%0 Conference Proceedings %T Ransomware Steals Your Phone. Formal Methods Rescue It %+ University of Sannio [Benevento] %A Mercaldo, Francesco %A Nardone, Vittoria %A Santone, Antonella %A Visaggio, Corrado, Aaron %< avec comité de lecture %( Lecture Notes in Computer Science %B 36th International Conference on Formal Techniques for Distributed Objects, Components, and Systems (FORTE) %C Heraklion, Greece %Y Elvira Albert %Y Ivan Lanese %3 Formal Techniques for Distributed Objects, Components, and Systems %V LNCS-9688 %P 212-221 %8 2016-06-06 %D 2016 %R 10.1007/978-3-319-39570-8_14 %K Malware %K Android %K Security %K Formal methods %K Temporal logic %Z Computer Science [cs] %Z Computer Science [cs]/Networking and Internet Architecture [cs.NI]Conference papers %X Ransomware is a recent type of malware which makes inaccessible the files or the device of the victim. The only way to unlock the infected device or to have the keys for decrypting the files is to pay a ransom to the attacker. Commercial solutions for removing ransomware and restoring the infected devices and files are ineffective, since this malware uses a very robust form of asymmetric cryptography and erases shadow copies and recovery points of the operating system. Literature does not count many solutions for effectively detecting and blocking ransomware and, at the best knowledge of the authors, formal methods were never applied to identify ransomware. In this paper we propose a methodology based on formal methods that is able to detect the ransomware and to identify in the malware’s code the instructions that implement the characteristic instructions of the ransomware. The results of the experimentation are strongly encouraging and suggest that the proposed methodology could be the right way to follow for developing commercial solutions that could successful intercept the ransomware and blocking the infections it provokes. %G English %Z TC 6 %Z WG 6.1 %2 https://inria.hal.science/hal-01432919/document %2 https://inria.hal.science/hal-01432919/file/426757_1_En_14_Chapter.pdf %L hal-01432919 %U https://inria.hal.science/hal-01432919 %~ IFIP-LNCS %~ IFIP %~ IFIP-TC %~ IFIP-WG %~ IFIP-TC6 %~ IFIP-WG6-1 %~ IFIP-FORTE %~ IFIP-LNCS-9688