@article{ART002935540},
author={Lee, Hyung Woo},
title={Cryptography Module Detection and Identification Mechanism on Malicious Ransomware Software},
journal={Journal of Internet of Things and Convergence},
issn={2466-0078},
year={2023},
volume={9},
number={1},
pages={1-7},
doi={10.20465/KIOTS.2023.9.1.001}
TY - JOUR
AU - Lee, Hyung Woo
TI - Cryptography Module Detection and Identification Mechanism on Malicious Ransomware Software
JO - Journal of Internet of Things and Convergence
PY - 2023
VL - 9
IS - 1
PB - The Korea Internet of Things Society
SP - 1
EP - 7
SN - 2466-0078
AB - Cases in which personal terminals or servers are infected by ransomware are rapidly increasing.
Ransomware uses a self-developed encryption module or combines existing symmetric key/public key encryption modules to illegally encrypt files stored in the victim system using a key known only to the attacker. Therefore, in order to decrypt it, it is necessary to know the value of the key used, and since the process of finding the decryption key takes a lot of time, financial costs are eventually paid. At this time, most of the ransomware malware is included in a hidden form in binary files, so when the program is executed, the user is infected with the malicious code without even knowing it. Therefore, in order to respond to ransomware attacks in the form of binary files, it is necessary to identify the encryption module used. Therefore, in this study, we developed a mechanism that can detect and identify by reverse analyzing the encryption module applied to the malicious code hidden in the binary file.
KW - Ransomware;Hidden Malicious Code;Reverse Engineering;Detection and identification Mechanism.
DO - 10.20465/KIOTS.2023.9.1.001
ER -
Lee, Hyung Woo. (2023). Cryptography Module Detection and Identification Mechanism on Malicious Ransomware Software. Journal of Internet of Things and Convergence, 9(1), 1-7.
Lee, Hyung Woo. 2023, "Cryptography Module Detection and Identification Mechanism on Malicious Ransomware Software", Journal of Internet of Things and Convergence, vol.9, no.1 pp.1-7. Available from: doi:10.20465/KIOTS.2023.9.1.001
Lee, Hyung Woo "Cryptography Module Detection and Identification Mechanism on Malicious Ransomware Software" Journal of Internet of Things and Convergence 9.1 pp.1-7 (2023) : 1.
Lee, Hyung Woo. Cryptography Module Detection and Identification Mechanism on Malicious Ransomware Software. 2023; 9(1), 1-7. Available from: doi:10.20465/KIOTS.2023.9.1.001
Lee, Hyung Woo. "Cryptography Module Detection and Identification Mechanism on Malicious Ransomware Software" Journal of Internet of Things and Convergence 9, no.1 (2023) : 1-7.doi: 10.20465/KIOTS.2023.9.1.001
Lee, Hyung Woo. Cryptography Module Detection and Identification Mechanism on Malicious Ransomware Software. Journal of Internet of Things and Convergence, 9(1), 1-7. doi: 10.20465/KIOTS.2023.9.1.001
Lee, Hyung Woo. Cryptography Module Detection and Identification Mechanism on Malicious Ransomware Software. Journal of Internet of Things and Convergence. 2023; 9(1) 1-7. doi: 10.20465/KIOTS.2023.9.1.001
Lee, Hyung Woo. Cryptography Module Detection and Identification Mechanism on Malicious Ransomware Software. 2023; 9(1), 1-7. Available from: doi:10.20465/KIOTS.2023.9.1.001
Lee, Hyung Woo. "Cryptography Module Detection and Identification Mechanism on Malicious Ransomware Software" Journal of Internet of Things and Convergence 9, no.1 (2023) : 1-7.doi: 10.20465/KIOTS.2023.9.1.001