Investigation of Modern Ransomware Key Generation Methods: A Review
Marah A. Aboud, K. Mariyappn · 2021
For years and the world of cyber is suffering from the most pernicious malware infection known as Ransomware which sat on top of the costliest malware attacks. Ransomware is considered to be a malicious software that attacks individuals as well as organizations for monetary purposes, it utilizes different types of encryption ways to encrypt important and sensitive files of the victims, extorting them to pay a ransom in order to decrypt the infected files. The heart action of the ransomware is encrypting the files of the victim with an encryption key that will make the victim unable to get the original files unless he has the decryption key, which won't happen unless he pays the ransom to the attacker. As the core function of the ransomware to encrypt the victim's files, it will use keys, taking into consideration the cryptosystems that the ransomware uses in its attack. Without a strong, secure, and hard to retrieve encryption keys, the ransomware will be a mere flimsy attack [1] leaving by that the attacker without getting their desired ransom from the victim. In this review paper we will discuss the ransomware encryption keys research area by going through the previous work of the researchers who focused their study on the ransomware encryption keys, from the point of how the ransomware authors get their keys, where they generate them, how they manage those keys in order to keep them safe and away from the victim.