2021
DOI: 10.13052/jcsm2245-1439.1013
|View full text |Cite
|
Sign up to set email alerts
|

Game Theory of Data-selling Ransomware

Abstract: We are experiencing the worst years of ransomware attacks with continuing news reports on high-profile ransomware attacks on organizations such as hospitals, schools, government agencies and private businesses. Recently a few ransomware attackers have gone beyond simply encrypting files and waiting for ransom. They threaten to release the data if the victims refuse their ransom request. In this paper, we propose a hypothetical new revenue model for the ransomware, i.e., selling the stolen data rather than publ… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1

Citation Types

0
16
1

Year Published

2021
2021
2023
2023

Publication Types

Select...
3
2
1
1

Relationship

0
7

Authors

Journals

citations
Cited by 15 publications
(28 citation statements)
references
References 18 publications
0
16
1
Order By: Relevance
“…Recent research has further explored the financial motivations and economic factors driving ransomware innovation [42]. Threat actors continuously refine tactics and tools to maximize profits, targeting victims based on perceived willingness-to-pay [3,43]. Groups are also professionalizing, with some even providing "customer service" to aid ransom payment and data recovery [31,1].…”
Section: Ransomware Evolutionmentioning
confidence: 99%
“…Recent research has further explored the financial motivations and economic factors driving ransomware innovation [42]. Threat actors continuously refine tactics and tools to maximize profits, targeting victims based on perceived willingness-to-pay [3,43]. Groups are also professionalizing, with some even providing "customer service" to aid ransom payment and data recovery [31,1].…”
Section: Ransomware Evolutionmentioning
confidence: 99%
“…Not only is phishing used to facilitate the installation of ransomware, also ransomware is increasingly used to indirectly steal credentials, which sometimes lead to more phishing [50,51]. Another way ransomware leads to phishing is in which the content of the phishing email seems more credible by addressing a recent or on going ransomware attack.…”
Section: Coordinating Ddos Phishing and Ransomware Attacksmentioning
confidence: 99%
“…A third way for ransomware to possibly lead to phishing was described by [50]. [50] studied different factors contributing to maximizing profit of a ransomware attack.…”
Section: Coordinating Ddos Phishing and Ransomware Attacksmentioning
confidence: 99%
See 1 more Smart Citation
“…Very recently, ideas from game theory have been found to be useful in the study of ransomware. While all ransomware follows the same fundamental principles, there is sufficient variety in observed phenomena to merit a variety of models, such as defence and deterrence [17]- [21], iterative negotiations [22], price discrimination [23], incentive to return encrypted data data [24], and sale of stolen data [25]. In this paper, we examine how game theory can be applied to the growing threat of targeted ransomware.…”
mentioning
confidence: 99%