Isolating Key Phrases to Identify Ransomware Attackers
Abstract
Ransomware attacks are a devastatingly severe class of cyber-attacks capable of crippling an organization through disrupting operations or egregious financial demands. A number of solutions have been proposed to decrease the risk of ransomware infection or detect ransomware once a system has been infected. However, these proposed solutions do not address the root of the problem: identifying the adversary that created them. This study takes steps towards identifying an adversary by utilizing linguistic analysis of ransomware messages to ascertain the adversary’s language of origin. Our proposed method begins by using existing ransomware messages. We isolate commonly used phrases by analyzing a number of notable ransomware attacks: CryptoLocker, Locky, Petya, Ryuk, WannaCry, Cerber, GandCrab, SamSam, Bad Rabbit, and TeslaCrypt. Afterwards, we translate these phrases from English to another language and then back to English using Google Translate and calculate the Levenshtein Distance between the two English phrases. Next, we identify the languages that have a Levenshtein Distance greater than 0 for these phrases due to differences in how parts of speech are implemented in the respective languages. Finally, we analyze new ransomware messages and rank the languages from easiest to most difficult to distinguish.
Keywords: ransomware, linguistic analysis, cybersecurity
DOI: 10.54941/ahfe1002200
Cite this paper
More from this volume
- A Metric to Assist in Detecting International Phishing or Ransomware Cyberattacks
- Insider Threat: Cognitive Effects of Modern Apathy towards Privacy, Trust, and Security
- A Didactic Tool for Digital Forensics
- A Closer Look at Insider Threat Research
- Social Engineering and Human-Robot Interactions' Risks
- Information Security Awareness and Training as a Holistic Key Factor – How Can a Human Firewall Take on a Complementary Role in Information Security?
- Cyberdefense Adaptive Training Based on the Classification of Operator Cognitive State
- Exploring Human and Environmental Factors that Make Organizations Resilient to Social Engineering Attacks
- Assessing Human Factors and Cyber Attacks at the Human-Machine Interface: Threats to Safety and Pilot and Controller Performance
- Navigating through Cyber Threats, A Maritime Navigator’s Experience
- A Coherence Model to Outline Obstacles and Success Factors for Information Security from the CISO's Point of View
- Privacy Concerns about Smart Home Devices: A Comparative Analysis between Non-Users and Users


AHFE Open Access