Analyzing WannaCry Ransomware Considering the Weapons and Exploits

Analyzing WannaCry Ransomware Considering the Weapons and Exploits
复制标题

考虑武器和漏洞分析 WannaCry 勒索软件

DOI:
10.23919/icact.2019.8702049
复制
发表时间:
2019
期刊:
2019 21st International Conference on Advanced Communication Technology (ICACT)
影响因子:
--
通讯作者:
R. Tso
R. Tso
中科院分区:
--
文献类型:
--
作者:
Da;Shou;R. Tso

文献摘要

被引文献

相似文献

随着勒索软件越来越受欢迎,它的创造者正在利用我们的恐惧来为自己谋利。勒索软件攻击的快速扩散表明勒索软件即服务(RaaS)和黑客武器集成的趋势日益明显。本文介绍了对臭名昭著的WannaCry勒索软件的分析,这是2017年传播最广、最具破坏性的恶意软件之一。本文讨论了勒索软件攻击的剖析,以了解WannaCry的多阶段执行,包括部署、安装、销毁和命令与控制。WannaCry的执行链包括几个黑客武器组件。WannaCry不仅将二进制文件嵌入资源部分以进行多阶段执行,还实现了强大的加密算法和密钥结构。对每个组件的逆向工程分析,沿着对WannaCry漏洞的网络分析,提供了对WannaCry内部设计的深入了解。这项研究的观察有助于最近的安全系统和未来的防御战略。
As ransomware has increased in popularity, its creators are using our fears to their advantage. The rapid proliferation of ransomware attacks indicates the growing tendency of ransomware-as-a-service (RaaS) and the integration of hacking weapons. This paper presents the analysis of the infamous WannaCry ransomware, which is one of the most propagated and damaging malware in 2017. The anatomy of ransomware attacks is discussed to understand the multi-phased execution of WannaCry, including the deployment, installation, destruction, and command-and-control. The chain of WannaCry’s execution comprises several hacking weapon components. WannaCry not only embeds the binary in the resource section for multi-phased execution, but also implements a strong encrypting algorithm and a key structure. A reverse engineering analysis of each component, along with the network analysis of WannaCry’s exploits offers an insight into the inner design of WannaCry. The observations of this research contribute to recent security systems and future defense strategies.