Abstract
Real-life cyber-attack incident handling requires research to improve the capability of incident response, detection, and defense against threats, including backdoor threats and ransomware attacks. This thesis addresses several of these issues, including enhancing the effectiveness and efficiency in analysis, detection, and incident response of stealth backdoor and ransomware threats and safeguarding the critical data from ransomware attacks if an immediate ransomware threat is identified.First, we propose a methodology called Target Attack Backdoor Malware Analysis and Attribution Matrix (TABMAX) to analyze this specific type of persistent module backdoor made explicitly for web servers to accelerate analysis and incident response. Second, we propose an incident response methodology matrix called BackDoor Incident Response Model (BDIRM) to handle incidents with backdoor effectively, thereby accelerating the eradication of the risk and impact of backdoor against organizations. Third, we propose RansomSOC, which is a Security Operations Center (SOC) framework specific to ransomware attack detection and response to ransomware detected earlier, reduce the impact of the ransomware infection on the target systems, and keep the critical data survival time for servers and workstations longer during a ransomware attack. Finally, we propose a ransomware incident response model to address the literature gap and illustrate the model application with a representative front-line ransomware incident response experience from one of our clients.
| Date of Award | 2022 |
|---|---|
| Original language | English |
| Awarding Institution |
|
| Supervisor | Kumaraswamy R Jogesh Muppala (Supervisor) |
Cite this
- Standard