Ransom ware Attacks on Financial Institutions: A Review of the Literature on Cybersecurity Risks and Countermeasures
DOI:
https://doi.org/10.47709/ijmdsa.v1i2.2198Keywords:
Keywords Ransom ware, banks and credit unions, cyber risks, double/triple extortion, Ransom ware as a service, cloud, data security, network segmentation, threat identification and detection.Abstract
Ransom ware threats have become a new and real threat to financial institutions because they present risks to data integrity, business continuity and consumers’ trust. The current review focuses on the evolution of Ransom ware, such as double and triple extortion, Ransom ware as a service, attacks on the cloud services and targeted financial institutions. Banks therefore are experiencing additional pressures as cyber criminals morph their tactics to target weaknesses in both original legacy and new-age or remote work structures and artificial intelligence. To counter these, the most effective approach involves a number of tiered defense inclusions that includes back up of the data, network separation, and patching and general employee education. Threat monitoring especially at an early stage as well as a solid endpoint security solution is necessary, in addition to a clear-cut Incident Response Plan so as to contain the attack consequences. As far as Ransom ware is concerned more focus should be placed on the latest trends and financial institutions should not stick to traditional threats and should embrace new technologies and advanced disaster recovery solutions. Through exercising a proactive approach towards cybersecurity assessment, financial institutions can build up their defenses to protect their significant assets against growing cybersecurity threats, and maintain operational continuity to run a business.
References
Mohammad Mehdi Ahmadian and Hamid Reza Shahriari. 2016. 2entFOX: A framework for high survivable ransomwares detection. In 2016 13th International Iranian Society of Cryptology Conference on Information Security and Cryptology (ISCISC’16). IEEE, 79–84.
Mohammad Mehdi Ahmadian, Hamid Reza Shahriari, and Seyed Mohammad Ghaffarian. 2015. Connection-monitor and connection-breaker: A novel approach for prevention and detection of high survivable ransomwares. In 2015 12th International Iranian Society of Cryptology Conference on Information Security and Cryptology (ISCISC’15). IEEE, 79–84
Yahye Abukar Ahmed, Bar?? Koçer, and Bander Ali Saleh Al-rimy. 2020. Automated analysis approach for the detection of high survivable ransomware. KSII Transactions on Internet and Information Systems (TIIS) 14, 5 (2020), 2236–2257.
Yahye Abukar Ahmed, Bar?? Koçer, Shamsul Huda, Bander Ali Saleh Al-rimy, and Mohammad Mehedi Hassan. 2020. A system call refinement-based enhanced Minimum Redundancy Maximum Relevance method for ransomware early detection. Journal of Network and Computer Applications (2020), 102753.
Jinwoo Ahn, Donggyu Park, Chang-Gyu Lee, Donghyun Min, Junghee Lee, Sungyong Park, Qian Chen, and Youngjae Kim. 2019. KEY-SSD: Access-control drive to protect files from ransomware attacks. https://arxiv.org/abs/1904.05012.
Muna Al-Hawawreh, Frank den Hartog, and Elena Sitnikova. 2019. Targeted ransomware: A new cyber threat to edge system of brownfield industrial Internet of Things. IEEE Internet of Things Journal 6, 4 (2019), 7137–7151.
Bander Ali Saleh Al-rimy, Mohd Aiziani Maarof, Mamoun Alazab, Fawaz Alsolami, Syed Zainudeen Mohd Shaid, Fuad A. Ghaleb, Tawfik Al-Hadhrami, and Abdullah Marish Ali. 2020. A pseudo feedback-based annotated TF-IDF technique for dynamic crypto-ransomware pre-encryption boundary delineation and features extraction. IEEE Access 8 (2020), 140586–140598.
Bander Ali Saleh Al-rimy, Mohd Aizaini Maarof, Mamoun Alazab, Syed Zainudeen Mohd Shaid, Fuad A. Ghaleb, Abdulmohsen Almalawi, Abdullah Marish Ali, and Tawfik Al-Hadhrami. 2020. Redundancy coefficient gradual upweighting-based mutual information feature selection technique for crypto-ransomware early detection. Future Generation Computer Systems (2020).
Bander Ali Saleh Al-rimy, Mohd Aizaini Maarof, Yuli Adam Prasetyo, Syed Zainudeen Mohd Shaid, and Asmawi Fadillah Mohd Ariffin. 2018. Zero-day aware decision fusion-based model for crypto-ransomware early detection. International Journal of Integrated Engineering 10, 6 (2018). ACM Computing Surveys, Vol. 54, No. 9, Article 197. Publication date: October 2021. 197:30 T. McIntosh et al.
Bander Ali Saleh Al-rimy, Mohd Aizaini Maarof, and Syed Zainudeen Mohd Shaid. 2019. Crypto-ransomware early detection model using novel incremental bagging with enhanced semi-random subspace selection. Future Generation Computer Systems 101 (2019), 476–491.
