Ransomware detection and mitigation using software-defined networking: The case of WannaCry

被引:52
|
作者
Akbanov, Maxat [1 ]
Vassilakis, Vassilios G. [1 ]
Logothetis, Michael D. [2 ]
机构
[1] Univ York, Dept Comp Sci, York, N Yorkshire, England
[2] Univ Patras, Dept Elect & Comp Engn, Patras, Greece
关键词
WannaCry; Ransomware; Software-defined networking; OpenFlow; Malware analysis;
D O I
10.1016/j.compeleceng.2019.03.012
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Modern day ransomware families implement sophisticated encryption and propagation schemes, thus limiting chances to recover the data almost to zero. We investigate the use of software-defined networking (SDN) to detect and mitigate advanced ransomware threat. We present our ransomware analysis results and our developed SDN-based security framework. For the proof of concept, the infamous WannaCry ransomware was used. Based on the obtained results, we design an SDN detection and mitigation framework and develop a solution based on OpenFlow. The developed solution detects suspicious activities through network traffic monitoring and blocks infected hosts by adding flow table entries into OpenFlow switches in a real-time manner. Finally, our experiments with multiple samples of WannaCry show that the developed mechanism in all cases is able to promptly detect the infected machines and prevent WannaCry from spreading. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页码:111 / 121
页数:11
相关论文
共 50 条
  • [21] Towards DDoS detection mechanisms in Software-Defined Networking
    Cui, Yunhe
    Qian, Qing
    Guo, Chun
    Shen, Guowei
    Tian, Youliang
    Xing, Huanlai
    Yan, Lianshan
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2021, 190
  • [22] A Survey on Software-Defined Networking
    Xia, Wenfeng
    Wen, Yonggang
    Foh, Chuan Heng
    Niyato, Dusit
    Xie, Haiyong
    IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2015, 17 (01): : 27 - 51
  • [23] Software-Defined Networking: A survey
    Farhady, Hamid
    Lee, HyunYong
    Nakao, Akihiro
    COMPUTER NETWORKS, 2015, 81 : 79 - 95
  • [24] On Scalability of Software-Defined Networking
    Yeganeh, Soheil Hassas
    Tootoonchian, Amin
    Ganjali, Yashar
    IEEE COMMUNICATIONS MAGAZINE, 2013, 51 (02) : 136 - 141
  • [25] Wavelet against random forest for anomaly mitigation in software-defined networking
    Zerbini, Cinara Brenda
    Carvalho, Luiz Fernando
    Abrao, Taufik
    Proenca Jr, Mario Lemes
    APPLIED SOFT COMPUTING, 2019, 80 : 138 - 153
  • [26] An enhanced saturation attack and its mitigation mechanism in software-defined networking
    Xu, Jianfeng
    Wang, Liming
    Xu, Zhen
    COMPUTER NETWORKS, 2020, 169
  • [27] Collaborative detection and mitigation of DDoS in software-defined networks
    Omer Elsier Tayfour
    Muhammad Nadzir Marsono
    The Journal of Supercomputing, 2021, 77 : 13166 - 13190
  • [28] Collaborative detection and mitigation of DDoS in software-defined networks
    Tayfour, Omer Elsier
    Marsono, Muhammad Nadzir
    JOURNAL OF SUPERCOMPUTING, 2021, 77 (11): : 13166 - 13190
  • [29] Caching Using Software-Defined Networking in LTE Networks
    Kimmerlin, Mael
    Costa-Requena, Jose
    Manner, Jukka
    2014 IEEE INTERNATIONAL CONFERENCE ON ADVANCED NETWORKS AND TELECOMMUNCATIONS SYSTEMS (ANTS), 2014,
  • [30] A Framework for Threats Analysis Using Software-Defined Networking
    Moldovan, Francisc
    Oprisa, Ciprian
    2018 IEEE 14TH INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTER COMMUNICATION AND PROCESSING (ICCP), 2018, : 451 - 457