SearcharxivSearch

arXiv subjects

Aaron Zimba

Publications and source records attributed to Aaron Zimba.

4 recordsLinked to original sources

Emerging Mobile Phone-based Social Engineering Cyberattacks in the Zambian ICT Sector

The number of registered SIM cards and active mobile phone subscribers in Zambia in 2020 surpassed the population of the country. This clearly shows that mobile phones in Zambia have become part of everyday life easing not only the way people communicate but also the way people perform financial transactions owing to the integration of mobile phone systems with financial payment systems. This development has not come without a cost. Cyberattackers, using various social engineering techniques have jumped onto the bandwagon to defraud unsuspecting users. Considering the aforesaid, this paper presents a high-order analytical approach towards mobile phone-based social engineering cyberattacks (phishing, SMishing, and Vishing) in Zambia which seek to defraud benign victims. This paper presents a baseline study to reiterate the problem at hand. Furthermore, we devise an attack model and an evaluation framework and ascertain the most prevalent types of attack. We also present a logistic regression analysis in the results section to conclude the most prevalent mobile phone-based type of social engineering attack. Based on the artifacts and observed insights, we suggest recommendations to mitigate these emergent social engineering cyberattacks.

cs.CR

Liberalisation of the International Gateway and Internet Development in Zambia: The Genesis, Opportunities, Challenges, and Future Directions

Telecommunication reforms in Zambia and the subsequent liberalisation of the international gateway was perceived as one of the means of promoting social and economic growth in both the urban and rural areas of the country. The outcome of this undertaking propelled the rapid development of Internet which has evidently brought about unprecedented paradigm shifts in the use of Information and Communication Technologies (ICTs). It is indisputable that ICTs, and the Internet in particular, have revolutionalised the way we communicate today. Furthermore, the penetration of ICTs to other spheres of our daily lives is evidence enough that the impacts thereof go beyond mere communicative facets of our lives. However, many challenges arose in the implementation of telecommunications reforms. In order to achieve the status quo, government had to make strategic liberalisation policies in the telecoms sector that saw the opening up of the international communication gateways to the private sector. This is in tandem with the fact that the relationship between government (through its formulation of policies and regulations) and other stakeholders determines the ability of a country to generate and use advanced knowledge for industrial competitiveness. As such, in this paper, we present the genesis and evaluate the impacts associated with the telecommunications reforms and the subsequent liberalisation of international communication gateways, and Internet development in Zambia. We further consider the challenges this has brought about and discuss possible future directions. This is helpful in forecasting the future landscape of the ICT sector considering that the country seeks to achieve universal coverage of both Internet and communication facilities to all Zambians across the country.

cs.NI

A Ransomware Classification Framework Based on File-Deletion and File-Encryption Attack Structures

Ransomware has emerged as an infamous malware that has not escaped a lot of myths and inaccuracies from media hype. Victims are not sure whether or not to pay a ransom demand without fully understanding the lurking consequences. In this paper, we present a ransomware classification framework based on file-deletion and file-encryption attack structures that provides a deeper comprehension of potential flaws and inadequacies exhibited in ransomware. We formulate a threat and attack model representative of a typical ransomware attack process from which we derive the ransomware categorization framework based on a proposed classification algorithm. The framework classifies the virulence of a ransomware attack to entail the overall effectiveness of potential ways of recovering the attacked data without paying the ransom demand as well as the technical prowess of the underlying attack structures. Results of the categorization, in increasing severity from CAT1 through to CAT5, show that many ransomwares exhibit flaws in their implementation of encryption and deletion attack structures which make data recovery possible without paying the ransom. The most severe categories CAT4 and CAT5 are better mitigated by exploiting encryption essentials while CAT3 can be effectively mitigated via reverse engineering. CAT1 and CAT2 are not common and are easily mitigated without any decryption essentials.

cs.CR

Demystifying Cryptocurrency Mining Attacks: A Semi-supervised Learning Approach Based on Digital Forensics and Dynamic Network Characteristics

Cryptocurrencies have emerged as a new form of digital money that has not escaped the eyes of cyber-attackers. Traditionally, they have been maliciously used as a medium of exchange for proceeds of crime in the cyber dark-market by cyber-criminals. However, cyber-criminals have devised an exploitative technique of directly acquiring cryptocurrencies from benign users' CPUs without their knowledge through a process called crypto mining. The presence of crypto mining activities in a network is often an indicator of compromise of illegal usage of network resources for crypto mining purposes. Crypto mining has had a financial toll on victims such as corporate networks and individual home users. This paper addresses the detection of crypto mining attacks in a generic network environment using dynamic network characteristics. It tackles an in-depth overview of crypto mining operational details and proposes a semi-supervised machine learning approach to detection using various crypto mining features derived from complex network characteristics. The results demonstrate that the integration of semi-supervised learning with complex network theory modeling is effective at detecting crypto mining activities in a network environment. Such an approach is helpful during security mitigation by network security administrators and law enforcement agencies.

cs.CR