ranDecepter: Real-time Identification and Deterrence of Ransomware Attacks
Md Sajidul Islam Sajid, Jinpeng Wei, Ehab Al-Shaer

TL;DR
ranDecepter is a real-time cyber deception system that detects ransomware, isolates it, and depletes attacker resources by feeding false information, demonstrating perfect accuracy and significant resource exhaustion in tests.
Contribution
The paper introduces ranDecepter, a novel real-time ransomware detection and deception framework that actively misleads attackers and depletes their resources, a new approach in cyber defense.
Findings
100% accuracy in ransomware identification
No false positives during evaluation
Depletes attacker resources with over 9 million entries generated
Abstract
Ransomware (RW) presents a significant and widespread threat in the digital landscape, necessitating effective countermeasures. Active cyber deception is a promising strategy to thwart RW and limiting its propagation by misleading it with false information and revealing its true behaviors. Furthermore, RW often acts as a communication conduit between attackers and defenders, allowing deception to return false data to attackers and deplete their resources. This paper introduces ranDecepter, a novel approach that combines active cyber deception with real-time analysis to enhance defenses against RW attacks. The ranDecepter identifies RW in real-time and isolates it within a deceptive environment, autonomously identifying critical elements in the RW code to create a loop mechanism. By repeatedly restarting the malware and transmitting counterfeit encryption information and secret keys to…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
