Bruteware: A Novel Family of Cryptoviral Attacks
摘要
We introduce a novel family of cryptoviral attacks designed to disrupt a system for a period of time determined by the attacker. This allows the attacker to impose a specific cost on the target organization or individual. We also unveil two practical cryptographic schemes that can be used to mount such attacks. The proposed schemes exploit the key generation and signing capabilities of the Trusted Platform Module (TPM) to create machine-bound computationally hard problems. These problems are constructed using time-based and memory-hard cryptographic primitives. Victims are then forced to allocate resources to solve them in order to recover their data. By analyzing detection and prevention techniques, this paper also provides guidance on defensive strategies to thwart the presented attacks.