Catching ransomware on the wire before it locks the file server
ID: 937f6738-790e-540f-ade9-98efbcd9c9d2
STIX ID: report--937f6738-790e-540f-ade9-98efbcd9c9d2
Feed Name: Help Net Security
Researchers at La Trobe University propose a network-side ransomware detection framework that inspects SMB packet sizes and operation patterns (Regions of Interest) on the wire to fingerprint and flag automated mapped-drive encryption; the model (Random Committee) reached ~99.6% accuracy in tests, detected many families quickly, and leverages known IOCs (e.g., ransom note sizes), while noting limitations such as evaluation on a single testbed, challenges with SMBv3 encryption, and exclusion of manual/hands-on-keyboard attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
