few years and the recent threat reports show an increase of growth in Ransomware infections. Researchers have identified different variants of Ransomware families since 2015. Lack of knowledge of the user about the threat is a major concern. Ransomware detection methodologies are still growing through the industry. Email is the easiest method to send Ransomware to its victims. Uninformed users tend to click on links and attachments without much consideration assuming the emails are genuine. As a solution to this in this paper R-Killer Ransomware detection tool is introduced. Tool can be integrated with existing email services. The core detection Engine (CDE) discussed in the paper focuses on separating suspicious samples from emails and handling them until a decision is made regarding the suspicious mail. It has the capability of preventing execution of identified ransomware processes. On the other hand, Sandboxing and URL analyzing system has the capability of communication with public threat intelligence services to gather known threat intelligence. The R-Killer has its own mechanism developed in its Proactive Monitoring System (PMS) which can monitor the processes created by downloaded email attachments and identify potential Ransomware activities. R-killer is capable of gathering threat intelligence without exposing the user's data to public threat intelligence services, hence protecting the confidentiality of user data.","PeriodicalId":228760,"journal":{"name":"2018 13th International Conference on Computer Science & Education (ICCSE)","volume":"58 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-08-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"10","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 13th International Conference on Computer Science & Education (ICCSE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCSE.2018.8468807","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 10

Abstract

Ransomware has become a common threat in past few years and the recent threat reports show an increase of growth in Ransomware infections. Researchers have identified different variants of Ransomware families since 2015. Lack of knowledge of the user about the threat is a major concern. Ransomware detection methodologies are still growing through the industry. Email is the easiest method to send Ransomware to its victims. Uninformed users tend to click on links and attachments without much consideration assuming the emails are genuine. As a solution to this in this paper R-Killer Ransomware detection tool is introduced. Tool can be integrated with existing email services. The core detection Engine (CDE) discussed in the paper focuses on separating suspicious samples from emails and handling them until a decision is made regarding the suspicious mail. It has the capability of preventing execution of identified ransomware processes. On the other hand, Sandboxing and URL analyzing system has the capability of communication with public threat intelligence services to gather known threat intelligence. The R-Killer has its own mechanism developed in its Proactive Monitoring System (PMS) which can monitor the processes created by downloaded email attachments and identify potential Ransomware activities. R-killer is capable of gathering threat intelligence without exposing the user's data to public threat intelligence services, hence protecting the confidentiality of user data.
R -杀手:基于电子邮件的勒索软件保护工具
勒索软件在过去几年中已经成为一种常见的威胁,最近的威胁报告显示,勒索软件感染的数量有所增加。自2015年以来,研究人员已经发现了勒索软件家族的不同变体。用户对威胁缺乏了解是一个主要问题。勒索软件检测方法在整个行业中仍在不断发展。电子邮件是向受害者发送勒索软件的最简单方法。不知情的用户倾向于点击链接和附件,而不考虑电子邮件的真实性。为了解决这一问题,本文引入了R-Killer勒索软件检测工具。工具可以与现有的电子邮件服务集成。本文讨论的核心检测引擎(CDE)侧重于从电子邮件中分离可疑样本并对其进行处理,直到对可疑邮件做出决定。它具有防止执行已识别的勒索软件进程的能力。另一方面,沙盒和URL分析系统具有与公共威胁情报机构通信的能力,可以收集已知的威胁情报。R-Killer在其主动监控系统(PMS)中开发了自己的机制,可以监控由下载的电子邮件附件创建的进程,并识别潜在的勒索软件活动。R-killer能够收集威胁情报,而不会将用户数据暴露给公共威胁情报服务,从而保护用户数据的机密性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信