透過您的圖書館登入
IP:18.117.196.184
  • 學位論文

勒索軟體攻擊行為與補救措施之探討

Discussion on Ransomware Attacks and Remedial Measures

指導教授 : 梁德昭

摘要


因網路的快速發展與普及化,生活周遭的服務都幾乎都朝向網路資訊服務發展,而現今勒索病毒的威脅性是日益增高,已是網路資訊安全的首要威脅,雖然市面上眾多的防毒軟體可以提供電腦基本防護,但使用者遭遇到勒索軟體攻擊時,防毒軟體可能無法在第一時間進行阻擋,電腦設備的檔案仍然會被進行加密後遭受勒索,只能無奈支付贖金或重新安裝電腦設備。 本研究為降低勒索病毒造成的損失,利用Jigsaw勒索軟體樣本和虛擬化技術,透過研究它的傳播途徑,分析其運行機制探討出可行的補救策略,運用工具將遭受勒索軟體加密檔案進行解密,幫助用戶在意外遭受勒索病毒的入侵時,仍然能夠有方式救回重要資料,受害者可無需支付贖金,便能順利地解密檔案取回使用權。

並列摘要


Due to the rapid development and popularization of the Internet, almost all the services around life are developing towards Internet information services. Nowadays, the threat of ransomware is increasing day by day, and it has become the primary threat to Internet information security. Antivirus software can provide basic computer protection, but when a user encounters a ransomware attack, the antivirus software may not be able to block it at the first time, and the files of the computer device will still be encrypted and then subjected to ransom, so they have no choice but to pay the ransom or reinstall it. Computer equipment. In order to reduce the losses caused by ransomware, this research uses Jigsaw ransomware samples and virtualization technology to explore possible remedial strategies by studying its transmission channels and analyzing its operating mechanism. When a user is accidentally invaded by a ransomware virus, there is still a way to recover important data, and the victim can successfully decrypt the file and retrieve the right to use without paying the ransom.

並列關鍵字

Ransomware Encryption Software Attack Vector

參考文獻


[1] 行政院國家資通安全會報技術服務中心,美國政府推出「對抗勒索軟體」單一入口網站,網址: https://www.nccst.nat.gov.tw/NewsRSSDetail?seq=16578,上網日期:2021年7月15日。
[2] 李志強,從勒索軟體談關鍵資訊基礎設施防護。清流雙月刊(37),頁40-47,2022年1月。
[3] 行政院國家資通安全會報技術服務中心,全球最大肉品供應商JBS遭勒索軟體攻擊,網址:https://www.nccst.nat.gov.tw/NewsRSSDetail?seq=16562,上網日期:2021年5月31日。
[4] Xin Luo (2007). Awareness Education as the Key to Ransomware Prevention. Information Systems Security, 16(4), 195-202.
[5] 維基百科,勒索軟體,網址:https://zh.wikipedia.org/wiki/勒索軟體。

延伸閱讀