Differential Area Analysis for Ransomware: Attacks, Countermeasures, and Limitations

03/30/2023
by   Marco Venturini, et al.
0

Crypto-ransomware attacks have been a growing threat over the last few years. The goal of every ransomware strain is encrypting user data, such that attackers can later demand users a ransom for unlocking their data. To maximise their earning chances, attackers equip their ransomware with strong encryption which produce files with high entropy values. Davies et al. proposed Differential Area Analysis (DAA), a technique that analyses files headers to differentiate compressed, regularly encrypted, and ransomware-encrypted files. In this paper, first we propose three different attacks to perform malicious header manipulation and bypass DAA detection. Then, we propose three countermeasures, namely 2-Fragments (2F), 3-Fragments (3F), and 4-Fragments (4F), which can be applied equally against each of the three attacks we propose. We conduct a number of experiments to analyse the ability of our countermeasures to detect ransomware-encrypted files, whether implementing our proposed attacks or not. Last, we test the robustness of our own countermeasures by analysing the performance, in terms of files per second analysed and resilience to extensive injection of low-entropy data. Our results show that our detection countermeasures are viable and deployable alternatives to DAA.

READ FULL TEXT

page 1

page 11

page 12

research
06/28/2021

Differential Area Analysis for Ransomware Attack Detection within Mixed File Datasets

The threat from ransomware continues to grow both in the number of affec...
research
02/09/2021

Avaddon ransomware: an in-depth analysis and decryption of infected systems

The commoditization of Malware-as-a-Service (MaaS) allows criminals to o...
research
10/15/2020

EnCoD: Distinguishing Compressed and Encrypted File Fragments

Reliable identification of encrypted file fragments is a requirement for...
research
10/24/2022

Comparison of Entropy Calculation Methods for Ransomware Encrypted File Identification

Ransomware is a malicious class of software that utilises encryption to ...
research
03/31/2021

Reliable Detection of Compressed and Encrypted Data

Several cybersecurity domains, such as ransomware detection, forensics a...
research
09/20/2021

Traitor-Proof PDF Watermarking

This paper presents a traitor-tracing technique based on the watermarkin...
research
11/22/2018

PE-AONT: Partial Encryption combined with an All-or-Nothing Transform

In this report, we introduce PE-AONT: a novel algorithm for fast and sec...

Please sign up or login with your details

Forgot password? Click here to reset