DOI: 10.17760/d20289366
|View full text |Cite
|
Sign up to set email alerts
|

Techniques and solutions for addressing ransomware attacks

Abstract: Ransomware is a form of extortion-based attack that locks the victim's digital resources and requests money to release them. Although the concept of ransomware is not new (i.e., such attacks date back at least as far as the 1980s), this type of malware has recently experienced a resurgence in popularity. In fact, over the last few years, a number of high-prole ransomware attacks were reported. Very recently, WannaCry ransomware infected thousands of vulnerable machines around the world, and substantially disru… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
5
0

Publication Types

Select...
3
2

Relationship

0
5

Authors

Journals

citations
Cited by 5 publications
(5 citation statements)
references
References 27 publications
(41 reference statements)
0
5
0
Order By: Relevance
“…In the second approach, which uses dynamic analysis, one method was to capture all the processes performed by the ransomware in a sandbox. One of the most notable actions of crypto-ransomware was the encryption operation, which generated a high repetition of file system activities that can be tracked by the monitoring I/O operation [16][17][18][19].…”
Section: Literature Reviewmentioning
confidence: 99%
“…In the second approach, which uses dynamic analysis, one method was to capture all the processes performed by the ransomware in a sandbox. One of the most notable actions of crypto-ransomware was the encryption operation, which generated a high repetition of file system activities that can be tracked by the monitoring I/O operation [16][17][18][19].…”
Section: Literature Reviewmentioning
confidence: 99%
“…These includes Eternal Blue, default admin password on web server, and vulnerabilities in restful web service, Modbus serial and TCP, objective C program that speaks NI-PSP and custom VI that interacts with a python script. Eternal Blue: [15,16] This is an exploit that focuses on Microsoft Windows and used for the wannacry ransomware attack in 2017. EternalBlue [17] is vulnerability in server message block (SMB) protocol.…”
Section: Vulnerability Assessment In Wadimentioning
confidence: 99%
“…An investigation of common characteristics of ransomware attacks was done by Kharraz [8] to detail its interaction with the file system. A monitoring tool to capture input/output (I/O) requests was developed to describe how malicious process interacts with file systems.…”
Section: Monitoring Ransomwarementioning
confidence: 99%