Manaar Alam, Sarani Bhattacharya, Swastika Dutta, Sayan Sinha, Debdeep Mukhopadhyay, and Anupam Chattopadhyay. 2019. RATAFIA: Ransomware analysis using time and frequency informed autoencoders. In 2019 IEEE International Symposium on Hardware Oriented Security and Trust (HOST’19). IEEE Computer Society, 218–227.
Ahmad O. Almashhadani, Mustafa Kaiiali, Sakir Sezer, and Philip O’Kane. 2019. A multi-classifier network-based crypto ransomware detection system: A case study of Locky ransomware. IEEE Access 7 (2019), 47053–47067.
Samah Alsoghyer and Iman Almomani. 2019. Ransomware detection system for android applications. Electronics 8, 8 (2019), 868.
Samah Alsoghyer and Iman Almomani. 2020. on the effectiveness of application permissions for android ransomware detection. In 2020 6th Conference on Data Science and Machine Learning Applications (CDMA’20). IEEE, 94–99
Abdulrahman Alzahrani, Hani Alshahrani, Ali Alshehri, and Huirong Fu. 2019. An intelligent behavior-based ransomware detection system for android platform. In 2019 1st IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications (TPS-ISA’19). IEEE, 28–35.
Abdulrahman Alzahrani, Ali Alshehri, Hani Alshahrani, Raed Alharthi, Huirong Fu, Anyi Liu, and Ye Zhu. 2018. RanDroid: Structural similarity approach for detecting ransomware applications in android platform. In 2018 IEEE International Conference on Electro/Information Technology (EIT’18). IEEE, 0892–0897.
Or Ami, Yuval Elovici, and Danny Hendler. 2018. Ransomware prevention using application authentication-based file access control. In Proceedings of the 33rd Annual ACM Symposium on Applied Computing. 1610–1619
Nicoló Andronio, Stefano Zanero, and Federico Maggi. 2015. Heldroid: Dissecting and detecting mobile ransomware. In International Symposium on Recent Advances in Intrusion Detection. Springer, 382–404.
Amir Atapour-Abarghouei, Stephen Bonner, and Andrew Stephen McGough. 2019. A King’s ransom for encryption: Ransomware classification using augmented one-shot learning and bayesian approximation. In 2019 IEEE International Conference on Big Data (Big Data’19). IEEE, 1601–1606.
Md. Ahsan Ayub, Andrea Continella, and Ambareen Siraj. 2020. An I/O request packet (IRP) driven effective ransomware detection scheme using artificial neural network. In 2020 IEEE 21st International Conference on Information Reuse and Integration for Data Science (IRI’20). IEEE Computer Society, 319–324.
Seong Il Bae, Gyu Bin Lee, and Eul Gyu Im. 2019. Ransomware detection using machine learning algorithms. Concurrency and Computation: Practice and Experience (2019), e5422.
SungHa Baek, Youngdon Jung, Aziz Mohaisen, Sungjin Lee, and DaeHun Nyang. 2018. SSD-insider: Internal defense of solid-state drive against ransomware with perfect data recovery. In 2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS’18). IEEE, 875–884.
Pranshu Bajpai and Richard Enbody. 2020. Attacking key management in ransomware. IT Professional 22, 2 (2020), 21–27.
Pranshu Bajpai and Richard Enbody. 2020. An empirical study of key generation in cryptographic ransomware. In 2020 International Conference on Cyber Security and Protection of Digital Services (Cyber Security’20). IEEE, 1–8
Pranshu Bajpai, Aditya K. Sood, and Richard Enbody. 2018. A key-management-based taxonomy for ransomware. In 2018 APWG Symposium on Electronic Crime Research (eCrime’18). IEEE, 1–12.
Abubakar Bello and Alana Maurushat. 2020. Technical and behavioural training and awareness solutions for mitigating ransomware attacks. In Computer Science On-line Conference. Springer, 164–176.
Eduardo Berrueta, Daniel Morato, Eduardo Magaña, and Mikel Izal. 2019. A survey on detection techniques for cryptographic ransomware. IEEE Access 7 (2019), 144925–144944.
Riccardo Bortolameotti, Thijs van Ede, Marco Caselli, Maarten H. Everts, Pieter Hartel, Rick Hofstede, Willem Jonker, and Andreas Peter. 2017. DECANTeR: DEteCtion of anomalous outbound HTTP TRaffic by passive application fingerprinting. In Proceedings of the 33rd Annual Computer Security Applications Conference. ACM, 373–386.
Marcus Botacin, Fabricio Ceschin, Ruimin Sun, Daniela Oliveira, and André Grégio. 2021. Challenges and pitfalls in malware research. Computers & Security 106 (2021), 102287.
