arXiv · 2304.04398
Ransomware Detection and Classification Strategies
Abstract
Ransomware uses encryption methods to make data inaccessible to legitimate users. To date a wide range of ransomware families have been developed and deployed, causing immense damage to governments, corporations, and private users. As these cyberthreats multiply, researchers have proposed a range of ransomware detection and classification schemes. Most of these methods use advanced machine learning techniques to process and analyze real-world ransomware binaries and action sequences. Hence this paper presents a survey of this critical space and classifies existing solutions into several categories, i.e., including network-based, host-based, forensic characterization, and authorship attribution. Key facilities and tools for ransomware analysis are also presented along with open challenges.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Aldin Vehabovic, Nasir Ghani, Elias Bou-Harb, Jorge Crichigno, Aysegul Yayimli. 2023-04-10. Ransomware Detection and Classification Strategies. https://doi.org/10.1109/blackseacom54372.2022.9858296
Cite the original work for its findings. Save a collection to share your selection of sources.