Ransomware continues to be an effective and lucrative means to extort large sums of money from organizations which depend on reliable access to data to meet their objectives. Often, the public embarrassment associated with falling victim to a ransomware attack is an effective motivator to pay and avoid the damaging headlines. The goal of this research is to improve the ability of security teams to identify ransomware samples in real-time. This type of determination has traditionally been difficult as attackers have been able to make small changes to malware to create variants which still infect systems but are not recognized by existing analysis tools. The work presented here uniquely leverages leaked source code which has been used by malicious actors to create custom ransomware variants for real ransomware campaigns. By isolating individual options for a build, we are able to determine ground truth and fingerprint its behavior using hardware-based side channel data collected by a CPU performance monitoring tool. This approach allowed us to successfully identify the Hardware Performance Counters and associated function calls which are directly correlated with specific capabilities inherent to the prolific Lockbit 3.0 ransomware. The specific function calls identified were those used to terminate Windows Defender protection and to search for shared network resources to encrypt. The methodology presented will help analysts detect ransomware samples for which there is no existing signature and narrow the scope of follow-on analysis, thus saving valuable time.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Identifying Ransomware Functions Through Microarchitectural Side-Channel Analysis

  • Connor Startzel,
  • Dane Brown,
  • T. Owens Walker,
  • Jennie E. Hill

摘要

Ransomware continues to be an effective and lucrative means to extort large sums of money from organizations which depend on reliable access to data to meet their objectives. Often, the public embarrassment associated with falling victim to a ransomware attack is an effective motivator to pay and avoid the damaging headlines. The goal of this research is to improve the ability of security teams to identify ransomware samples in real-time. This type of determination has traditionally been difficult as attackers have been able to make small changes to malware to create variants which still infect systems but are not recognized by existing analysis tools. The work presented here uniquely leverages leaked source code which has been used by malicious actors to create custom ransomware variants for real ransomware campaigns. By isolating individual options for a build, we are able to determine ground truth and fingerprint its behavior using hardware-based side channel data collected by a CPU performance monitoring tool. This approach allowed us to successfully identify the Hardware Performance Counters and associated function calls which are directly correlated with specific capabilities inherent to the prolific Lockbit 3.0 ransomware. The specific function calls identified were those used to terminate Windows Defender protection and to search for shared network resources to encrypt. The methodology presented will help analysts detect ransomware samples for which there is no existing signature and narrow the scope of follow-on analysis, thus saving valuable time.