DIMAQS detects ransomware in MySQL databases via runtime query sequence monitoring and colored Petri net pattern matching, reporting zero false positives/negatives and under 5% overhead.
6E.g., for Prolog databases the ransom message insertion and table dele- tion could be mapped to the assert and the retractall commands
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.CR 1years
2019 1verdicts
UNVERDICTED 1representative citing papers
citing papers explorer
-
Hands Off my Database: Ransomware Detection in Databases through Dynamic Analysis of Query Sequences
DIMAQS detects ransomware in MySQL databases via runtime query sequence monitoring and colored Petri net pattern matching, reporting zero false positives/negatives and under 5% overhead.