Understanding the Evolution of Ransomware: Paradigm Shifts in Attack Structures

Understanding the Evolution of Ransomware: Paradigm Shifts in Attack Structures
复制标题

了解勒索软件的演变:攻击结构的范式转变

DOI:
10.5815/ijcnis.2019.01.03
复制
发表时间:
2019
影响因子:
--
通讯作者:
Mumbi Chishimba
Mumbi Chishimba
中科院分区:
--
文献类型:
--
作者:
Aaron Zimba;Mumbi Chishimba

文献摘要

参考文献

被引文献

相似文献

在过去的二十年里,勒索软件的破坏性影响持续加剧,它已从仅仅是机会性攻击转变为精心策划的攻击。个人和商业组织都不断成为勒索软件的受害者,在单次攻击中,受害者被迫向网络犯罪分子支付高达100万美元,而其他一些则遭受了数亿美元的损失。显然,勒索软件是企业系统面临的一种新兴网络威胁,不容忽视。在本文中,我们探讨了勒索软件的演变以及攻击结构的相关范式转变,并聚焦于技术和经济影响。我们构建了一个适用于企业系统中常见的级联网络设计结构的攻击模型。我们将勒索软件攻击过程的安全状态建模为有限状态机的转换,其中状态转换描述了保密性、完整性和可用性的破坏。我们提出了一个勒索软件分类框架,该框架基于一种基于数据删除和文件加密攻击结构的分类算法,对给定勒索软件的毒性进行分类。从CAT1到CAT5严重程度递增的类别,对在不支付赎金要求的情况下保留数据的潜在方法的技术能力和整体有效性进行了分类。我们通过“永恒之蓝”(WannaCry)攻击用例评估了我们的建模方法,并根据这些模型提出了缓解策略和最佳实践建议。
The devasting effects of ransomware have continued to grow over the past two decades which have seen ransomware shift from just being opportunistic attacks to carefully orchestrated attacks. Individuals and business organizations alike have continued to fall prey to ransomware where victims have been forced to pay cybercriminals even up to $1 million in a single attack whilst others have incurred losses in hundreds of millions of dollars. Clearly, ransomware is an emerging cyber threat to enterprise systems that can no longer be ignored. In this paper, we address the evolution of the ransomware and the associated paradigm shifts in attack structures narrowing down to the technical and economic impacts. We formulate an attack model applicable to cascaded network design structures common in enterprise systems. We model the security state of the ransomware attack process as transitions of a finite state machine where state transitions depict breaches of confidentiality, integrity, and availability. We propose a ransomware categorization framework that classifies the virulence of a given ransomware based on a proposed classification algorithm that is based on data deletion and file encryption attack structures. The categories that increase in severity from CAT1 to CAT5 classify the technical prowess and the overall effectiveness of potential ways of retaining the data without paying the ransom demand. We evaluate our modeling approach with a WannaCry attack use case and suggest mitigation strategies and recommend best practices based on these models.
DOI: 10.1049/iet-net.2017.0207
发表时间: 2018-08
期刊: IET Networks
影响因子: 1.4
作者:
Philip O'Kane;S. Sezer;Domhnall Carlin
通讯作者: Philip O'Kane;S. Sezer;Domhnall Carlin