Study of built-in information protection tools of Unix systems on the example of malware infection

DOI: 10.21293/1818-0442-2023-26-4-29-34

Download article in PDF format

JATS xml

Abstract: This article provides a comparative analysis of the built-in information protection tools of the Unix family operating systems using the example of malware infection of the operating system. The study involved open-source operating systems – Debian, and domestic operating systems – Alt Linux, RedOS, Astra Linux Special Edition. A ransomware virus was used as a malicious software. The presented results demonstrate the greatest ability of the Astra Linux operating system to resist malware infection.

Keywords: information security, information protection, malicious software, virus, ransomware, operating system, information protection tool

For citation:
Nikroshkin I. V., Medvedev M. A., Ognev I. A., Krasnikov A. D. Study of built-in information protection tools of Unix systems on the example of malware infection. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki, 2023, vol. 26, no. 4, pp. 29–34. DOI: 10.21293/1818-0442-2023-26-4-29-34

Authors and copyright holders:

  • Nikroshkin I. V. , Novosibirsk State Technical University (Novosibirsk, Russia)
  • Medvedev M. A. , Novosibirsk State Technical University (Novosibirsk, Russia)
  • Ognev I. A. , Novosibirsk State Technical University (Novosibirsk, Russia)
  • Krasnikov A. D. , Novosibirsk State Technical University (Novosibirsk, Russia)

