Digital forensic readiness framework for ransomware investigation

dc.contributor.authorSingh, Avinash
dc.contributor.authorIkuesan, Adeyemi Richard
dc.contributor.authorVenter, H.S. (Hein)
dc.contributor.emailhventer@cs.up.ac.zaen_ZA
dc.date.accessioned2019-01-22T10:50:14Z
dc.date.available2019-01-22T10:50:14Z
dc.date.issued2019
dc.description.abstractOver the years there has been a significant increase in the exploitation of the security vulnerabilities of Windows operating systems, the most severe threat being malicious software (malware). Ransomware, a variant of malware which encrypts files and retains the decryption key for ransom, has recently proven to become a global digital epidemic. The current method of mitigation and propagation of malware and its variants, such as anti-viruses, have proven ineffective against most Ransomware attacks. Theoretically, Ransomware retains footprints of the attack process in the Windows Registry and the volatile memory of the infected machine. Digital Forensic Readiness (DFR) processes provide mechanisms for the pro-active collection of digital footprints. This study proposed the integration of DFR mechanisms as a process to mitigate Ransomware attacks. A detailed process model of the proposed DFR mechanism was evaluated in compliance with the ISO/IEC 27043 standard. The evaluation revealed that the proposed mechanism has the potential to harness system information prior to, and during a Ransomware attack. This information can then be used to potentially decrypt the encrypted machine. The implementation of the proposed mechanism can potentially be a major breakthrough in mitigating this global digital endemic that has plagued various organizations. Furthermore, the implementation of the DFR mechanism implies that useful decryption processes can be performed to prevent ransom payment.en_ZA
dc.description.departmentComputer Scienceen_ZA
dc.description.librarianhj2019en_ZA
dc.description.urihttp://www.springer.com/series/8197en_ZA
dc.identifier.citationSingh, A., Ikuesan, A.R. & Venter, H.S. 2019, 'Digital forensic readiness framework for ransomware investigation', Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, vol. 259, pp. 91-105.en_ZA
dc.identifier.issn1867-8211 (print)
dc.identifier.issn1867-822X (online)
dc.identifier.other10.1007/978-3-030-05487-8_5
dc.identifier.urihttp://hdl.handle.net/2263/68203
dc.language.isoenen_ZA
dc.publisherSpringeren_ZA
dc.rights© ICST Institute for Computer Sciences, Social Informatics and Telecommunications Engineering 2019. Published by Springer Nature Switzerland AG 2019. All rights reserved. The original publication is available at http://www.springer.com/series/8197.en_ZA
dc.subjectWindows forensicsen_ZA
dc.subjectDigital forensic readiness (DFR)en_ZA
dc.subjectRansom forensicsen_ZA
dc.subjectMemoryen_ZA
dc.subjectRegistryen_ZA
dc.subjectInvestigationen_ZA
dc.titleDigital forensic readiness framework for ransomware investigationen_ZA
dc.typePostprint Articleen_ZA

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Singh_Digital_2019.pdf
Size:
1.02 MB
Format:
Adobe Portable Document Format
Description:
Postprint Article

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.75 KB
Format:
Item-specific license agreed upon to submission
Description: