Using Software-Defined Networking for Ransomware Mitigation: The Case of CryptoWall

作者:Cabaj Krzysztof*; Mazurczyk Wojciech
来源:IEEE Network, 2016, 30(6): 14-20.
DOI:10.1109/MNET.2016.1600110NM

摘要

Currently, different forms of ransomware are increasingly threatening Internet users. Modern ransomware encrypts important user data, and it is only possible to recover it once a ransom has been paid. In this article we show how software-defined networking can be utilized to improve ransomware mitigation. In more detail, we analyze the behavior of popular ransomware - CryptoWall - and, based on this knowledge, propose two real-time mitigation methods. Then we describe the design of an SDN-based system, implemented using OpenFlow, that facilitates a timely reaction to this threat, and is a crucial factor in the case of crypto ransomware. What is important is that such a design does not significantly affect overall network performance. Experimental results confirm that the proposed approach is feasible and efficient.

  • 出版日期2016-12