Skip to main navigation Skip to search Skip to main content

The rise of ransomware: Forensic analysis for windows based ransomware attacks

  • Çankiri Karatekin University

Research output: Contribution to journalArticlepeer-review

57 Citations (Scopus)

Abstract

While information technologies grow and propagate worldwide, malwares have modified and risen their efficiency towards information system. Recently, the attackers have started to use ransom software (ransomware) as an effective method of cyberattack because of their profitability. Ransomware infiltrate victim systems in various ways, usually encrypt files in the system, and demand a ransom to allow user access to the encrypted files again. Although security mechanisms such as firewalls, anti-virus programs, and automated analysis programs have been developed to combat this threat, these mechanisms have little success and fail to protect the valuable assets stored in local or cloud storage resources. In this study, an effective detection and analysis method against ransomware was proposed, and the proposed method was discussed in detail with a case study. As a result of the study, potential information about the attacker were found to be accessible through characteristic behavior analysis of the onion ransomware, which was analyzed in accordance with the proposed method. This paper also presents an insight to the ransomware threat and provides a basic review of the methods and techniques used in the detection and analysis of ransomware attacks.

Original languageEnglish
Article number116198
JournalExpert Systems with Applications
Volume190
DOIs
Publication statusPublished - 15 Mar 2022

Keywords

  • Analysis techniques
  • Cybersecurity
  • Digital forensic
  • Malware attacks
  • Onion ransomware
  • Ransomware detection

Fingerprint

Dive into the research topics of 'The rise of ransomware: Forensic analysis for windows based ransomware attacks'. Together they form a unique fingerprint.

Cite this