랜섬웨어 동적 분석을 위한 시그니처 추출 및 선정 방법

Method of Signature Extraction and Selection for Ransomware Dynamic Analysis

초록

Recently, there are increasing damages by ransomware in the world. Ransomware is a malicious software that infects computer systems and restricts user’s access to them by locking the system or encrypting user’s files saved in the hard drive. Victims are forced to pay the ‘ransom’ to recover from the damage and regain access to their personal files. Strong countermeasure is needed due to the extremely vicious way of attack with enormous damage. Malware analysis method can be divided into two approaches: static analysis and dynamic analysis. Recent malwares are usually equipped with elaborate packing techniques which are main obstacles for static analysis of malware. Therefore, this paper suggests a dynamic analysis method to monitor activities of ransomware. The proposed method can analyze ransomwares more accurately. The suggested method is comprised of extracting signatures of benign program, malware, and ransomware, and selecting the most appropriate signatures for ransomware detection.

키워드

랜섬웨어랜섬웨어 탐지악성코드동적 분석시그니처유사도 분석ransomwareransomware detectionmalwaredynamic analysissignaturesimilarity analysis
제목
랜섬웨어 동적 분석을 위한 시그니처 추출 및 선정 방법
제목 (타언어)
Method of Signature Extraction and Selection for Ransomware Dynamic Analysis
저자
이규빈옥정윤임을규
DOI
10.5626/KTCP.2018.24.2.99
발행일
2018-02
저널명
정보과학회 컴퓨팅의 실제 논문지
24
2
페이지
99 ~ 104