NDSS 2025 – Detecting Ransomware Despite I/O Overhead: A Practical Multi-Staged Approach
嗯,用户让我帮忙总结一篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”之类的开头。好的,我先看看这篇文章讲的是什么。 文章标题是关于勒索软件的检测方法。作者们来自RWTH Aachen University和Fraunhofer FKIE。他们提出了一种多阶段的方法,用于检测勒索软件,同时考虑了I/O操作的开销问题。 首先,勒索软件攻击现在非常严重,影响到企业和个人。现有的检测方法主要通过实时监控I/O活动,但这些方法可能会显著影响系统性能,尤其是SSD这样的快速存储设备。 作者们分析了监控不同I/O特征对系统性能的影响,发现即使简单的特征如缓冲区的熵也会让执行时间增加350%,SSD性能下降75%。为了应对这个问题,他们提出了一个动态调整监控特征数量的方法。 具体来说,他们设计了一个多阶段的入侵检测系统(IDS),根据进程的行为实时调整监控阶段。良性进程进入监控较少特征的阶段,而可疑进程则进入监控更多特征的阶段。这样可以显著减少I/O操作的时间开销。 实验结果显示,这种方法在保持检测准确度的同时,将开销降低了大约一个数量级。因此,实时行为监控在勒索软件检测中变得可行。 总结一下:文章讨论了现有勒索软件检测方法的性能问题,并提出了一种多阶段的方法来平衡检测和性能之间的关系。 </think> 本文探讨了勒索软件检测中的I/O开销问题,并提出了一种多阶段方法以平衡检测与性能。研究发现简单特征分析可使SSD性能下降75%,因此建议动态调整监控特征数量。实验表明该方法可将开销降低一个数量级,同时保持较高检测率。 2026-1-27 16:0:0 Author: securityboulevard.com(查看原文) 阅读量:0 收藏

Session 10B: Ransomware

Authors, Creators & Presenters: Christian van Sloun (RWTH Aachen University), Vincent Woeste (RWTH Aachen University), Konrad Wolsing (RWTH Aachen University & Fraunhofer FKIE), Jan Pennekamp (RWTH Aachen University), Klaus Wehrle (RWTH Aachen University)
PAPER
Detecting Ransomware Despite I/O Overhead: A Practical Multi-Staged Approach
Ransomware attacks have become one of the most widely feared cyber attacks for businesses and home users. Since attacks are evolving and use advanced phishing campaigns and zero-day exploits, everyone is at risk, ranging from novice users to experts. As a result, much research has focused on preventing and detecting ransomware attacks, with real-time monitoring of I/O activity being the most prominent approach for detection. These approaches have in common that they inject code into the execution of the operating system’s I/O stack, a more and more optimized system. However, they seemingly do not consider the impact the integration of such mechanisms would have on system performance or only consider slow storage mediums, such as rotational hard disk drives. This paper analyzes the impact of monitoring different features of relevant I/O operations for Windows and Linux. We find that even simple features, such as the entropy of a buffer, can increase execution time by 350% and reduce SSD performance by up to 75%. To combat this degradation, we propose adjusting the number of monitored features based on a process’s behavior in real-time. To this end, we design and implement a multi-staged IDS that can adjust overhead by moving a process between stages that monitor different numbers of features. By moving seemingly benign processes to stages with fewer features and less overhead while moving suspicious processes to stages with more features to confirm the suspicion, the average time a system requires to perform I/O operations can be reduced drastically. We evaluate the effectiveness of our design by combining actual I/O behavior from a public dataset with the measurements we gathered for each I/O operation and found that a multi-staged design can reduce the overhead to I/O operations by an order of magnitude while maintaining similar detection accuracy of traditional single-staged approaches. As a result, real-time behavior monitoring for ransomware detection becomes feasible despite its inherent overhead impacts.
ABOUT NDSS
The Network and Distributed System Security Symposium (NDSS) fosters information exchange among researchers and practitioners of network and distributed system security. The target audience includes those interested in practical aspects of network and distributed system security, with a focus on actual system design and implementation. A major goal is to encourage and enable the Internet community to apply, deploy, and advance the state of available security technologies.

Our thanks to the Network and Distributed System Security (NDSS) Symposium for publishing their Creators, Authors and Presenter’s superb NDSS Symposium 2025 Conference content on the Organizations’ YouTube Channel.

Permalink

*** This is a Security Bloggers Network syndicated blog from Infosecurity.US authored by Marc Handelman. Read the original post at: https://www.youtube-nocookie.com/embed/CMJoSHl5zdA?si=yAQC1lzdpEAmVvN6


文章来源: https://securityboulevard.com/2026/01/ndss-2025-detecting-ransomware-despite-i-o-overhead-a-practical-multi-staged-approach/
如有侵权请联系:admin#unsafe.sh