First-person ( jury)
Hello everyone,
The typical characteristics of a ransomware attack is an encryption of personal information and or documents while demanding a ransom be paid in order to decrypt the files. The ransom payment is often paid in the form of cryptocurrency in order to make sure the attackers stays anonymous.
You can identify a ransom attack by the loss of use of your files. You become locked out because the attacker has encrypted your files.
Tools that can be used to detect, trace and eliminate this kind of threat include the tripwire configuration manager. This tool can give you the ability to monitor several different platforms, such as Amazon Web Services (AWS), Azure-based assets and Googling Cloud Platform from one single console.
Another tool is the honeypot. It can be used to detect attempts of unauthorized use of your system. According to us.Norton.com, a honeypot is a system that mimics likely targets of cyber attacks. It does this in order to gain information about how the cyber criminal would operate.
Lastly, an operating system command is a security vulnerability in which a command is injected into a program by an attacker which compromises the application.
The threat can be eliminated by making sure your files are backed up and stored safely. You should have an adequate cybersecurity team to monitor for sign of an attack. If this does not work , you may end up paying the ransom. But that is no guarantee that the threat will be eliminated.
Second person (tyus)
Hey class,
When you think about Ransomware, you want to consider how long it has been around. Since 1989, it has been magnified in scope and complexity. If you think about what it is, it is malware that prevents users from accessing their system it personal files. There are two types of campaigns for ransomware which are human-operated and auto-spreading. Some types of human-operated attacks would be gaining initial access, credential theft, lateral movement, and persistence. Attackers can gain access after they deploy a plethora of tools to get your credentials.
Some examples of a campaign attack would be RobbinHood ransomware, NetWalker, PonyFinal, Maze, and REvil. RobbinHood was introduced in 2019 when it infected Baltimore and Greenville city networks. The purpose is to take advantage of a vulnerable driver installed on a user’s machine. NetWalker was on the rise since the pandemic, in which its main targets were hospitals and healthcare providers. NetWalker would launch Mimikatz and steal credentials then use them to launch PsExec.
PonyFinal would be considered the tail end of human-operated ransomware campaigns. Attackers deploy bruted force attacks against systems management servers to gain initial access. Maze has been around for some time and was one of the first ransomware used to sell stolen data. Finally, REvil was one of the first ransomware to take advantage of the Pulse VPN vulnerabilities to steal credentials used to access networks.
Ransomware characteristics, attack chains and mitigations. (2020, July 8). The State of Security. https://www.tripwire.com/state-of-security/featured/ransomware-characteristics-attack-chains-recent-campaigns/
Last Completed Projects
| topic title | academic level | Writer | delivered |
|---|