Ross Brewer. 2016. Ransomware attacks: Detection, prevention and cure. Network Security 2016, 9 (2016), 5–9.
Calvin Brierley, Jamie Pont, Budi Arief, David J. Barnes, and Julio Hernandez-Castro. 2020. PaperW8: An IoT bricking ransomware proof of concept. In Proceedings of the 15th International Conference on Availability, Reliability and Security. 1–10.
Krzysztof Cabaj, Marcin Gregorczyk, and Wojciech Mazurczyk. 2018. Software-defined networking-based crypto ransomware detection using HTTP traffic characteristics. Computers & Electrical Engineering 66 (2018), 353–368.
Edward Cartwright, Julio Hernandez Castro, and Anna Cartwright. 2019. To pay or not: Game theoretic models of ransomware. Journal of Cybersecurity 5, 1 (2019), tyz009.
Jason Castiglione and Dusko Pavlovic. 2019. Dynamic distributed secure storage against ransomware. IEEE Transactions on Computational Social Systems (2019). ACM Computing Surveys, Vol. 54, No. 9, Article 197. Publication date: October 2021. Ransomware Mitigation in the Modern Era 197:31
Jing Chen, Chiheng Wang, Ziming Zhao, Kai Chen, Ruiying Du, and Gail-Joon Ahn. 2017. Uncovering the face of android ransomware: Characterization and real-time detection. IEEE Transactions on Information Forensics and Security 13, 5 (2017), 1286–1300.
Qian Chen and Robert A. Bridges. 2017. Automated behavioral analysis of malware: A case study of wannacry ransomware. In 2017 16th IEEE International Conference on Machine Learning and Applications (ICMLA’17). IEEE, 454–460.
Qian Chen, Sheikh Rabiul Islam, Henry Haswell, and Robert A. Bridges. 2019. Automated ransomware behavior analysis: Pattern extraction and early detection. In International Conference on Science of Cyber Security. Springer, 199–214
Christopher J. W. Chew and Vimal Kumar. 2019. Behaviour based ransomware detection. Proceedings of 34th International Conference on Computers and Their Applications 58 (2019), 127–136
Aniello Cimitile, Francesco Mercaldo, Vittoria Nardone, Antonella Santone, and Corrado Aaron Visaggio. 2018. Talos: No more ransomware victims with formal methods. International Journal of Information Security 17, 6 (2018), 719–738.
Aviad Cohen and Nir Nissim. 2018. Trusted detection of ransomware in a private cloud using machine learning methods leveraging meta-features from volatile memory. Expert Systems with Applications 102 (2018), 158–178.
Shagufta Mehnaz, Anand Mudgerikar, and Elisa Bertino. 2018. RWGuard: A real-time detection system against cryptographic ransomware. In International Symposium on Research in Attacks, Intrusions, and Defenses. Springer, 114–136.
Per Håkon Meland, Yara Fareed Fahmy Bayoumy, and Guttorm Sindre. 2020. The Ransomware-as-a-Service economy within the darknet. Computers & Security (2020), 101762
Francesco Mercaldo, Vittoria Nardone, Antonella Santone, and Corrado Aaron Visaggio. 2016. Ransomware steals your phone. Formal methods rescue it. In International Conference on Formal Techniques for Distributed Objects, Components, and Systems. Springer, 212–221.
Donghyun Min, Donggyu Park, Jinwoo Ahn, Ryan Walker, Junghee Lee, Sungyong Park, and Youngjae Kim. 2018. Amoeba: An autonomous backup and recovery SSD for ransomware attack defense. IEEE Computer Architecture Letters 17, 2 (2018), 245–248.
Jaimin Modi, Issa Traore, Asem Ghaleb, Karim Ganame, and Sherif Ahmed. 2019. Detecting ransomware in encrypted web traffic. In International Symposium on Foundations and Practice of Security. Springer, 345–353.
Chris Moore. 2016. Detecting ransomware with honeypot techniques. In 2016 Cybersecurity and Cyberforensics Conference (CCC’16). IEEE, 77–81
Daniel Morato, Eduardo Berrueta, Eduardo Magaña, and Mikel Izal. 2018. Ransomware early detection by the analysis of file sharing traffic. Journal of Network and Computer Applications 124 (2018), 14–32.
Andreas Moser, Christopher Kruegel, and Engin Kirda. 2007. Limits of static analysis for malware detection. In 23rd Annual Computer Security Applications Conference (ACSAC’07). IEEE, 421–430.
Ori Or-Meir, Nir Nissim, Yuval Elovici, and Lior Rokach. 2019. Dynamic malware analysis in the modern era—A state of the art survey. ACM Computing Surveys (CSUR) 52, 5 (2019), 1–48.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2022 Alexandara Harry

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.










