A4 Article in conference proceedings
Refining Cyber Situation Awareness with Honeypots in Case of a Ransomware Attack (2024)


Ihanus, J., Kokkonen, T., & Hämäläinen, T. (2024). Refining Cyber Situation Awareness with Honeypots in Case of a Ransomware Attack. In Á. Rocha, H. Adeli, G. Dzemyda, F. Moreira, & A. Poniszewska-Marańda (Eds.), WorldCIST 2024 : Good Practices and New Perspectives in Information Systems and Technologies (985, pp. 92-101). Springer. Lecture Notes in Networks and Systems. https://doi.org/10.1007/978-3-031-60215-3_10


JYU authors or editors


Publication details

All authors or editorsIhanus, Jouni; Kokkonen, Tero; Hämäläinen, Timo

Parent publicationWorldCIST 2024 : Good Practices and New Perspectives in Information Systems and Technologies

Parent publication editorsRocha, Álvaro; Adeli, Hojjat; Dzemyda, Gintautas; Moreira, Fernando; Poniszewska-Marańda, Aneta

Place and date of conferenceLodz, Poland26.-28.3.2024

ISBN978-3-031-60214-6

eISBN978-3-031-60215-3

Journal or seriesLecture Notes in Networks and Systems

ISSN2367-3370

eISSN2367-3389

Publication year2024

Volume985

Pages range92-101

Number of pages in the book228

PublisherSpringer

Place of PublicationCham

Publication countrySwitzerland

Publication languageEnglish

DOIhttps://doi.org/10.1007/978-3-031-60215-3_10

Publication open accessNot open

Publication channel open access


Abstract

The cyber threat landscape is vast and unstable. One of the top threats in the present moment is ransomware, which is constantly spreading in prevalence. To protect organisations’ cyber operating environment, ability to perceive elements relating to this threat is crucial. At the same time, many security controls face challenges in terms of fidelity of the security events. In this paper, honeypot technology is studied to support situation awareness in case of a ransomware attack. Especially detection capabilities of the honeypots are considered from the perspective of technical characteristic of ransomware. As a conclusion, we propose a construction model for enhancing cyber situation awareness using honeypots during various stages of a ransomware attack. Additionally, the analysed results are explained with identified future research topics.


Keywordscyber securitysafety and securityextortion


Contributing organizations


Ministry reportingYes

Preliminary JUFO rating1


Last updated on 2024-13-05 at 11:00