Policy-based and Behavioral Framework to Detect Ransomware Affecting Resource-constrained Sensors

Alberto Huertas Celdrán, Pedro Miguel Sánchez Sánchez, Eder J. Scheid, Timucin Besken, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller · NOMS 2022-2022 IEEE/IFIP Network Operations and Management Symposium · 2022

Traditionally, data centers have been the preferred target for ransomware attacks. However, the increasing number of IoT (Internet-of-Things) devices managing valuable data is attracting the attention of cybercriminals and ransomware towards resource-constrained devices. So far, literature has demonstrated the suitability of monitoring the behavior of devices to detect some malware infections. However, most of these existing solutions have been designed and validated in Windows-based systems without computational restrictions.Thus, this work presents a lightweight policy-based framework that uses behavioral fingerprinting to detect anomalies and classify ransomware affecting resource-constrained and Linux-based sensors. The framework detection capabilities have been validated in a resource-constrained spectrum sensor belonging to ElectroSense, a real crowdsensing platform. In particular, three policies, created as a proof-of-concept, resulted in promising findings in terms of detection performance and time, when identifying anomalies by classifying two recent ransomware samples affecting a Raspberry Pi acting as sensor.

Read the paper · More papers on PaperTik