Research on a knowledge-powered cross-domain investigation of cyber-extortion operators사이버 강탈 운영자를 분석하는 지식 기반 교차 도메인 수사에 관한 연구

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 173
  • Download : 0
Fueled through the protections afforded by anonymous payment systems such as Bitcoin, cyberextortionhas emerged as a lucrative cyber-criminal business model. Globally, schemes such as ransomware,wreak havoc on organizations, individuals, and even governments, with little or no help fromlaw enforcement to combat these crimes. Unfortunately, despite the high visibility of these crimes andthe billions of dollars that are produced, little is known about the underlying flow and dissemination ofthe extorted currency once paid by the victims. In this paper, we describe a cross-domain investigationframework to analyze the links among crimeware operators and their extortion campaigns. We highlightthe utility of the system through case studies of multiple cybercrime syndicates, beginning with Clop,a recent ransomware campaign. Our system, eXpos´e was able to successfully characterize 3rd-partyentities that the operator(s) of Clop have dealt with. This is done by mining Bitcoin transactions andfusing this information with other transactions captured within an entity-graph knowledge base that isconstructed by our system. Using eXpos´e, we present an analysis that shows that the Clop operator(s)were involved in multiple extortion campaigns, and by grouping scam-related addresses eXpos´e reveals adistribution of funds managed by these operators that is currently at more than 11K BTC (approximately96.7 Million U.S. dollars at the current exchange rate in November 2019). We also present case-studiesthat reveal close inter-connections to entities from other cyber-criminal operations, including the Necursbotnet, scam-based extortion campaigns and The Shadow Brokers.
Advisors
Shin, Seungwonresearcher신승원researcher
Description
한국과학기술원 :전기및전자공학부,
Publisher
한국과학기술원
Issue Date
2020
Identifier
325007
Language
eng
Description

학위논문(석사) - 한국과학기술원 : 전기및전자공학부, 2020.2,[iv, 29 p. :]

Keywords

cyber investigation▼acyber crime▼aransomware▼abitcoin▼aknowledge base; 사이버 수사▼a사이버 범죄▼a랜섬웨어▼a비트코인▼a지식 기반

URI
http://hdl.handle.net/10203/284716
Link
http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=911325&flag=dissertation
Appears in Collection
EE-Theses_Master(석사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0