Review of research on ransomware in industrial control systems
Online published: 2025-01-25
Copyright
Industrial control systems (ICS) are the nerve centers of critical national infrastructure, including petroleum, petrochemicals, intelligent manufacturing, electricity, water resources, and transportation. These systems are closely linked to people’s lives, social economy, and national security, and have increasingly become high-value targets for hacker ransomware attacks. The widespread application of ICS, the diversity of their equipment, the lack of information security considerations in early design, and their characteristics such as high availability, control timing, and long life cycles, expose ICS to significant cybersecurity risks. In recent years, ransomware attacks targeting industrial enterprises have attracted wide attention. Given the enormous threat posed by ransomware to ICS enterprises, this study investigates information and data on ransomware attacks involving ICS. First, typical cases of ransomware attacks on ICS in recent years were analyzed, followed by an in-depth examination and summary of the key technologies involved in each phase of the attack process. Then, the characteristics and shortcomings of existing ICS ransomware models were discussed, and a new ransomware model for ICS was proposed. Subsequently, defense measures against ransomware in ICS were reviewed, and finally, recommendations were provided for future research on the detection and defense of ransomware attacks targeting ICS.
DAI Hao , JIANG Bowen , SHANG Sijia , DING Yuanchuan , CUI Bohan , QU Tianheng , HU Yan , SUN Limin . Review of research on ransomware in industrial control systems[J]. Journal of Cybersecurity, 2024 , 2(5) : 17 -31 . DOI: 10.20172/j.issn.2097-3136.240502
表 1 侦察阶段的关键技术汇总Table 1 Summary of key technologies in the reconnaissance phase |
| 代表文献 | 技术 | 目标 | 手段 | 防御方法 | 主要特点 |
| Salahdine等[25] | 社会工程攻击 | 通过内部人员获取 敏感信息 | 贿赂、伪装身份、心理学 | 安全意识培训 | 简单高效,但依赖于 受害者行为 |
| Mazurczyk等[26] | 开源情报收集 | 收集公开信息 | 搜索引擎、公开的工控数据库、网络扫描 | 限制信息公开 | 实施简单,但获取的 敏感信息有限 |
| Bou-Harb等[27] | 指纹识别 | 识别系统或设备 具体细节 | 扫描网络和设备、协议分析、PLC识别 | 网络流量监控、访问控制 | 可以获取敏感信息,但容易被防御措施防范 |
| Sayakkara等[28] | 侧信道攻击 | 窃取设备运行时 泄露的信息 | 电磁泄漏、声波分析、 功耗分析 | 隔离敏感设备、屏蔽干扰 | 难以防范,但攻击难度高 |
表 2 感染阶段的关键技术汇总Table 2 Summary of key technologies in the infection phase |
| 代表文献 | 技术 | 目标 | 手段 | 防御方法 | 主要特点 |
| O'DONNELL等[29] | 恶意邮件 | 传播恶意软件病毒 | 钓鱼邮件、恶意附件 | 邮件过滤、恶意软件 扫描 | 成本低、传播广泛, 但易被拦截 |
| Zhang等[33] | 移动存储介质 | 物理接触传播 恶意软件病毒 | 恶意USB设备、Autorun功能 | 禁用Autorun功能、USB设备监控 | 可针对不联网的系统 |
| Allen等[34] | 水坑攻击 | 向特定群体传播 恶意软件病毒 | 网站劫持、定向钓鱼 | 域名过滤、网络隔离 | 针对性强 |
