首页|基于主动欺骗的反勒索软件方法

基于主动欺骗的反勒索软件方法

扫码查看
考虑到勒索软件对数据安全构成的严重威胁及其攻击手段的日益智能化和复杂化,针对传统防御方法的局限性,提出了一种基于主动欺骗的反勒索软件方法.结合静态启发式算法和动态启发式算法对欺骗文件进行动态部署,在此基础上建立了基于主动欺骗的动态文件安全模型.针对不同风险级别的勒索软件,采用不同的策略生成动态欺骗文件,通过模拟真实数据的特征来迷惑勒索软件,使其无法区分真实数据和欺骗数据,从而保护用户的真实数据不被加密或破坏.实验结果表明,所提方法有效增加了文件的动态性、多样性和欺骗性,大幅扩展了数据攻击面的转换空间,能够有效地抵御勒索软件攻击.
Anti-ransomware method based on active deception
Considering the serious threat that ransomware poses to data security and the increasing intelligence and com-plexity of its attack methods,an anti-ransomware method based on active deception was proposed to address the limita-tions of traditional defense methods.By combining static heuristic algorithms and dynamic heuristic algorithms to dy-namically deploy deceptive files,a dynamic file security model based on active deception was established.Different strategies were employed to generate dynamic deceptive files for ransomware of different risk levels,confusing ransom-ware by simulating the characteristics of real data,making it unable to distinguish between real and deceptive data,thus protecting users'real data from encryption or destruction.Experimental results show that the proposed method effec-tively increases the dynamism,diversity,and deceptiveness of files,significantly expanding the shifting space of data at-tack surfaces and effectively defending against ransomware attacks.

active deceptionanti-ransomwaredata attack surfacedata deception

陈凯、马多贺、唐志敏、DAI Jun

展开 >

中国科学院信息工程研究所,北京 100095

中国科学院大学网络空间安全学院,北京 100095

伍斯特理工学院计算机科学系,伍斯特 01609

主动欺骗 反勒索软件 数据攻击面 数据欺骗

中国通信标准化协会"电信网和互联网勒索软件防范技术要求"标准基金

2023-0722T-YD

2024

通信学报
中国通信学会

通信学报

CSTPCD北大核心
影响因子:1.265
ISSN:1000-436X
年,卷(期):2024.45(7)
  • 22