T Dargahi
A cyber-kill-chain based taxonomy of crypto-ransomware features
Dargahi, T; Dehghantanha, A; Nikkhah Bahrami, P; Conti, M; Bianchi, G; Benedetto, L
Authors
A Dehghantanha
P Nikkhah Bahrami
M Conti
G Bianchi
L Benedetto
Abstract
In spite of being just a few years old, ransomware is quickly becoming a serious threat to our digital infrastructures, data and services. Majority of ransomware families are requesting for a ransom payment to restore a custodian access or decrypt data which were encrypted by the ransomware earlier. Although the ransomware attack strategy seems to be simple, security specialists ranked ransomware as a sophisticated attack vector with many variations and families. Wide range of features which are available in different families and versions of ransomware further complicates their detection and analysis. Though the existing body of research provides significant discussions about ransomware details and capabilities, the all research body is fragmented. Therefore, a ransomware feature taxonomy would advance cyber defenders’ understanding of associated risks of ransomware. In this paper we provide, to the best of our knowledge, the first scientific taxonomy of ransomware features, aligned with Lockheed Martin Cyber Kill Chain (CKC) model. CKC is a well-established model in industry that describes stages of cyber intrusion attempts. To ease the challenge of applying our taxonomy in real world, we also provide the corresponding ransomware defence taxonomy aligned with Courses of Action matrix (an intelligence-driven defence model). We believe that this research study is of high value for the cyber security research community, as it provides the researchers with a means of assessing the vulnerabilities and attack vectors towards the intended victims.
Journal Article Type | Article |
---|---|
Acceptance Date | Jul 6, 2019 |
Online Publication Date | Aug 7, 2019 |
Publication Date | Dec 1, 2019 |
Deposit Date | Jul 15, 2019 |
Publicly Available Date | Sep 4, 2019 |
Journal | Journal of Computer Virology and Hacking Techniques |
Print ISSN | 2274-2042 |
Electronic ISSN | 2263-8733 |
Publisher | Springer Verlag |
Volume | 15 |
Pages | 277-305 |
DOI | https://doi.org/10.1007/s11416-019-00338-7 |
Publisher URL | https://doi.org/10.1007/s11416-019-00338-7 |
Related Public URLs | https://link.springer.com/journal/11416 |
Files
Dargahi2019_Article_ACyber-Kill-ChainBasedTaxonomy.pdf
(903 Kb)
PDF
Licence
http://creativecommons.org/licenses/by/4.0/
Publisher Licence URL
http://creativecommons.org/licenses/by/4.0/