2023
Autores
Cardoso, WR; Silva, JM; Ribeiro, AdRL;
Publicação
SSRN Electronic Journal
Abstract
2023
Autores
Esteves, T; Pereira, B; Oliveira, RP; Marco, J; Paulo, J;
Publicação
2023 42ND INTERNATIONAL SYMPOSIUM ON RELIABLE DISTRIBUTED SYSTEMS, SRDS 2023
Abstract
Cryptographic ransomware attacks are constantly evolving by obfuscating their distinctive features (e.g., I/O patterns) to bypass detection mechanisms and to run unnoticed at infected servers. Thus, efficiently exploring the I/O behavior of ransomware families is crucial so that security analysts and engineers can better understand these and, with such knowledge, enhance existing detection methods. In this paper, we propose CRIBA, an open-source framework that simplifies the exploration, analysis, and comparison of I/O patterns for Linux cryptographic ransomware. Our solution combines the collection of comprehensive information about system calls issued by ransomware samples, with a customizable and automated analysis and visualization pipeline, including tailored correlation algorithms and visualizations. Our study, including 5 Linux ransomware families, shows that CRIBA provides comprehensive insights about the I/O patterns of these attacks while aiding in exploring common and differentiating traits across families.
2013
Autores
Silva, JMC; Carvalho, P; Lima, SR;
Publicação
2013 Proceedings IEEE INFOCOM Workshops, Turin, Italy, April 14-19, 2013
Abstract
2013
Autores
Silva, JMC; Carvalho, P; Lima, SR;
Publicação
Proceedings of the IEEE INFOCOM 2013, Turin, Italy, April 14-19, 2013
Abstract
2016
Autores
Silva, JMC;
Publicação
Abstract
2024
Autores
Silva, JM; Ribeiro, D; Ramos, LFM; Fonte, V;
Publicação
PROCEEDINGS OF THE 57TH ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES
Abstract
The availability of public services through online platforms has improved the coverage and efficiency of essential services provided to citizens worldwide. These services also promote transparency and foster citizen participation in government processes. However, the increased online presence also exposes sensitive data exchanged between citizens and service providers to a wider range of security threats. Therefore, ensuring the security and trustworthiness of online services is crucial to Electronic Government (EGOV) initiatives' success. Hence, this work assesses the security posture of online platforms hosted in 3068 governmental domain names, across all UN Member States, in three dimensions: support for secure communication protocols; the trustworthiness of their digital certificate chains; and services' exposure to known vulnerabilities. The results indicate that despite its rapid development, the public sector still falls short in adopting international standards and best security practices in services and infrastructure management. This reality poses significant risks to citizens and services across all regions and income levels.
The access to the final selection minute is only available to applicants.
Please check the confirmation e-mail of your application to obtain the access code.