首页|期刊导航|物联网学报|AI增强勒索病毒:工作机理与防御方法

AI增强勒索病毒:工作机理与防御方法OA

AI-assisted ransomware:operating principles and defense methods

中文摘要英文摘要

随着数字经济的迅猛发展,网络安全风险日益加剧.据相关报道,勒索病毒已成为网络空间最具破坏性的威胁之一.值得警惕的是,网络黑客正在不断尝试利用先进的人工智能(AI,artificial intelligence)技术培育新型勒索病毒,使得病毒更智能、更具隐蔽性和破坏力.因此,如何全面审视 AI 对网络安全带来的新影响,深入揭示其工作原理并研究和构建有效的防御方法迫在眉睫.目前,尚未有文献系统全面地总结并分析 AI 增强勒索病毒危害的原理和影响.为此,首先,对勒索病毒进行了分类;接着,剖析了勒索病毒的攻击流程;然后,结合最新研究进展,深入阐述了 AI 增强勒索病毒的工作机理;最后,从预防、预测、检测、识别及缓解 5 个方面,系统归纳了基于 AI 的勒索病毒应对措施,并分析了 AI 增强勒索病毒的发展趋势与未来可能研究方向,旨在为网络安全领域的从业者提供有价值的参考与启示.

With the rapid development of the digital economy,cybersecurity risks have become increasingly severe.Ac-cording to relevant reports,ransomware has emerged as one of the most destructive threats in cyberspace.Alarmingly,cy-bercriminals are continuously leveraging advanced artificial intelligence(AI)technologies to develop next-generation ran-somware,making these attacks more intelligent,covert,and damaging.Consequently,it is imperative to comprehensively examine the new impact of AI on cybersecurity,deeply reveal the operating principles of AI-assisted ransomware,and build effective defense strategies.At present,there is a lack of systematic and comprehensive literature analyzing the oper-ating principles and impacts of AI-assisted ransomware.To address this gap,firstly,ransomware was categorized.Subse-quently,the attack process of ransomware was analyzed.And then,combined with the latest research progress,the operat-ing principles of AI-assisted ransomware were elaborated in depth.Finally,response measures to operating principles ran-somware were systematically summarized from five key perspectives:prevention,prediction,detection,identification and mitigation.Additionally,the development trends and potential future research directions of AI-assisted ransomware were analyzed,aiming to provide valuable insights and guidance for practitioners in the field of cybersecurity.

李业深;董鹏;朱贺;郭孝天;尹晨旭;熊轲

北京交通大学高速铁路网络管理教育部工程研究中心,北京 100044||北京交通大学计算机科学与技术学院,北京 100044中铁信(北京)网络技术研究院有限公司,北京 100044中铁信(北京)网络技术研究院有限公司,北京 100044北京交通大学高速铁路网络管理教育部工程研究中心,北京 100044||北京交通大学计算机科学与技术学院,北京 100044北京交通大学高速铁路网络管理教育部工程研究中心,北京 100044||北京交通大学计算机科学与技术学院,北京 100044北京交通大学高速铁路网络管理教育部工程研究中心,北京 100044||北京交通大学计算机科学与技术学院,北京 100044

信息技术与安全科学

勒索病毒网络安全人工智能防御体系

ransomwarecybersecurityartificial intelligencedefense system

《物联网学报》 2026 (1)

125-138,14

国家自然科学基金资助项目(No.62071033)北京市自然科学基金昌平创新联合基金资助项目(No.L234084)中国国家铁路集团有限公司科研专项(No.L2023W001) The National Natural Science Foundation of China(No.62071033),The Changping Innovation Joint Fund of Beijing Natural Science Foundation(No.L234084),The Project of China Railway Corporation(No.L2023W001)

10.11959/j.issn.2096-3750.2026.00511

评论