랜섬웨어는 사용자의 파일을 암호화하여 금전을 탈취하는 멀웨어로 기본적인 파일 읽기/쓰기/수정/삭제와 같은 간단한 행동만으로 랜섬웨어 제작이 가능하다. 그러나 최근 랜섬웨어 탐지의...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T17355714
서울 : 숭실대학교 정보과학대학원, 2025
학위논문(석사) -- 숭실대학교 정보과학대학원 , 정보보안학과(정원) , 2026. 2
2025
한국어
서울
56 ; 26 cm
지도교수: 강병윤
I804:11044-200000943606
0
상세조회0
다운로드랜섬웨어는 사용자의 파일을 암호화하여 금전을 탈취하는 멀웨어로 기본적인 파일 읽기/쓰기/수정/삭제와 같은 간단한 행동만으로 랜섬웨어 제작이 가능하다. 그러나 최근 랜섬웨어 탐지의...
랜섬웨어는 사용자의 파일을 암호화하여 금전을 탈취하는 멀웨어로 기본적인 파일 읽기/쓰기/수정/삭제와 같은 간단한 행동만으로 랜섬웨어 제작이 가능하다. 그러나 최근 랜섬웨어 탐지의 고도화로 랜섬웨어 제작자들은 압축 파일등 응용 프로그램의 행동을 랜섬웨어가 모방하여 탐지를 은폐하려는 전술을 채택하여 랜섬웨어 탐지 프로그램의 오탐을 유발한다. 본 연구는 낮은 오인 탐지를 위해 프로세스가 실시간으로 파일 읽기/쓰기를 행동 비율을 기반으로 랜섬웨어가 탐지하는 동적 탐지 기법을 제안한다. 본 연구에서는 압축 프로그램을 포함한 정상 프로그램 4종 와 랜섬웨어 7종을 대상으로 실험을 진행하였고 그 결과 7종 전원 탐지 및 정상 프로그램 4종이 오탐 되지 않았다. 또한 평균 3.7%의 낮은 오버헤드를 보였다. 본 연구는 복잡한 보안 솔루션 적용이 어려우며 안전성과 호환성으로 인해 레거시 OS을 사용하고 있는 산업, 의료 환경에서 보안성 향상에 기여를 할 수가 있다.
다국어 초록 (Multilingual Abstract)
Ransomware is malware that encrypts user files and extorts money. It can be created with simple actions like reading /writing /modifying/deleting files. However, with the recent advancements in ransomware detection, ransomware creators are adopting ta...
Ransomware is malware that encrypts user files and extorts money. It can be created with simple actions like reading /writing /modifying/deleting files. However, with the recent advancements in ransomware detection, ransomware creators are adopting tactics by mimicking the behavior of applications, such as compressed files, leading to false positives in ransomware detection programs. This study proposes a dynamic detection technique that based on the real-time file read/write behavior of processes, reducing false positives. Experiments were conducted on four legitimate programs, including compression programs, and seven ransomwares. The results showed that all seven strains were detected, and four legitimate programs were free of false positives and a low average overhead of 3.7%. This study can contribute to improving security in industrial and healthcare environments where complex security solutions are difficult to implement and legacy operating systems are reliant on security and compatibility.
목차 (Table of Contents)