CRIBA: A Tool for Comprehensive Analysis of Cryptographic Ransomware's I/O Behavior

dc.contributor.author Tânia Conceição Araújo en
dc.contributor.author Bruno Filipe Pereira en
dc.contributor.author João Tiago Paulo en
dc.contributor.author João Marco en
dc.contributor.other 7401 en
dc.contributor.other 8963 en
dc.contributor.other 5621 en
dc.contributor.other 6946 en
dc.date.accessioned 2025-01-23T14:24:08Z
dc.date.available 2025-01-23T14:24:08Z
dc.date.issued 2023 en
dc.description.abstract Cryptographic ransomware attacks are constantly evolving by obfuscating their distinctive features (e.g., I/O patterns) to bypass detection mechanisms and to run unnoticed at infected servers. Thus, efficiently exploring the I/O behavior of ransomware families is crucial so that security analysts and engineers can better understand these and, with such knowledge, enhance existing detection methods. In this paper, we propose CRIBA, an open-source framework that simplifies the exploration, analysis, and comparison of I/O patterns for Linux cryptographic ransomware. Our solution combines the collection of comprehensive information about system calls issued by ransomware samples, with a customizable and automated analysis and visualization pipeline, including tailored correlation algorithms and visualizations. Our study, including 5 Linux ransomware families, shows that CRIBA provides comprehensive insights about the I/O patterns of these attacks while aiding in exploring common and differentiating traits across families. en
dc.identifier P-00Z-X1W en
dc.identifier.uri https://repositorio.inesctec.pt/handle/123456789/15276
dc.language eng en
dc.rights info:eu-repo/semantics/openAccess en
dc.title CRIBA: A Tool for Comprehensive Analysis of Cryptographic Ransomware's I/O Behavior en
dc.type en
dc.type Publication en
Files
Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
P-00Z-X1W.pdf
Size:
1.18 MB
Format:
Adobe Portable Document Format
Description: