The Experts below are selected from a list of 57 Experts worldwide ranked by ideXlab platform
Engin Kirda - One of the best experts on this subject based on the ideXlab platform.
-
DIMVA - Cutting the Gordian Knot: A Look Under the Hood of Ransomware Attacks
Detection of Intrusions and Malware and Vulnerability Assessment, 2015Co-Authors: Amin Kharraz, Davide Balzarotti, Leyla Bilge, William Van B. Robertson, Engin KirdaAbstract:In this paper, we present the results of a long-term study of ransomware attacks that have been observed in the wild between 2006 and 2014. We also provide a holistic view on how ransomware attacks have evolved during this period by analyzing 1,359 samples that belong to 15 different ransomware families. Our results show that, despite a continuous improvement in the encryption, deletion, and communication techniques in the main ransomware families, the number of families with sophisticated destructive capabilities remains quite small. In fact, our analysis reveals that in a large number of samples, the malware simply locks the victim's computer desktop or attempts to encrypt or delete the victim's Files using only superficial techniques.i?źOur analysis also suggests that stopping advanced ransomware attacks is not as complex as it has been previously reported. For example, we show that by monitoring abnormal File system activity, it is possible to design a practical defense system that could stop a large number of ransomware attacks, even those using sophisticated encryption capabilities. A close examination on the File system activities of multiple ransomware samples suggests that by looking at I/O requests and protecting Master File Table MFT in the NTFS File system, it is possible to detect and prevent a significant number of zero-day ransomware attacks.
-
Cutting the gordian knot: A look under the hood of ransomware attacks
Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2015Co-Authors: Amin Kharraz, Davide Balzarotti, Leyla Bilge, William Van B. Robertson, Engin KirdaAbstract:In this paper, we present the results of a long-term study of ransomware attacks that have been observed in the wild between 2006 and 2014. We also pro-vide a holistic view on how ransomware attacks have evolved during this period by analyzing 1,359 samples that belong to 15 different ransomware families. Our results show that, despite a continuous improvement in the encryption, deletion, and communication techniques in the main ransomware families, the number of families with sophisticated destructive capabilities remains quite small. In fact, our analysis reveals that in a large number of samples, the malware simply locks the victim's computer desktop or attempts to encrypt or delete the victim's Files using only superficial techniques. Our analysis also suggests that stopping ad-vanced ransomware attacks is not as complex as it has been previously reported. For example, we show that by monitoring abnormal File system activity, it is pos-sible to design a practical defense system that could stop a large number of ran-somware attacks, even those using sophisticated encryption capabilities. A close examination on the File system activities of multiple ransomware samples sug-gests that by looking at I/O requests and protecting Master File Table (MFT) in the NTFS File system, it is possible to detect and prevent a significant number of zero-day ransomware attacks.
Ecir Ugur Kucuksille - One of the best experts on this subject based on the ideXlab platform.
-
Recovering Data Using MFT Records in NTFS File System
Academic Perspective Procedia, 2018Co-Authors: Suleyman Gokhan Taskin, Ecir Ugur KucuksilleAbstract:Data storage devices use a specific structure when storing or accessing the stored data. This is called File system. Before beginning to store data in the data storage device, it must be formatted absolutely. While this data storage device is being formatted, the File system should be selected.NTFS, the most commonly used File system, keeps the Files in the disk as a list in the MFT (Master File Table) File. Even if the File is deleted, the File record in this Table will not be deleted. The physical location of the File can be found by looking at these MFT records.In this study, computer software was created on the basis of restoring the disk using a MFT File of the NTFS File system, and the result was examined.When national studies are examined, data recovery programs on the market are compared with each other. When international studies are examined, it is seen that NTFS and MFT concepts are explained but data recovery method using MFT records is not examined in detail.
-
Recovering Data Using MFT Records in NTFS File System
Academic Perspective Procedia, 2018Co-Authors: Suleyman Gokhan Taskin, Ecir Ugur KucuksilleAbstract:Data storage devices use a specific structure when storing or accessing the stored data. This is called File system. Before beginning to store data in the data storage device, it must be formatted absolutely. While this data storage device is being formatted, the File system should be selected.NTFS, the most commonly used File system, keeps the Files in the disk as a list in the MFT (Master File Table) File. Even if the File is deleted, the File record in this Table will not be deleted. The physical location of the File can be found by looking at these MFT records.In this study, computer software was created on the basis of restoring the disk using a MFT File of the NTFS File system, and the result was examined.When national studies are examined, data recovery programs on the market are compared with each other. When international studies are examined, it is seen that NTFS and MFT concepts are explained but data recovery method using MFT records is not examined in detail.
Neng-hsin Shih - One of the best experts on this subject based on the ideXlab platform.
-
Reconstructing ADS data hiding in windows NTFS: A temporal analysis
Digital Investigation, 2018Co-Authors: Yuan-pei Chen, Neng-hsin ShihAbstract:Abstract The Windows NTFS File system supports for alternate data streams (ADS) to provide compatibility with Files in the Macintosh File system. ADS can be used for hidden channels of storing and exchanging information on machines without altering their original functionality or contents. ExecuTables in ADS can be executed from the command line. It is common for attackers to hide malware in cover media (Files or folders) by ADS creation, modification or overwriting. The temporal information is significant when the computer is on. The attributes of $SI and $FN in the Master File Table (MFT) hold the following four forensically interesting EMAC-time stamps. Timestamp dynamics refers to any influence that adds, changes, obscures, contaminates, or obliterates timestamps, regardless of intent. Getting precise information about the File metadata in the MFT is important to the assessment of the scenario of the offense. The study of File metadata and ADS manipulation assists in establishing timestamp patterns and correlating activities from timestamp evidence. Some experimental processes were conducted to identify EMAC-time stamps in $SI and $FN, collect experimental observations in MFT, examine hidden channels, analyze timeline scenario, and present artifacts and non-artifacts to reconstruct the incident. This study explores the temporal analysis facing the law enforcement community and discusses the application of Forensic Toolkit (FTK) software to copy with the increasingly ADS feature in digital forensic investigations. This study also establishes some timestamp rules on ADS manipulation, enhances the performance of investigations, and helps investigators reconstruct an incident. It is beneficial for investigators to evaluate an accident if an attacker has manipulated ADS to conceal his offense.
