Content area

Abstract

Ransomware is a very effective form of malware that is recently spreading out on an impressive number of workstations and smartphones. This malware blocks the access to the infected machine or to the files located in the infected machine. The attackers will restore the machine and files only after the payment of a certain amount of money, usually given in the form of bitcoins. Commercial solutions are still ineffective to recognize the last variants of ransomware, and the problem has been poorly investigated in literature. In this paper we discuss a methodology based on formal methods for detecting ransomware malware on Android devices. We have implemented our method in a tool named Talos. We evaluate the method, and the obtained results show that Talos is very effective in recognizing ransomware (accuracy of 0.99) even when it is obfuscated (accuracy still remains at 0.99).

Details

Title
Talos: no more ransomware victims with formal methods
Author
Cimitile, Aniello 1 ; Mercaldo, Francesco 2 ; Nardone, Vittoria 1 ; Santone, Antonella 3 ; Visaggio, Corrado Aaron 1 

 Department of Engineering, University of Sannio, Benevento, Italy 
 Institute for Informatics and Telematics, CNR, Pisa, Italy 
 Department of Bioscience and Territory, University of Molise, Pesche, IS, Italy 
Pages
719-738
Publication year
2018
Publication date
Nov 2018
Publisher
Springer Nature B.V.
ISSN
16155262
e-ISSN
16155270
Source type
Scholarly Journal
Language of publication
English
ProQuest document ID
1978527548
Copyright
International Journal of Information Security is a copyright of Springer, (2017). All Rights Reserved.