2021Unpublished venueRequires access

Ransomware Analysis using Cyber Kill Chain

Qublai Khan Ali Mirza, Martin Brown, Oliver Halling, Louie Shand, Abu Alam

Open publisher page 14 citations

Abstract

The havoc caused by ransomware in the recent past is far greater than any other form of malware. Victims of this specific form of malware include, but not limited to; SMEs, large organizations, and government infrastructure. Most of these ransomwares exploit zero-day vulnerabilities and quite easily bypass the conventional security mechanisms, which means even the modern security mechanisms are surpassed by these weaponised pieces of code. This paper presents a thorough analysis of four different and quite lethal ransomware; Petya, Mamba, Cerber, and WannaCry. The unique and common features of these four malware were identified by implementing Cyber Kill Chain phases. The common features extracted from these ransomwares can be used to train analysts in order to identify a ransomware attack in its early stages and block any damage it can cause. Thus, providing future analysts features to identify enabling a more proactive and apt response when dealing with future malware threats.

About this research paper

What this paper is about

The havoc caused by ransomware in the recent past is far greater than any other form of malware. Victims of this specific form of malware include, but not limited to; SMEs, large organizations, and government infrastructure. Most of these ransomwares exploit zero-day vulnerabilities and quite easily bypass the conventional security mechanisms, which means even the modern security mechanisms are surpassed by these weaponised pieces of code. This paper presents a thorough analysis of four different and quite lethal ransomware; Petya, Mamba, Cerber, and WannaCry. The unique and common features of these four malware were identified by implementing Cyber Kill Chain phases. The common features extracted from these ransomwares can be used to train analysts in order to identify a ransomware attack in its early stages and block any damage it can cause. Thus, providing future analysts features to identify enabling a more proactive and apt response when dealing with future malware threats.

Why it matters

OpenAlex reports 14 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

The havoc caused by ransomware in the recent past is far greater than any other form of malware. Victims of this specific form of malware include, but not limited to; SMEs, large organizations, and government infrastructure. Most of these ransomwares exploit zero-day vulnerabilities and quite easily bypass the conventional security mechanisms, which means even the modern security mechanisms are surpassed by these weaponised pieces of code. This paper presents a thorough analysis of four different and quite lethal ransomware; Petya, Mamba, Cerber, and WannaCry. The unique and common features of these four malware were identified by implementing Cyber Kill Chain phases. The common features extracted from these ransomwares can be used to train analysts in order to identify a ransomware attack in its early stages and block any damage it can cause. Thus, providing future analysts features to identify enabling a more proactive and apt response when dealing with future malware threats.

Key concepts: Ransomware, Malware, Computer security, Cryptovirology, Exploit, Computer science, Malware analysis, Government (linguistics)

Related papers

Back to paper searchBrowse research topicsOriginal source
Ransomware Analysis using Cyber Kill Chain — Research Paper | ScholarLens