Memory Forensics Against Ransomware

No ratings

Presented at CyberScience2020 2020 by

Ransomware leverages the unique knowledge of cryptographic secrets, such as the encryption key,against the victim. Obtaining the decryption key removes that leverage and hence eliminates the requirement ofpaying the ransom. In this paper, we examine the effectiveness of physical memory forensics against ransomwareto recover raw symmetric and asymmetric keys and demonstrate file decryption against several real-worldransomware. We also use our own virulent ransomware that are equipped with an effective hybrid cryptosystem toexplore the limits of such memory-based side-channel attacks on ransomware. Our results indicate that cryptographickeys can be discovered during encryption in the ransomware process memory for durations long enough to facilitatecomplete data recovery.