  • 1. Maniriho P. API-MalDetect: Automated malware detection framework for windows based on API calls and deep learning techniques / P. Maniriho, A.N. Mahmood, M.J.M. Chowdhury // Journal of Network and Computer Applications. Amsterdam: Elsevier Ltd, 2023, pp. 1–18.
  • 2. Jing C. Ensemble dynamic behavior detection method for adversarial malware / C. Jing, Y. Wu, C. Cui // Future Generation Computer Systems, 2022, no. 130, pp. 193–206.
  • 3. Maniriho P. A study on malicious software behavior analysis and detection techniques: Taxonomy, current trends and challenges / P. Maniriho, A.N. Mahmood, M.J.M. Chowdhury // Future Generation Computer Systems, 2022, no. 130, pp. 1–18.
  • 4. Labutin N.G. [Preventing ransomware from penetrating corporate information systems] // Current trends in the development of science and technology. Belgorod: Limited Liability Company «Agency for Advanced Scientific Research», 2017, pp. 113–115 (in Russ.)
  • 5. Baizdrenko E.A. [Information Threats to Small Businesses: Ransomware] // Topical Issues of Accounting and Management in the Information Economy. Sevastopol: OOO «Ribest», 2018, pp. 270–274 (in Russ.)
  • 6. Putivlskaya I.Y. [Market analysis of ransomware viruses] / I.Y. Putivlskaya, A.O. Tkach // Science and Education: Domestic and Foreign Experience. Belgorod: OOO GiK, 2018, pp. 37–41 (in Russ.)
  • 7. Teplovodskikh A.D. [Aspects of protection against ransomware] / A.D. Teplovodskikh, S.S. Zotov // Alley of Science, 2017, no. 12, pp. 367–371 (in Russ.)
  • 8. Dolmatov M.P. [Ransomware viruses] / M.P. Dolmatov, K.A. Yarmosh, V.L. Sklyaruk // Modern Problems of Radio Electronics and Telecommunications, 2018, no. 1, 209 p. (in Russ.)
  • 9. Begovic K. Cryptographic ransomware encryption detection: Survey / K. Begovic, A. Al-Ali, Q. Malluhi // Computers & Security, 2023, no. 132, pp. 1–16.
  • 10. Berrueta E. Survey on Detection Techniques for Cryptographic Ransomware / E. Berrueta, D. Morato, E. Magana, M.A. Izal // IEEE Access, 2016, no. 7, pp. 1–21.
  • 11. Su D. Detecting Android locker-ransomware on Chinese social networks / D. Su, J. Liu, X. Wang, W. Wang // IEEE Access. 2017. pp. 20381–20393. Available at: https://www.researchgate.net/publication/329769980_Detecting_Android_Locker-Ransomware_on_Chinese_Social_Networks (Accessed: October 12, 2023).
  • 12. Murali R. Evolving malware variants as antigens for antivirus systems / R. Murali, P. Thangavel, C. Sh. Velayutham // Expert Systems with Applications, 2023, no. 226, pp. 1–15.
  • 13. Dwan B. The computer virus – From there to here: An historical perspective // Computer Fraud & Security, 2000, no. 12, pp. 13–16.
  • 14. Mawgoud A.A. A malware obfuscation AI technique to evade antivirus detection in counter forensic domain Enabling AI applications in data science / A.A. Mawgoud, H.M. Rady, B.S. Tawfik // Springer, 2021, pp. 597–615. Available at: https://www.researchgate.net/publication/344349230_A_Malware_Obfuscation_AI_Technique_to_Evade_Antivirus_Detection_in_Counter_Forensic_Domain (Accessed: October 12, 2023)
  • 15. The 2023 Global Ransomware Report. Available at: https://www.fortinet.com/content/dam/fortinet/assets/reports/report-2023-ransomware-global-research.pdf (Accessed: September 08, 2023).
  • 16. 2023 Mid-year cyber security report: report reveals 48 ransomware groups have breached over 2,200 victims. Available at: https://research.checkpoint.com/2023/2023-mid-year-cyber-security-report-report-reveals-48-ransomware-groups-have-breached-over-2200-victims/ (Accessed: September 08, 2023).
  • 17. Analyst Report: Techniques, Tactics, and Procedures (TTPs) of Ransomware Groups (in Russ.). Available at: https://go.kaspersky.com/rs/802-IJN-240/images/Report_Common%20TTPs%20of%20modern%20ransomware.pdf (Accessed: September 08, 2023).
  • 18. Cybersecurity threatscape: Q1 2023 (in Russ.). Available at: https://www.ptsecurity.com/ww-en/analytics/cybersecurity-threatscape-2023-q1/ (Accessed: September 08, 2023).
  • 19. Protecting your business against ransomware attacks? Explaining the motivations of entrepreneurs to take future protective measures against cybercrimes using an extended protection motivation theory model / L. Bekkers, S. van 't Hoff-de Goede, E. Misana-ter Huurne, Y. van Houten, R. Spithoven, E.R. Leukfeldt // Computers & Security, 2023, no. 127, pp. 1–12.
  • 20. E. Johns Cyber Security Breaches Survey 2021: Statistical Release. 1 ed. London: Department for Digital, Culture, Media and Sport, 2021, 66 p.
  • 21. Rohn E. Explaining small business InfoSec posture using social theories / E. Rohn, G. Sabari, G. Leshem // Information and Computer Security, 2016, no. 24, vol. 5, pp. 434–556.
  • 22. Osborn E. Risk and the small-scale cyber security decision making dialogue – a UK case study / E. Osborn, A. Simpson // Computer Journal, 2018, no. 61, vol. 4, pp. 472–495.
  • 23. R. Van der Kleij, R. Leukfeldt Cyber resilient behavior: integrating human behavioral models and resilience engineering capabilities into cyber security // International Conference on Applied Human Factors and Ergonomics, 2019, pp. 16–27. Available at: https://www.researchgate.net/publication/333645550_Cyber_Resilient_Behavior_Integrating_Human_Behavioral_Models_and_Resilience_Engineering_Capabilities_into_Cyber_Security (Accessed: October 12, 2023).
  • 24. Vashishtha L.K. An Ensemble approach for advance malware memory analysis using Image classification techniques / L.K. Vashishtha, K. Chatterjee, S.S. Rout // Journal of Information Security and Applications, 2023, no. 77, pp. 1–14.
  • 25. Bozkir A.S. Utilization and comparision of convolutional neural networks in malware recognition / A.S. Bozkir, A.O. Cankaya, M. Aydos // 27th Signal Processing and Communications Applications Conference, 2019, pp. 1–4.
  • 26. MaleVis dataset home page Available at: https://web.cs.hacettepe.edu.tr/~selman/malevis/ (Accessed: October 12, 2023).
  • 27. A forensic analysis of android malware-how is malware written and how it could be detected? / K. Allix, Q. Jérome, T.F. Bissyandé, J. Klein, R. State, Y. Le Traon // IEEE 38th Annual Computer Software and Applications Conference, 2014, pp. 384–393.
  • 28. Rathnayaka C. An efficient approach for advanced malware analysis using memory forensic technique / C. Rathnayaka, A. Jamdagni // IEEE Trustcom/BigDataSE/ICESS, 2017, pp. 1145–1150.
  • 29. Volatile memory analysis using the MinHash method for efficient and secured detection of malware in private cloud / N. Nissim, O. Lahav, A. Cohen, Y. Elovici, L. Rokach // Computers & Security, 2019, no. 87, pp. 1–20.
Editorial office address

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 701-582

  journal@tusur.ru

 

Viktor N. Maslennikov

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 51-21-21 / 51-43-02

Subscription for updates