Ransomware detection and mitigation using software-defined networking: The case of WannaCry

被引:52
|
作者
Akbanov, Maxat [1 ]
Vassilakis, Vassilios G. [1 ]
Logothetis, Michael D. [2 ]
机构
[1] Univ York, Dept Comp Sci, York, N Yorkshire, England
[2] Univ Patras, Dept Elect & Comp Engn, Patras, Greece
关键词
WannaCry; Ransomware; Software-defined networking; OpenFlow; Malware analysis;
D O I
10.1016/j.compeleceng.2019.03.012
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Modern day ransomware families implement sophisticated encryption and propagation schemes, thus limiting chances to recover the data almost to zero. We investigate the use of software-defined networking (SDN) to detect and mitigate advanced ransomware threat. We present our ransomware analysis results and our developed SDN-based security framework. For the proof of concept, the infamous WannaCry ransomware was used. Based on the obtained results, we design an SDN detection and mitigation framework and develop a solution based on OpenFlow. The developed solution detects suspicious activities through network traffic monitoring and blocks infected hosts by adding flow table entries into OpenFlow switches in a real-time manner. Finally, our experiments with multiple samples of WannaCry show that the developed mechanism in all cases is able to promptly detect the infected machines and prevent WannaCry from spreading. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页码:111 / 121
页数:11
相关论文
共 50 条
  • [41] Verification Framework for Software-Defined Networking
    Kang, Miyoung
    Cho, Jong Jin
    2022 24TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT): ARITIFLCIAL INTELLIGENCE TECHNOLOGIES TOWARD CYBERSECURITY, 2022, : 518 - 523
  • [42] Misreporting Attacks in Software-Defined Networking
    Burke, Quinn
    McDaniel, Patrick
    La Porta, Thomas
    Yu, Mingli
    He, Ting
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS (SECURECOMM 2020), PT I, 2020, 335 : 276 - 296
  • [43] Software-defined networking (SDN): a survey
    Benzekki, Kamal
    El Fergougui, Abdeslam
    Elalaoui, Abdelbaki Elbelrhiti
    SECURITY AND COMMUNICATION NETWORKS, 2016, 9 (18) : 5803 - 5833
  • [44] Toward Software-Defined Middlebox Networking
    Gember, Aaron
    Prabhu, Prathmesh
    Ghadiyali, Zainab
    Akella, Aditya
    PROCEEDINGS OF THE 11TH ACM WORKSHOP ON HOT TOPICS IN NETWORKS (HOTNETS-XI), 2012, : 7 - 12
  • [45] Toward Software-Defined Battlefield Networking
    Nobre, Jeferson
    Rosario, Denis
    Both, Cristiano
    Cerqueira, Eduardo
    Gerla, Mario
    IEEE COMMUNICATIONS MAGAZINE, 2016, 54 (10) : 152 - 157
  • [46] Semantic Failover in Software-Defined Networking
    Hsueh, Shu-Wen
    Lin, Tung-Yueh
    Lei, Weng-Ian
    Ngai, Chi-Leung Patrick
    Sheng, Yu-Hang
    Wu, Yu-Sung
    2018 IEEE 23RD PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING (PRDC), 2018, : 299 - 308
  • [47] A Software-Defined Approach to IoT Networking
    Christian Jacquenet
    Mohamed Boucadair
    ZTE Communications, 2016, 14 (01) : 61 - 66
  • [48] Software-Defined Networking: A Comprehensive Survey
    Kreutz, Diego
    Ramos, Fernando M. V.
    Verissimo, Paulo Esteves
    Rothenberg, Christian Esteve
    Azodolmolky, Siamak
    Uhlig, Steve
    PROCEEDINGS OF THE IEEE, 2015, 103 (01) : 14 - 76
  • [49] Software-Defined Networking of Linux Containers
    Costache, Cosmin
    Machidon, Octavian
    Mladin, Adrian
    Sandu, Florin
    Bocu, Razvan
    2014 ROEDUNET CONFERENCE 13TH EDITION: NETWORKING IN EDUCATION AND RESEARCH JOINT EVENT RENAM 8TH CONFERENCE, 2014,
  • [50] SADM-SDNC: security anomaly detection and mitigation in software-defined networking using C-support vector classification
    Tohid Jafarian
    Mohammad Masdari
    Ali Ghaffari
    Kambiz Majidzadeh
    Computing, 2021, 103 : 641 - 673