English

SAFARI: a Scalable Air-gapped Framework for Automated Ransomware Investigation

Cryptography and Security 2025-04-11 v1

Abstract

Ransomware poses a significant threat to individuals and organisations, compelling tools to investigate its behaviour and the effectiveness of mitigations. To answer this need, we present SAFARI, an open-source framework designed for safe and efficient ransomware analysis. SAFARI's design emphasises scalability, air-gapped security, and automation, democratising access to safe ransomware investigation tools and fostering collaborative efforts. SAFARI leverages virtualisation, Infrastructure-as-Code, and OS-agnostic task automation to create isolated environments for controlled ransomware execution and analysis. The framework enables researchers to profile ransomware behaviour and evaluate mitigation strategies through automated, reproducible experiments. We demonstrate SAFARI's capabilities by building a proof-of-concept implementation and using it to run two case studies. The first analyses five renowned ransomware strains (including WannaCry and LockBit) to identify their encryption patterns and file targeting strategies. The second evaluates Ranflood, a contrast tool which we use against three dangerous strains. Our results provide insights into ransomware behaviour and the effectiveness of countermeasures, showcasing SAFARI's potential to advance ransomware research and defence development.

Keywords

Cite

@article{arxiv.2504.07868,
  title  = {SAFARI: a Scalable Air-gapped Framework for Automated Ransomware Investigation},
  author = {Tommaso Compagnucci and Franco Callegati and Saverio Giallorenzo and Andrea Melis and Simone Melloni and Alessandro Vannini},
  journal= {arXiv preprint arXiv:2504.07868},
  year   = {2025}
}

Comments

Accepted at IFIP SEC 2025