Malware authors leverage strong cryptographic primitives to hold user files as a hostage in their own devices until a ransom is paid. Indeed, victims not protected against ransomware are forced to pay the ransom or lose the files if ignoring the extortion. Devices are by no means immune from ransomware attacks. The reality is that there is a limited study on how to protect end-user devices against ransomware while there is hardly any protection available. Ransomware uses legiti- mate operating system processes that even state-of-the-art and advanced anti-malware products are ineffective against them. The results of our static and dynamic analysis illustrate that a local file system plays a critical role in the operation of all ransomware engines. Therefore, this study investigates the correlation existed between the file system opera- tions to identify metrics such as the absolute occurrence frequency of a system file to identify a ransomware attack from within the kernel. We employ business process mining techniques to analyze collected log files from samples of seven recent live ransomware families and use the Naive discovery algorithm to study the absolute occurrence frequency of system files. The findings are visualized by state charts and sequence diagrams. Finally, the study identifies eight common system files that ransomware calls on in order to encrypt a victim’s files on their device.
Book chapter
Using Process Mining to Identify File System Metrics Impacted by Ransomware Execution
Mobile, Secure, and Programmable Networking, pp.57-71
International Conference on Mobile, Secure and Programmable Networking, 6th (Online, 28-Oct-2020 - 29-Oct-2020)
Lecture Notes in Computer Science, 12605, Springer
2021
Abstract
Details
- Title
- Using Process Mining to Identify File System Metrics Impacted by Ransomware Execution
- Authors
- Arash Mahboubi (Author) - Charles Sturt UniversityKeyvan Ansari (Author) - University of the Sunshine Coast, Queensland, School of Science, Technology and EngineeringSeyit Camtepe (Author) - Commonwealth Scientific and Industrial Research Organisation
- Contributors
- Samia Bouzefrane (Editor) - Centre d'Etudes et De Recherche en Informatique et CommunicationsMaryline Laurent (Editor) - Télécom ParisSelma Boumerdassi (Editor) - Centre d'Etudes et De Recherche en Informatique et CommunicationsEric Renault (Editor) - ESIEE Paris
- Publication details
- Mobile, Secure, and Programmable Networking, pp.57-71
- Conference details
- International Conference on Mobile, Secure and Programmable Networking, 6th (Online, 28-Oct-2020 - 29-Oct-2020)
- Series
- Lecture Notes in Computer Science; 12605
- Publisher
- Springer
- DOI
- 10.1007/978-3-030-67550-9_5; 10.1007/978-3-030-67550-9
- ISSN
- 1611-3349
- ISBN
- 9783030675509
- Organisation Unit
- School of Science, Technology and Engineering; University of the Sunshine Coast, Queensland
- Language
- English
- Record Identifier
- 99496007302621
- Output Type
- Book chapter
Metrics
61 Record Views