中文

基于Hypervisor并利用Kitsune网络特征的双重勒索软件检测方法

密码学与安全 2025-08-28 v1

摘要

由于许多组织针对传统加密勒索软件采用了更强大、更具弹性的数据备份策略,双重勒索软件攻击已成为主流。本文详细介绍了双重勒索软件攻击中使用的攻击阶段、战术、程序和工具。然后,我们提出了一种新颖的检测方法,利用从轻量级Hypervisor获取的低层存储和内存行为特征以及网络流量特征,建立纵深防御策略,以应对攻击者攻破操作系统级防护的情况。我们采用轻量级Kitsune网络入侵检测系统(NIDS)的网络特征来检测双重勒索软件攻击中的数据窃取阶段。我们的实验结果表明,所提出的方法在数据窃取阶段检测率的宏F分数上提高了0.166。最后,我们讨论了所提方法的局限性和未来工作。

关键词

引用

@article{arxiv.2508.08655,
  title  = {Hypervisor-based Double Extortion Ransomware Detection Method Using Kitsune Network Features},
  author = {Manabu Hirano and Ryotaro Kobayashi},
  journal= {arXiv preprint arXiv:2508.08655},
  year   = {2025}
}

备注

\copyright 2025 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works