Ransomware Modeling Based on a Process Mining Approach

Autor: Ebrahim Mahdipour, Ali Aghamohammadpour, Iman Attarzadeh
Jazyk: angličtina
Rok vydání: 2022
Předmět:
Zdroj: International Journal of Information and Communication Technology Research, Vol 14, Iss 3, Pp 27-36 (2022)
Druh dokumentu: article
ISSN: 2251-6107
2783-4425
Popis: Ransomware attacks are taking advantage of the ongoing coronavirus pandemics and attacking the vulnerable systems in the health sector. Modeling ransomware attacks help to identify and simulate attacks against security environments, using likely adversary techniques. Process Mining (PM) is a field of study that focuses on analyzing process logs linked with the execution of the processes of a system to acquire insight into the variety of characteristics of how the functions behave. This paper presents a PM conformance-based approach to determining ransomware processes. First, frequent ransomware techniques were identified using state-of-the-art MITRE ATT&CK. Then, a model was developed to gather ransomware techniques using a process-based approach. The PM-based Prom tool is used to check the conformance of malware processes alongside the presented model to illustrate its efficiency. The model can identify chain processes associated with ransom-related behaviors. In this study, the presented model was evaluated using thirty common malwares in the healthcare industry. The approach demonstrates that this model could successfully classify ninety percent of malware instances as ransomware and non-ransomware. Finally, guidelines for future research are provided. We believe the proposed method will uncover behavioral models that will enable us to hunt ransomware threats.
Databáze: Directory of Open Access Journals