Abstract
Ransomware poses a growing threat to critical infrastructure, where successful attacks can disrupt operational technology (OT) and industrial control systems (ICS) with significant public safety consequences. However, attributing ransomware incidents to specific threat actors remains challenging due to ransomware-as-a-service ecosystems, actor rebranding, and the obfuscation of traditional indicators of compromise. This paper presents Semantic Shields, an NLP-driven attribution framework that leverages BERT-generated semantic embeddings and DBSCAN clustering to profile ransomware actors through the linguistic characteristics of ransom notes. Using a dataset of 295 ransom notes from 189 distinct threat groups, the framework achieved an 87.2% true positive clustering rate and identified multiple previously undocumented relationships between ostensibly distinct ransomware groups. These findings demonstrate that natural language artifacts provide valuable attribution signals and highlight the potential of NLP-based profiling as a force multiplier for critical infrastructure defense and cyber threat intelligence.
DOI
https://doi.org/10.5038/2378-0789.9.1.1154
Recommended Citation
Trowbridge, Henry; Zalcberg, Ian; Schley, Ryan; Yagemann, Carter; Phan, Natasha; Maduposu, Srikar; and Buck, Vimal
(2026)
"Semantic Shields: Automating Critical Infrastructure Defense via NLP-Driven Ransomware Profiling,"
Military Cyber Affairs: Vol. 9
:
Iss.
1
, Article 5.
https://doi.org/10.5038/2378-0789.9.1.1154
Available at:
https://digitalcommons.usf.edu/mca/vol9/iss1/5
Included in
Computer and Systems Architecture Commons, Cybersecurity Commons, Databases and Information Systems Commons, Digital Communications and Networking Commons, Information Security Commons, OS and Networks Commons, Systems Architecture Commons