| CIS[35] | 恶意广告 | 传播恶意软件病毒 | 广告网络投毒、 钓鱼重定向 | 广告过滤、浏览器 安全插件 | 传播广泛,但易被拦截 |
| Ohm等[36] | 供应链攻击 | 传播恶意软件病毒、 植入后门 | 软件更新劫持、 第三方组件感染 | 供应链安全评估、 软件成分分析 | 传播广泛、隐蔽性强、攻击周期长 |
| CISA[37] | 托管服务商攻击 | 向多个客户传播 恶意软件病毒 | 远程访问滥用、 MSP后台入侵 | 多因素认证、托管 服务商审查 | 通过一个入口访问 多个客户系统 |
| Huerta等[39] | 持久化技术 | 长期控制受害系统 | 注册表植入、 安装后门程序 | 行为分析、系统 完整性监控 | 长期控制已感染系统 |
| Rudd等[40] | 隐蔽性技术 | 隐藏恶意活动 | 代码混淆、加密流量 | 流量分析、反混淆工具 | 使勒索软件活动难以 被检测出来 |
| Butt等[41] | 横向移动技术 | 扩大感染范围 | 捕获凭证、 内部协议滥用 | 网络分段、访问 权限最小化 | 深入内网、快速获取更多资源和权限 |
表 3 制造威胁阶段的关键技术汇总Table 3 Summary of key technologies in the threat generation phase |
| 代表文献 | 技术 | 目标 | 手段 | 防御方法 | 主要特点 |
| Kharraz等[43] | 屏幕锁定 | 阻止访问屏幕 | 远程桌面协议(RDP)劫持、系统服务篡改 | 强制多因素认证 | 简单直接、容易被检测出来和解除 |
| Bacani等[44] | 浏览器锁定 | 阻止使用浏览器 | JavaScript循环弹窗、插件劫持 | 安全浏览器扩展、更新和修复漏洞 | 容易实施、容易绕过 |
| Fisher等[45] | MBR锁定 | 阻止启动系统 | MBR覆写、Bootkit、Rootkit | MBR备份、安全启动、硬件保护 | 破坏性强、难以恢复 |
| Formby等[32] | 更改PLC密码 | 阻止访问PLC | 使用工业协议发起命令、写入PLC内存地址 | PLC日志监控、异常密码修改检测 | 阻止合法用户 访问PLC |
| Formby等[32] | 更改PLC的ACL配置 | 控制PLC访问权限 | 修改ACL、更改网络设备的防火墙规则 | ACL配置审核、最小权限原则 | 阻止对PLC的 网络访问 |
| Formby等[32] | 启用PLC的OEM锁 | 防止设备固件修复 | BIOS/UEFI设置修改、OEM工具滥用 | 固件更新、OEM锁启用检测 | 难以恢复、依赖 硬件支持 |
| Formby等[32] | 更改网络配置 | 干扰网络通信 | DHCP设置篡改、路由器或交换机配置修改 | 网络配置审计、PLC通信流量监控 | 影响广泛、难以被检测出来 |
| Stubbs等[46] | 对称密钥加密 | 加密数据 | AES加密、DES加密 | 数据备份、CPU占用检测、熵检测 | 简单高效、密钥易被截获 |
| Hull等[47] | 非对称密钥加密 | 加密数据 | RSA加密 | 数据备份、CPU占用检测、熵检测 | 效率低、用于解密的私钥难以被截获 |
| Akbanov等[48] | 混合加密 | 加密数据 | RSA和AES加密 算法结合 | 数据备份、CPU占用检测、熵检测 | 高效、实现复杂 |
| Formby等[32] | 指令替换加密 | 篡改PLC程序 | 语义等价指令替换 | 程序完整性检查、 代码审计 | 使PLC程序执行异常,难以恢复 |
| Formby等[32] | PLC程序加密 | 加密PLC程序 | AES加密、RAS加密 | 程序加密、 防篡改措施 | 使PLC程序彻底无法执行 |
| Govil等[49] | 逻辑炸弹 | 延时触发破坏 | 条件触发、恶意梯形 逻辑代码 | 代码审计、异常行为检测 | 高破坏性 |
| Adamov等[51] | 数据回传 | 窃取数据 | C&C服务器、加密隧道 | 数据泄露防护、网络流量监控 | 信息收集、依赖网络 |
表 4 静态检测技术和动态检测技术对比Table 4 Comparison of static detection techniques and dynamic detection techniques |
| 静态检测 | 动态检测 | ||
| 比较维度 | 检测对象 | 程序的可执行文件等静态数据 | 程序运行时的行为和活动 |
| 提取特征 | 熵特征、PE头信息、字符串等 | API调用、文件读写、日志记录等 | |
| 检测方法 | 利用统计学习和机器学习等技术 | 利用统计学习和机器学习等技术 | |
| 优点 | 检测速度快,不需要执行程序 | 检测范围广,能够发现未知和变种的勒索软件 | |
| 缺点 | 对未知或变种的勒索软件无效 | 资源消耗大,需要在沙箱等虚拟环境执行程序 | |
表 5 工控系统勒索软件检测技术和传统IT系统勒索软件检测技术的比较Table 5 Comparison of ransomware detection techniques between industrial control system and traditional IT system |
| 比较维度 | 工控系统勒索软件检测 | 传统IT系统勒索软件检测 |
| 检测目标 | 保护物理设备和工业流程的安全,防止设备控制中断 | 保障数据完整性和系统可用性,防止数据被加密和锁定 |
| 数据来源 | 控制程序代码、SCADA系统日志、现场控制设备数据 | 通用软件的可执行文件及运行时行为和活动 |
| 系统架构 | 分布式协同检测 | 集中式检测 |
| 行业特征 | 需要融合领域知识的专用检测 | 通用检测 |
| 设备特性 | 轻量级检测 | 检测技术复杂度较高 |
| 1 |
SAVAGE K,COOGAN P,LAU H. The evolution of ransomware[R]. 2015.
