Ransomware: Anti-virus unable to detect it
ieeexplore.ieee.org
Ransomware: Anti-virus unable to detect it
1–7 of 7 posts
Re: Ransomware: Anti-virus unable to detect it
#2Re: Ransomware: Anti-virus unable to detect it
#3Interesting. You still need to download the ransomware file encryption program, which is something users aren't likely to have, and would quickly be detected everywhere once a few people report it. Normal compression programs have limits and wouldn't continue working after the user reboots etc.
Things like this are why popular operating systems are increasingly diverting control from the user to their vendor. And frankly I think it's impossible for those vendors to win the arms race TFA refers to.
Re: Ransomware: Anti-virus unable to detect it
#4Interesting. You still need to download the ransomware file encryption program, which is something users aren't likely to have, and would quickly be detected everywhere once a few people report it. Normal compression programs have limits and wouldn't continue working after the user reboots etc.
Re: Ransomware: Anti-virus unable to detect it
#5Re: Ransomware: Anti-virus unable to detect it
#6Interesting. You still need to download the ransomware file encryption program, which is something users aren't likely to have, and would quickly be detected everywhere once a few people report it. Normal compression programs have limits and wouldn't continue working after the user reboots etc.
Windows includes a full disk encryption system and a file encryption system. All you need to do is steal the key and remove it from the user.
I'd argue the easier part is the encryption, the harder part is the ransom delivery and file decryption automation.
Re: Ransomware: Anti-virus unable to detect it
#7Earlier quoted context omitted.
Windows includes a full disk encryption system and a file encryption system. All you need to do is steal the key and remove it from the user.
The ransomware part requires you to have some way of informing the user of the situation, and give them a way to pay the ransom and communicate. I'd argue the easier part is the encryption, the harder part is the ransom delivery and file decryption automation.