Title: Internet Forensic Platform for Tracking the Money Flow of Financially-Motivated Malware

Number of Project:700326


Abstract


The Internet has become a key piece of any business activity. Criminal activity is not an exception. Some crimes previous to the Internet, such as thefts and scams, have found in the Internet the perfect tool for developing their activities. The Internet allows criminals hiding their real identity and the possibility to purchase specific tools for stealing sensitive data with a very low investment. The overall objective of RAMSES is to design and develop a holistic, intelligent, scalable and modular platform for Law Enforcement Agencies (LEAs) to facilitate digital Forensic Investigations. The system will extract, analyse, link and interpret information extracted from Internet related with financially-motivated malware. Customers, developers and malware victims will be included in order to obtain a better understanding of how and where malware is spread and to get to the source of the threat. To achieve these ambitious objectives, this project will rely on disruptive Big Data technologies to firstly extract and storage, and secondly look for patterns of fraudulent behaviour in enormous amounts of unstructured and structured data. We will focus on 2 case studies: Ransomware and Banking Trojans. In order to this, RAMSES brings together the latest technologies to develop an intelligent software platform, combining scraping of public and deep web, detecting manipulation and steganalysis for images and videos, tracking malware payments, extraction and analysis of malware samples and Big Data analysis and visualizations tools. Validation pilots will take place in three different EU countries (Portugal, Belgium and Spain) being the first a mono-LEA pilot in each site and the second a collaborative investigation pilot between several LEAs. Commercial potential will be validated during the project supported by a feasibility study to assess determinants for the adoption of the platform and appropriate business models.


Partners


Project Card


Acronym RAMSES
Number of Project 700326
Title Internet Forensic Platform for Tracking the Money Flow of Financially-Motivated Malware
Financing European Commission, Horizon 2020 - Research and Innovation Framework Program
Program H2020: Societal Challenges
Subprogram Societal Challenges: Secure societies - Protecting freedom and security of Europe and its citizens
Code Call H2020-FCT-2015, Innovation Action
Type of Action H2020-FCT-2015
Number of Partners 11
UCM Budget 722.542,99 €
Total Budget 3.532.000 €
Start Date 01/09/2016
End Date 30/11/2019
Main Researcher (UCM) Luis Javier García Villalba