|
| 2 |
杭州安恒信息技术股份有限公司. 《2023全球勒索软件研究报告》:勒索攻击近倍增长背后的洞察及应对[R/OL]. [2024-08-09]. https://www.dbappsecurity.com.cn/content/details4215_22408.html.
DBAPPSecurity Co.,Ltd. “2023 Global ransomware research report”:insights and responses to the nearly doubling of ransomware attacks[R/OL]. [2024-08-09]. https://www.dbappsecurity.com.cn/content/details4215_22408.html.
|
| 3 |
Hillstone. 解读台积电事件,制造业工控安全真的不堪一击?[EB/OL]. (2018-08-17)[2024-08-09]. https://www.freebuf.com/company-information/181302.html.
Hillstone. Interpreting the TSMC incident:is industrial control security in manufacturing really vulnerable?[EB/OL]. (2018-08-17)[2024-08-09]. https://www.freebuf.com/company-information/181302.html.
|
| 4 |
WIKIPEDIA. Lockbit[EB/OL]. (2024-11-03)[2024-12-09]. https://en.wikipedia.org/wiki/Lockbit.
|
| 5 |
安天. 勒索软件 Sodinokibi 运营组织的关联分析[EB /OL]. (2019-07-08)[2024-08-09]. https://www.antiy.cn/observe_download/observe_190.pdf.
Antiy. Correlation analysis of the ransomware sodinokibi operations group[EB/OL]. (2019-07-08)[2024-08-09]. https://www.antiy.cn/observe_download/observe_190.pdf.
|
| 6 |
2021活跃勒索组织之DarkSide [EB/OL]. (2021-08-20)[2024-08-09]. https://www.freebuf.com/articles/paper/285440.html.
DarkSide:active ransomware group of 2021 [EB/OL]. (2021-08-20)[2024-08-09]. https://www.freebuf.com/articles/paper/285440.html.
|
| 7 |
2021活跃勒索组织追踪之Clop[EB/OL]. (2021-08-23)[2024-08-09]. https://www.freebuf.com/vuls/285740.html.
Tracking the active ransomware group Clop in 2021 [EB/OL]. (2021-08-23)[2024-08-09]. https://www.freebuf.com/vuls/285740.html.
|
| 8 |
HAMILL J. Dark Angels steal world’s largest-ever ransomware payment[EB/OL]. (2024-07-30) [2024-08-09]. https://www.thestack.technology/worlds-largest-ever-ransomware-payment-zscaler/.
|
| 9 |
CHAPPELL B,NEUMAN S. US says North Korea ‘directly responsible’for WannaCry ransomware attack[J]. National Public Radio,2017.
|
| 10 |
BERR J. WannaCry ransomware attack losses could reach $4 billion[J]. CBS News,2017,16.
|
| 11 |
FIORE B,HA K,HUYNH L,et al. Security analysis of ransomware:a deep dive into WannaCry and locky[C]//Proceedings of the 13th Annual Computing and Communication Workshop and Conference (CCWC 2023). Piscataway:IEEE Press,2023:285-294.
|
| 12 |
LIU Z,CHEN C,ZHANG L Y,et al. Working mechanism of eternalblue and its application in ransomworm[C]//Proceedings of the 14th International Symposium on Cyberspace Safety and Security. Berlin:Springer International Publishing,2022:178-191.
|
| 13 |
LU G H,LIU Y,CHEN Y F,et al. A comprehensive detection approach of wannacry:principles,rules and experiments[C]//Proceedings of 2020 International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery. Piscataway:IEEE Press,2020:41-49.
|
| 14 |
DA-YU K A O,HSIAO S C,RAYLIN T S O. Analyzing WannaCry ransomware considering the weapons and exploits[C]//Proceedings of the 21st International Conference on Advanced Communication Technology (ICACT 2019). Piscataway:IEEE Press,2019:1098-1107.
|
| 15 |
LEE M,MERCER W,RASCAGNERES P. Player 3 has entered the game:say hello to “WannaCry”[EB/OL]. (2017-05-12) [2024-08-09]. https://blog.talosintelligence.com/wannacry/.
|
| 16 |
CISA. Understanding ransomware threat actors:LockBit[EB/OL]. (2023-06-14) [2024-08-09]. https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a.
|
| 17 |
Avertium. LockBit 2.0 ransomware:an in-depth look at lockfile & LockBit[EB/OL]. [2024-08-09]. https://explore.avertium.com/resource/lockbit-2-0-ransomware.
|
| 18 |
Trendmicro., . Ransomware spotlight:LockBit | trend micro (SG)[EB/OL]. (2024-05-07) [2024-08-09]. https://www.trendmicro.com/vinfo/sg/security/news/ransomware-spotlight/ransomware-spotlight-lockbit.
|
| 19 |
ELIANDO E, PURNOMO Y. LockBit 2.0 ransomware: analysis of infection, persistence, prevention mechanism[J]. CogITo Smart Journal, 2022, 8 (1): 232- 243.
|
| 20 |
AKINYEMI O, SULAIMAN R, ABOSATA N. Analysis of the LockBit 3.0 and its infiltration into advanced's infrastructure crippling NHS services[J]. arXiv., 2308, 05565, 2023.
|
| 21 |
DERBYSHIRE R, GREEN B, WALT C V D, et al. Dead Man’s PLC: towards viable cyber extortion for operational technology[J]. Digital Threats: Research and Practice, 2023, 5 (3): 1- 24.
|
| 22 |
GREEN B,KROTOFIL M,ABBASI A. On the significance of process comprehension for conducting targeted ICS attacks[C]//Proceedings of 2017 Workshop on Cyber-Physical Systems Security and PrivaCy. New York:ACM Press,2017:57-67.
|
| 23 |
BERTINO E, ISLAM N. Botnets and internet of things security[J]. Computer, 2017, 50 (2): 76- 79.
|
| 24 |
MITRE. MITRE ATT&CKTM[R/OL]. https://attack.mitre.org/.
|
| 25 |
SALAHDINE F, KAABOUCH N. Social engineering attacks: a survey[J]. Future internet, 2019, 11 (4): 89.
|
| 26 |
MAZURCZYK W, CAVIGLIONE L. Cyber reconnaissance techniques[J]. Communications of the ACM, 2021, 64 (3): 86- 95.
|
| 27 |
BOU-HARB E, DEBBABI M, ASSI C. Cyber scanning: a comprehensive survey[J]. IEEE Communications Surveys & Tutorials, 2013, 16 (3): 1496- 1519.
|
| 28 |
SAYAKKARA A, LE-KHAC N A, SCANLON M. A survey of electromagnetic side-channel attacks and discussion on their case-progressing potential for digital forensics[J]. Digital Investigation, 2019, 29, 43- 54.
|
| 29 |
O’DONNELL L. ThreatList:top 5 most dangerous attachment types[EB/OL]. (2019-05-13) [2024-08-09]. https://threatpost.com/threatlist-top-5-most-dangerous-attachment-types/144635/.
|
| 30 |
ZIMBA A, WANG Z S, CHEN H S. Multi-stage crypto ransomware attacks: a new emerging cyber threat to critical infrastructure and industrial control systems[J]. ICT Express, 2018, 4 (1): 14- 18.
|
| 31 |
CIMPANU C. One of Roman Abramovich’s Companies got hit by ransomware[EB/OL]. (2020-03-05) [2024-08-09]. https://www.zdnet.com/article/one-of-roman-abramovichs-companies-got-hit-by-ransomware/.
|
| 32 |
FORMBY D,DURBHA S,BEYAH R. Out of control:ransomware for industrial control systems[C]//Proceedings of RSA Conference. 2017:8.
|
| 33 |
ZHANG Y,SUN Z,YANG L,et al. All your PLCs belong to me:ICS ransomware is realistic[C]//Proceedings of the 19th International Conference on Trust,Security and Privacy in Computing and Communications. Piscataway:IEEE Press,2020:502-509.
|
| 34 |
ALLEN J,YANG Z,LANDEN M,et al. Mnemosyne:an effective and efficient postmortem watering hole attack investigation system[C]//Proceedings of 2020 ACM SIGSAC Conference on Computer and Communications Security. New York:ACM Press,2020:787-802.
|
| 35 |
Ransomware:facts,threats,and countermeasures - CIS[EB/OL]. (2017-05-18) [2024-08-09]. https://www.cisecurity.org/blog/ransomware-facts-threats-and-countermeasures/.
|
| 36 |
OHM M,PLATE H,SYKOSCH A,et al. Backstabber’s knife collection:a review of open source software supply chain attacks[C]//Proceedings of the 17th International Conference Detection of Intrusions and Malware,and Vulnerability Assessment. Berlin:Springer,2020:23-43.
|
| 37 |
Protecting against cyber threats to managed service providers and their customers[EB/OL]. (2022-05-11) [2024-08-09]. https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-131a.
|
| 38 |
FAYI S Y A. What Petya/NotPetya ransomware is and what its remidiations are[C]//Proceedings of the 15th International Conference On Information Technology. Berlin:Springer,2018:93-100.
|
| 39 |
VILLALÓN-HUERTA A, MARCO-GISBERT H, RIPOLL-RIPOLL I. A taxonomy for threat actors’ persistence techniques[J]. Computers & Security, 2022, 121, 102855.
|
| 40 |
RUDD E M, ROZSA A, GÜNTHER M, et al. A survey of stealth malware attacks, mitigation measures, and steps toward autonomous open world solutions[J]. IEEE Communications Surveys & Tutorials, 2016, 19 (2): 1145- 1172.
|
| 41 |
BUTT U J,ABBOD M,LORS A,et al. Ransomware threat and its impact on SCADA[C]//Proceedings of the 12th International Conference On Global Security,Safety And Sustainability. Piscataway:IEEE Press,2019:205-212.
|
| 42 |
HUTCHINS E M, CLOPPERT M J, AMIN R M. Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains[J]. Leading Issues in Information Warfare & Security Research, 2011, 1 (1): 80.
|
| 43 |
KHARRAZ A,ROBERTSON W K,BALZAROTTI D,et al. Cutting the gordian knot:a look under the hood of ransomware attacks[C]//Proceedings of the 12th Detection of Intrusions and Malware,and Vulnerability Assessment(DIMVA 2015). Berlin:Springer,2015:3-24.
|
| 44 |
BACANI A,SANCHO D,YANEZA J. REVETON ransomware spreads with old tactics,new infection method[EB/OL]. (2014-12-14)[2024-08-09]. https://www.botnets.fr/wiki/REVETON_Ransomware_Spreads_with_Old_Tactics,_New_Infection_Method.
|
| 45 |
FISHER D. New seftad ransomware attacks master boot record[EB/OL]. (2010-11-30)[2024-08-02]. https://threatpost.com/new-seftad-ransomware-attacks-master-boot-record-113010/74714/.
|
| 46 |
STUBBS R. An overview of symmetric encryption and the key lifecycle[EB/OL]. (2020-03-11)[2024-08-02]. https://www.cryptomathic.com/news-events/blog/an-overview-of-symmetric-encryption-and-the-key-lifecycle.
|
| 47 |
HULL G, JOHN H, ARIEF B. Ransomware deployment methods and analysis: views from a predictive model and human responses[J]. Crime Science, 2019, 8 (1): 1- 22.
|
| 48 |
AKBANOV M, VASSILAKIS V G, LOGOTHETIS M D. WannaCry ransomware: analysis of infection, persistence, recovery prevention and propagation mechanisms[J]. Journal of Telecommunications and Information Technology, 2019, (1): 113- 124.
|
| 49 |
GOVIL N,AGRAWAL A,TIPPENHAUER N O. On ladder logic bombs in industrial control systems[C]//Proceedings of CyberICPS 2017 and SECPRE 2017. Berlin:Springer,2018:110-126.
|
| 50 |
MCLAUGHLIN S. On dynamic malware payloads aimed at programmable logic controllers[C]//Proceedings of the 6th USENIX Workshop on Hot Topics in Security (HotSec 2011). Berkeley:USENIX Association,2011.
|
| 51 |
ADAMOV A,CARLSSON A. The state of ransomware. trends and mitigation techniques[C]//Proceedings of 2017 IEEE East-West Design & Test Symposium (EWDTS). Piscataway:IEEE Press,2017:1-8.
|
| 52 |
O'KANE P, SEZER S, CARLIN D. Evolution of ransomware[J]. IET Networks, 2018, 7 (5): 321- 327.
|
| 53 |
RAJ A,NARAYAN V,MUSKAN V,et al. Modern ransomware:evolution,methodology,attack model,prevention and mitigation using multi‐tiered approach[J]. Security and Privacy,2024:e436.
|
| 54 |
KEIJZER N. Inside the world of ransomware dissecting the attack[EB/OL]. https://northwave-cybersecurity.com/threat-intel-research/inside-the-world-of-ransomware-dissecting-the-attack.
|
| 55 |
KEIJZER N. Inside the world of ransomware part 2/3:different roles within a ransomware attack[EB/OL]. https://northwave-cybersecurity.com/threat-intel-research/inside-the-world-of-ransomware-part-2-3-different-roles-within-a-ransomware-attack.
|
| 56 |
刘亦翔. [极思]以攻促防:勒索软件攻击实战演练[EB/OL](2024-01-05)[2024-08-09]. https://mp.weixin.qq.com/s/yHJhWBpMj4vd-3XNHzcrtA.
LIU Y X. [Extreme thinking] enhancing defense through offense:ransomware attack simulation [EB/OL].(2024-01-05)[2024-08-09]. https://mp.weixin.qq.com/s/yHJhWBpMj4vd-3XNHzcrtA.
|
| 57 |
ALVEE S R B,AHN B,KIM T,et al. Ransomware attack modeling and artificial intelligence-based ransomware detection for digital substations[C]//Proceedings of the 6th IEEE Workshop on the Electronic Grid (eGRID 2021). Piscataway:IEEE Press,2021:01-05.
|
| 58 |
ZHU J T, JANG-JACCARD J, SINGH A, et al. A few-shot meta-learning based siamese neural network using entropy features for ransomware classification[J]. Computers & Security, 2022, 117, 102691.
|
| 59 |
SHARMA S, KRISHNA C R, KUMAR R. RansomDroid: forensic analysis and detection of android ransomware using unsupervised machine learning technique[J]. Digital Investigation, 2021, 37, 301168.
|
| 60 |
MISHRA A K,OBAIDAT M S,BHAJPAI H,et al. Ransomware attacks detection methodology to protect IoT-enabled critical infrastructures[C]//Proceedings of 2023 IEEE Global Communications Conference. Piscataway:IEEE Press,2023:6037-6042.
|
| 61 |
HWANG J, KIM J, LEE S, et al. Two-stage ransomware detection using dynamic analysis and machine learning techniques[J]. Wireless Personal Communications, 2020, 112 (4): 2597- 2609.
|
| 62 |
ALMOUSA M,BASAVARAJU S,ANWAR M. API-based ransomware detection using machine learning-based threat detection models[C]//Proceedings of the 18th International Conference on Privacy,Security and Trust. Piscataway:IEEE Press,2021:1-7.
|
| 63 |
LEE S, JHO N, CHUNG D, et al. Rcryptect: real-time detection of cryptographic function in the user-space filesystem[J]. Computers & Security, 2022, 112, 102512.
|
| 64 |
HOMAYOUN S, DEHGHANTANHA A, AHMADZADEH M, et al. Know abnormal, find evil: frequent pattern mining for ransomware threat hunting and intelligence[J]. IEEE Transactions on Emerging Topics in Computing, 2020, 8 (2): 341- 351.
|
| 65 |
Ahmed Y A, Huda S, Al-rimy B A S, et al. A weighted minimum redundancy maximum relevance technique for ransomware early detection in industrial IoT[J]. Sustainability, 2022, 14 (3): 1231.
|
| 66 |
BASNET M,POUDYAL S,ALI M H,et al. Ransomware detection using deep learning in the SCADA system of electric vehicle charging station[C]//Proceedings of 2021 IEEE PES Innovative Smart Grid Technologies Conference-Latin America. Piscataway:IEEE Press,2021:1-5.
|
| 67 |
AL-HAWAWREH M, SITNIKOVA E, ABOUTORAB N. Asynchronous peer-to-peer federated capability-based targeted ransomware detection model for industrial IoT[J]. IEEE Access, 2021, 9, 148738- 148755.
|
| 68 |
MATHANE V, LAKSHMI P V. Predictive analysis of ransomware attacks using context-aware AI in IoT systems[J]. International Journal of Advanced Computer Science and Applications, 2021, 12 (4): 240- 244.
|
| 69 |
CELDRÁN A H, SÁNCHEZ P M S, VON DER ASSEN J, et al. Behavioral fingerprinting to detect ransomware in resource-constrained devices[J]. Computers & Security, 2023, 135, 103510.
|
/
| 〈 |
|
〉 |