A Review and Analysis of Ransomware Using Memory Forensics and Its Tools

6Citations
Citations of this article
21Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Cybercrimes reached its peak in 2017, a year marked by extraordinary attacks including multi-million dollar theft. New malware and ransomware with the exponential growth of 64% have laid their impact in the cyber world and left them with no choice except to pay the ransom. On an average, 2 lakh samples of new malware are captured per day in the last year and it is estimated that cybercrime will cost over $2 Trillion by the end of 2019, according to Juniper research. To combat and identify the attacks, digital forensics plays a crucial role in cyber investigations. In particular, memory forensics helps by unhiding the tons of hidden secret information. In memory forensics, crucial facts are stored, retrieved, and presented as a robust proof which can be accepted even in the courtroom. This paper conducts intensive survey on importance of memory forensics and its tools. Also, practical implementation is done on memory dumps collected from WannaCry ransomware affected computer. In-depth analysis is carried out by means of tracing injected dynamic link library (DLLs), process hollowing and reverse engineering. The findings and the open challenges are also presented.

Cite

CITATION STYLE

APA

Paul Joseph, D., & Norman, J. (2020). A Review and Analysis of Ransomware Using Memory Forensics and Its Tools. In Smart Innovation, Systems and Technologies (Vol. 159, pp. 505–514). Springer. https://doi.org/10.1007/978-981-13-9282-5_48

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free