2023
DOI: 10.3390/s23104728
|View full text |Cite
|
Sign up to set email alerts
|

Neutralization Method of Ransomware Detection Technology Using Format Preserving Encryption

Abstract: Ransomware is one type of malware that involves restricting access to files by encrypting files stored on the victim’s system and demanding money in return for file recovery. Although various ransomware detection technologies have been introduced, existing ransomware detection technologies have certain limitations and problems that affect their detection ability. Therefore, there is a need for new detection technologies that can overcome the problems of existing detection methods and minimize the damage from r… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2

Citation Types

0
2
0

Year Published

2024
2024
2024
2024

Publication Types

Select...
1

Relationship

0
1

Authors

Journals

citations
Cited by 1 publication
(2 citation statements)
references
References 17 publications
0
2
0
Order By: Relevance
“…Most of these encodings consist of lightweight operations, thereby not significantly impacting the speed of the ransomware attack. However, if the defense system identifies that the file is encoded, it can effectively detect the file infected with ransomware because decoding can be performed without the key [ 40 ].…”
Section: Ransomware Detection and Neutralization Methodsmentioning
confidence: 99%
See 1 more Smart Citation
“…Most of these encodings consist of lightweight operations, thereby not significantly impacting the speed of the ransomware attack. However, if the defense system identifies that the file is encoded, it can effectively detect the file infected with ransomware because decoding can be performed without the key [ 40 ].…”
Section: Ransomware Detection and Neutralization Methodsmentioning
confidence: 99%
“…FPE is an encryption method that maintains the same format for plaintext and ciphertext, thus keeping the entropy after encryption similar to that of plaintext. In [ 40 ], the FF1 algorithm was used to circumvent entropy-based ransomware detection using the characteristics of FPE. However, this can reduce the speed of ransomware’s encryption attack due to its high computational complexity.…”
Section: Ransomware Detection and Neutralization Methodsmentioning
confidence: 99%