A ransomware game involves a ransomware attacker \(\mathcal {A}\) and a victim \(\mathcal {V}\) deciding to cooperate or not. The victim may or may not trust the ransomware attacker to unlock files after paying the ransom to prevent data loss. Simultaneously, the attacker can strategically decide whether or not to unlock the files after receiving payment. This can be modelled as a strategic game, repeated over time. In addition, the attacker may change their mind at any point and stop the game. Likewise, the victim, at any time, might become incapable of playing by being bankrupt, or uninterested by having established recovery and resilience. We develop a novel stochastic game-theoretic model for analysing this scenario and provide equilibria for a single victim and multiple victims. We also study convergence towards equilibria from mutual experience collected by victims and the attacker and compare the equilibrium limits of the model with recommendations from real-life reported experience.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Ransom Roulette: Learning the Games Behind Cyber Extortion

  • Eckhard Pflügel,
  • Stefan Rass

摘要

A ransomware game involves a ransomware attacker \(\mathcal {A}\) and a victim \(\mathcal {V}\) deciding to cooperate or not. The victim may or may not trust the ransomware attacker to unlock files after paying the ransom to prevent data loss. Simultaneously, the attacker can strategically decide whether or not to unlock the files after receiving payment. This can be modelled as a strategic game, repeated over time. In addition, the attacker may change their mind at any point and stop the game. Likewise, the victim, at any time, might become incapable of playing by being bankrupt, or uninterested by having established recovery and resilience. We develop a novel stochastic game-theoretic model for analysing this scenario and provide equilibria for a single victim and multiple victims. We also study convergence towards equilibria from mutual experience collected by victims and the attacker and compare the equilibrium limits of the model with recommendations from real-life reported experience.