Hands Off my Database: Ransomware Detection in Databases through Dynamic Analysis of Query Sequences

07/15/2019
by   Lukas Iffländer, et al.
0

Ransomware is an emerging threat which imposed a $ 5 billion loss in 2017 and is predicted to hit $ 11.5 billion in 2019. While initially targeting PC (client) platforms, ransomware recently made the leap to server-side databases - starting in January 2017 with the MongoDB Apocalypse attack, followed by other attack waves targeting a wide range of DB types such as MongoDB, MySQL, ElasticSearch, Cassandra, Hadoop, and CouchDB. While previous research has developed countermeasures against client-side ransomware (e.g., CryptoDrop and ShieldFS), the problem of server-side ransomware has received zero attention so far. In our work, we aim to bridge this gap and present DIMAQS (Dynamic Identification of Malicious Query Sequences), a novel anti-ransomware solution for databases. DIMAQS performs runtime monitoring of incoming queries and pattern matching using Colored Petri Nets (CPNs) for attack detection. Our system design exhibits several novel techniques to enable efficient detection of malicious query sequences globally (i.e., without limiting detection to distinct user connections). Our proof-of-concept implementation targets MySQL servers. The evaluation shows high efficiency with no false positives and no false negatives and very moderate performance overhead of under 5 publish our data sets and implementation allowing the community to reproduce our tests and compare to our results.

READ FULL TEXT
research
08/03/2018

Adaptive Traffic Fingerprinting for Darknet Threat Intelligence

Darknet technology such as Tor has been used by various threat actors fo...
research
06/06/2018

AIQL: Enabling Efficient Attack Investigation from System Monitoring Data

The need for countering Advanced Persistent Threat (APT) attacks has led...
research
08/24/2018

AuthPDB: Query Authentication for Outsourced Probabilistic Databases

Spurred by developments such as cloud computing, there are increasing ef...
research
10/08/2021

IHOP: Improved Statistical Query Recovery against Searchable Symmetric Encryption through Quadratic Optimization

Searchable Symmetric Encryption (SSE) schemes allow a client to perform ...
research
01/26/2020

AI-Powered GUI Attack and Its Defensive Methods

Since the first Graphical User Interface (GUI) prototype was invented in...
research
03/16/2022

Extensive Threat Analysis of Vein Attack Databases and Attack Detection by Fusion of Comparison Scores

The last decade has brought forward many great contributions regarding p...
research
12/04/2021

PhishMatch: A Layered Approach for Effective Detection of Phishing URLs

Phishing attacks continue to be a significant threat on the Internet. Pr...

Please sign up or login with your details

Forgot password? Click here to reset