RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    낮은 오인 탐지를 위한 파일 읽기/쓰기 행동 비율 기반 랜섬웨어 탐지 기법 = File Read/Write Behavior Ratio-Based Ransomware Detection for Low False Positive Detection

    한글로보기

    https://www.riss.kr/link?id=T17355714

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수
    인용문이 복사되었습니다.

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    랜섬웨어는 사용자의 파일을 암호화하여 금전을 탈취하는 멀웨어로 기본적인 파일 읽기/쓰기/수정/삭제와 같은 간단한 행동만으로 랜섬웨어 제작이 가능하다. 그러나 최근 랜섬웨어 탐지의 고도화로 랜섬웨어 제작자들은 압축 파일등 응용 프로그램의 행동을 랜섬웨어가 모방하여 탐지를 은폐하려는 전술을 채택하여 랜섬웨어 탐지 프로그램의 오탐을 유발한다. 본 연구는 낮은 오인 탐지를 위해 프로세스가 실시간으로 파일 읽기/쓰기를 행동 비율을 기반으로 랜섬웨어가 탐지하는 동적 탐지 기법을 제안한다. 본 연구에서는 압축 프로그램을 포함한 정상 프로그램 4종 와 랜섬웨어 7종을 대상으로 실험을 진행하였고 그 결과 7종 전원 탐지 및 정상 프로그램 4종이 오탐 되지 않았다. 또한 평균 3.7%의 낮은 오버헤드를 보였다. 본 연구는 복잡한 보안 솔루션 적용이 어려우며 안전성과 호환성으로 인해 레거시 OS을 사용하고 있는 산업, 의료 환경에서 보안성 향상에 기여를 할 수가 있다.
    번역하기

    랜섬웨어는 사용자의 파일을 암호화하여 금전을 탈취하는 멀웨어로 기본적인 파일 읽기/쓰기/수정/삭제와 같은 간단한 행동만으로 랜섬웨어 제작이 가능하다. 그러나 최근 랜섬웨어 탐지의...

    랜섬웨어는 사용자의 파일을 암호화하여 금전을 탈취하는 멀웨어로 기본적인 파일 읽기/쓰기/수정/삭제와 같은 간단한 행동만으로 랜섬웨어 제작이 가능하다. 그러나 최근 랜섬웨어 탐지의 고도화로 랜섬웨어 제작자들은 압축 파일등 응용 프로그램의 행동을 랜섬웨어가 모방하여 탐지를 은폐하려는 전술을 채택하여 랜섬웨어 탐지 프로그램의 오탐을 유발한다. 본 연구는 낮은 오인 탐지를 위해 프로세스가 실시간으로 파일 읽기/쓰기를 행동 비율을 기반으로 랜섬웨어가 탐지하는 동적 탐지 기법을 제안한다. 본 연구에서는 압축 프로그램을 포함한 정상 프로그램 4종 와 랜섬웨어 7종을 대상으로 실험을 진행하였고 그 결과 7종 전원 탐지 및 정상 프로그램 4종이 오탐 되지 않았다. 또한 평균 3.7%의 낮은 오버헤드를 보였다. 본 연구는 복잡한 보안 솔루션 적용이 어려우며 안전성과 호환성으로 인해 레거시 OS을 사용하고 있는 산업, 의료 환경에서 보안성 향상에 기여를 할 수가 있다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    Ransomware is malware that encrypts user files and extorts money. It can be created with simple actions like reading /writing /modifying/deleting files. However, with the recent advancements in ransomware detection, ransomware creators are adopting tactics by mimicking the behavior of applications, such as compressed files, leading to false positives in ransomware detection programs. This study proposes a dynamic detection technique that based on the real-time file read/write behavior of processes, reducing false positives. Experiments were conducted on four legitimate programs, including compression programs, and seven ransomwares. The results showed that all seven strains were detected, and four legitimate programs were free of false positives and a low average overhead of 3.7%. This study can contribute to improving security in industrial and healthcare environments where complex security solutions are difficult to implement and legacy operating systems are reliant on security and compatibility.
    번역하기

    Ransomware is malware that encrypts user files and extorts money. It can be created with simple actions like reading /writing /modifying/deleting files. However, with the recent advancements in ransomware detection, ransomware creators are adopting ta...

    Ransomware is malware that encrypts user files and extorts money. It can be created with simple actions like reading /writing /modifying/deleting files. However, with the recent advancements in ransomware detection, ransomware creators are adopting tactics by mimicking the behavior of applications, such as compressed files, leading to false positives in ransomware detection programs. This study proposes a dynamic detection technique that based on the real-time file read/write behavior of processes, reducing false positives. Experiments were conducted on four legitimate programs, including compression programs, and seven ransomwares. The results showed that all seven strains were detected, and four legitimate programs were free of false positives and a low average overhead of 3.7%. This study can contribute to improving security in industrial and healthcare environments where complex security solutions are difficult to implement and legacy operating systems are reliant on security and compatibility.

    더보기

    목차 (Table of Contents)

    • 제1 장 서론 1
    • 1.1 연구 배경 1
    • 1.2 연구의 내용 및 범위 3
    • 1.3 논문의 구성 4
    • 제2 장 관련 연구 5
    • 제1 장 서론 1
    • 1.1 연구 배경 1
    • 1.2 연구의 내용 및 범위 3
    • 1.3 논문의 구성 4
    • 제2 장 관련 연구 5
    • 2.1 랜섬웨어 진행 단계 및 특징 5
    • 2.1.1 페이로드 전달 및 정찰 단계 5
    • 2.1.2 공격 지시 단계 7
    • 2.1.3 파괴 단계 10
    • 2.1.4 금품 갈취 요구 단계 13
    • 2.2 랜섬웨어 탐지 방법 14
    • 2.2.1 동적 분석 기반 탐지 기법 15
    • 2.2.2 허니팟 기반 탐지 기법 17
    • 2.3 기존 랜섬웨어 탐지 기법 한계점 22
    • 2.3.1 동적 분석 기반 랜섬웨어 탐지 기법 한계점 22
    • 2.3.2 허니팟 기반 탐지 랜섬웨어 탐지 기법 한계점 24
    • 제3 장 파일 읽기/쓰기 행동 비율 기반 랜섬웨어 탐지 기법 26
    • 3.1 위협 모델 26
    • 3.2 가설 27
    • 3.3 탐지 알고리즘 기법 구성 29
    • 제4 장 실험 36
    • 4.1 정상 프로그램과 랜섬웨어 탐지 및 오탐 실험 구현 36
    • 4.2 베어메탈 성능 테스트 실험 구현 39
    • 제5 장 결과 및 분석 41
    • 5.1 정상 프로그램과 랜섬웨어의 탐지 및 오탐 41
    • 5.2 베어메탈 환경에서 오버헤드 45
    • 제6 장 결론 47
    • 참고문헌 49
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