Defeating Ransomware By Hooking System Calls On Windows Os
but.event.date | 27.04.2021 | cs |
but.event.title | STUDENT EEICT 2021 | cs |
dc.contributor.author | Touš, Filip | |
dc.date.accessioned | 2021-07-21T07:06:58Z | |
dc.date.available | 2021-07-21T07:06:58Z | |
dc.date.issued | 2021 | cs |
dc.description.abstract | This paper explains why ransomware needs to use the Windows API to encrypt files andhow this can be utilized to protect sensitive data from ransomware. Critical API functions are examinedon a low level and a generic method to monitor and possibly block their usage through systemcall hooks is presented. This approach is then demonstrated with a custom kernel mode driver whichcan keep protected files safe from any user mode malware. It is then compared to current ransomwareprotection in Windows 10. | en |
dc.format | text | cs |
dc.format.extent | 24-27 | cs |
dc.format.mimetype | application/pdf | en |
dc.identifier.citation | Proceedings I of the 27st Conference STUDENT EEICT 2021: General papers. s. 24-27. ISBN 978-80-214-5942-7 | cs |
dc.identifier.isbn | 978-80-214-5942-7 | |
dc.identifier.uri | http://hdl.handle.net/11012/200756 | |
dc.language.iso | cs | cs |
dc.publisher | Vysoké učení technické v Brně, Fakulta elektrotechniky a komunikačních technologií | cs |
dc.relation.ispartof | Proceedings I of the 27st Conference STUDENT EEICT 2021: General papers | en |
dc.relation.uri | https://conf.feec.vutbr.cz/eeict/index/pages/view/ke_stazeni | cs |
dc.rights | © Vysoké učení technické v Brně, Fakulta elektrotechniky a komunikačních technologií | cs |
dc.rights.access | openAccess | en |
dc.subject | ransomware | en |
dc.subject | Windows API | en |
dc.subject | system call | en |
dc.subject | hooking | en |
dc.title | Defeating Ransomware By Hooking System Calls On Windows Os | en |
dc.type.driver | conferenceObject | en |
dc.type.status | Peer-reviewed | en |
dc.type.version | publishedVersion | en |
eprints.affiliatedInstitution.department | Fakulta elektrotechniky a komunikačních technologií | cs |
Files
Original bundle
1 - 1 of 1
Loading...
- Name:
- 24_eeict-2021_1.pdf
- Size:
- 258.39 KB
- Format:
- Adobe Portable Document Format
- Description: