Digital Zone: Jurnal Teknologi Informasi dan Komunikasi
Vol. 14 No. 1 (2023): Digital Zone: Jurnal Teknologi Informasi dan Komunikasi

Ransomware Attacks Threat Modeling Using Bayesian Network: Pemodelan Ancaman Serangan Ransomware Menggunakan Bayesian Network

Sulistiadi (Universitas Indonesia)
Muhammad Salman (Universitas Indonesia)



Article Info

Publish Date
27 May 2023

Abstract

Ransomware is a dangerous malware that blocks access to data through encryption, and it exploits device vulnerabilities to perform chain attacks from one system to another. This study results in modeling the threat of ransomware attacks using Bayesian Network. The structure of the model is created using device vulnerabilities that can be exploited. As the basis for calculating the probability of the model, the EPSS vulnerability score is used. The risk exposure rating is calculated through the joint probability distribution formulation based on attack scenarios. Our model shows that ransomware attacks are most likely to exploit the chain of vulnerabilities CVE-2021-26855, CVE-2021-26857, CVE-2021-27065, CVE-2021-36942, and CVE-2017-0144 which has a probability value of 0.046534. In addition, the use of the EPSS also makes the risk assessment more factual, accurate, and effective. The threat modeling method can help in identifying ransomware attacks through a chain of vulnerabilities, making risk assessment more precise.

Copyrights © 2023






Journal Info

Abbrev

dz

Publisher

Subject

Computer Science & IT Engineering

Description

Digital Zone journal publish by Fakultas Ilmu Komputer Universitas Lancang Kuning (Online ISSN 2477-3255 and Print ISSN 2086-4884) This journal publish two periode in a year on May and ...