Detecting Ransomware Execution in a Timely Manner

01/12/2022
by   Anthony Melaragno, et al.
0

Ransomware has been an ongoing issue since the early 1990s. In recent times ransomware has spread from traditional computational resources to cyber-physical systems and industrial controls. We devised a series of experiments in which virtual instances are infected with ransomware. We instrumented the instances and collected resource utilization data across a variety of metrics (CPU, Memory, Disk Utility). We design a change point detection and learning method for identifying ransomware execution. Finally we evaluate and demonstrate its ability to detect ransomware efficiently in a timely manner when trained on a minimal set of samples. Our results represent a step forward for defense, and we conclude with further remarks for the path forward.

READ FULL TEXT
research
02/13/2020

Compensation of Linear Attacks to Cyber Physical Systems through ARX System Identification

Cyber-Physical Systems (CPSs) are vastly used in today's cities critical...
research
03/16/2022

High dimensional change-point detection: a complete graph approach

The aim of online change-point detection is for a accurate, timely disco...
research
12/24/2019

Deadline-aware Scheduling for Maximizing Information Freshness in Industrial Cyber-Physical System

Age of Information is an interesting metric that captures the freshness ...
research
03/01/2020

Change Point Detection in Software Performance Testing

We describe our process for automatic detection of performance changes f...
research
03/15/2012

Real-Time Scheduling via Reinforcement Learning

Cyber-physical systems, such as mobile robots, must respond adaptively t...
research
02/08/2018

On Ordering Multi-Robot Task Executions within a Cyber Physical System

With robots entering the world of Cyber Physical Systems (CPS), ordering...

Please sign up or login with your details

Forgot password? Click here to reset