-
Reconstructing ADS data hiding in windows NTFS: A temporal analysis
Digital Investigation, 2018Co-Authors: Da-yu Kao, Yuan-pei Chen, Neng-hsin ShihAbstract:Abstract The Windows NTFS File system supports for alternate data streams (ADS) to provide compatibility with Files in the Macintosh File system. ADS can be used for hidden channels of storing and exchanging information on machines without altering their original functionality or contents. ExecuTables in ADS can be executed from the command line. It is common for attackers to hide malware in cover media (Files or folders) by ADS creation, modification or overwriting. The temporal information is significant when the computer is on. The attributes of $SI and $FN in the Master File Table (MFT) hold the following four forensically interesting EMAC-time stamps. Timestamp dynamics refers to any influence that adds, changes, obscures, contaminates, or obliterates timestamps, regardless of intent. Getting precise information about the File metadata in the MFT is important to the assessment of the scenario of the offense. The study of File metadata and ADS manipulation assists in establishing timestamp patterns and correlating activities from timestamp evidence. Some experimental processes were conducted to identify EMAC-time stamps in $SI and $FN, collect experimental observations in MFT, examine hidden channels, analyze timeline scenario, and present artifacts and non-artifacts to reconstruct the incident. This study explores the temporal analysis facing the law enforcement community and discusses the application of Forensic Toolkit (FTK) software to copy with the increasingly ADS feature in digital forensic investigations. This study also establishes some timestamp rules on ADS manipulation, enhances the performance of investigations, and helps investigators reconstruct an incident. It is beneficial for investigators to evaluate an accident if an attacker has manipulated ADS to conceal his offense.
Amin Kharraz - One of the best experts on this subject based on the ideXlab platform.
-
DIMVA - Cutting the Gordian Knot: A Look Under the Hood of Ransomware Attacks
Detection of Intrusions and Malware and Vulnerability Assessment, 2015Co-Authors: Amin Kharraz, Davide Balzarotti, Leyla Bilge, William Van B. Robertson, Engin KirdaAbstract:In this paper, we present the results of a long-term study of ransomware attacks that have been observed in the wild between 2006 and 2014. We also provide a holistic view on how ransomware attacks have evolved during this period by analyzing 1,359 samples that belong to 15 different ransomware families. Our results show that, despite a continuous improvement in the encryption, deletion, and communication techniques in the main ransomware families, the number of families with sophisticated destructive capabilities remains quite small. In fact, our analysis reveals that in a large number of samples, the malware simply locks the victim's computer desktop or attempts to encrypt or delete the victim's Files using only superficial techniques.i?źOur analysis also suggests that stopping advanced ransomware attacks is not as complex as it has been previously reported. For example, we show that by monitoring abnormal File system activity, it is possible to design a practical defense system that could stop a large number of ransomware attacks, even those using sophisticated encryption capabilities. A close examination on the File system activities of multiple ransomware samples suggests that by looking at I/O requests and protecting Master File Table MFT in the NTFS File system, it is possible to detect and prevent a significant number of zero-day ransomware attacks.
-
Cutting the gordian knot: A look under the hood of ransomware attacks
Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2015Co-Authors: Amin Kharraz, Davide Balzarotti, Leyla Bilge, William Van B. Robertson, Engin KirdaAbstract:In this paper, we present the results of a long-term study of ransomware attacks that have been observed in the wild between 2006 and 2014. We also pro-vide a holistic view on how ransomware attacks have evolved during this period by analyzing 1,359 samples that belong to 15 different ransomware families. Our results show that, despite a continuous improvement in the encryption, deletion, and communication techniques in the main ransomware families, the number of families with sophisticated destructive capabilities remains quite small. In fact, our analysis reveals that in a large number of samples, the malware simply locks the victim's computer desktop or attempts to encrypt or delete the victim's Files using only superficial techniques. Our analysis also suggests that stopping ad-vanced ransomware attacks is not as complex as it has been previously reported. For example, we show that by monitoring abnormal File system activity, it is pos-sible to design a practical defense system that could stop a large number of ran-somware attacks, even those using sophisticated encryption capabilities. A close examination on the File system activities of multiple ransomware samples sug-gests that by looking at I/O requests and protecting Master File Table (MFT) in the NTFS File system, it is possible to detect and prevent a significant number of zero-day ransomware attacks.
Wang Shi-dong - One of the best experts on this subject based on the ideXlab platform.
-
Research on technology of data recovery in computer forensics
Journal of Chongqing University of Posts and Telecommunications, 2010Co-Authors: Wang Shi-dongAbstract:To solve data recovery problems in computer forensics,this paper proposed a new method for data recovery based on NTFS(new technology File system).By analyzing the structure of MFT(Master File Table),MFT File record,the three File attributes(attribute of standard_information,attribute of File_name,attribute of data)and the change of the attribute value in the head of the File record after File deletion,implementation of the new data recovery method was illustrated in detail,Experimental results show that the designed software in the search volume and efficiency has been improved significantly.