Intrusion and ransomware detection system

Ahmed El-Kosairy, Marianne Amir Azer · 2018

Attackers and cybercriminals are always in a race to either compromise networks and servers or embezzle ransoms through ransomware. Intruders must be prevented from such exploitations of assets, and their malicious attempts counterattacked. Among of the easiest ways of preventing intruders from compromising servers and networks is the use of traditional security controls, such as Intrusion Prevention Systems (IPS), firewalls and Anti-viruses. Such tactics could be successful at lower attacks levels. Current attacks are more aggressive, they can bypass most security tools. Servers are being compromised and files encrypted for ransom. In this paper, we introduce layers of deception systems to detect any intrusion or ransomware trying to gain access to compromise private files by using a deception system based on honeyfiles and honeytokens. We deploy a proof of concept implementation of one of the key deception methods proposed to detect ransomware and intruders.

Read the paper · More papers on PaperTik