Title
Ransomware Automatic Data Acquisition Tool.
Abstract
Ransomware attacks reported to authorities face the technical difficulty of local police units in gathering information and executing proper forensic analysis. This paper proposes a forensic analysis tool that acts during the final stage of the ransomware infection cycle to provide a quick and easy option to acquire valuable information for the forensic analyst in order to facilitate the subsequent classification of ransomware. The proposed tool combines pop-up window capture showing the ransomware and through the optical character recognition techniques, obtaining the rescue message along with the payment address and value. In addition, it extracts the files generated by the ransomware and dumps the virtual memory of the system for analysis by the forensic technician. To evaluate the accuracy of the tool, experiments were conducted with different samples of ransomware on a real computer, under a controlled environment.
Year
DOI
Venue
2018
10.1109/ACCESS.2018.2868885
IEEE ACCESS
Keywords
Field
DocType
Bitcoin,crypto currency,forensic analysis,Internet,memory dump,optical character recognition,pattern recognition,ransomware
Technician,Ransomware,Computer science,Cryptography,Computer security,Virtual memory,Data acquisition,Optical character recognition,Computer network,Payment,The Internet
Journal
Volume
ISSN
Citations 
6
2169-3536
0
PageRank 
References 
Authors
0.34
0
5