错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Negotiating with Attackers

  • Anirudh Khanna

摘要

The issue of whether or not to engage in negotiations with ransomware attackers is not easy. It has many pros and cons regarding legal, ethical, and practical implications. Unfortunately, there is no straightforward answer to this question because the application of these measures may depend on the existence and characteristics of the attack, as well as on the organization that is being targeted. This chapter will, therefore, explain the underlying factors regarding negotiations and inform organizations of some of the best practices for dealing with cyber criminals. Ransomware is a constantly evolving threat that targets businesses, governments, and individuals in the form of malicious software that demands that the victim pay the attacker a sum of money within a specified time for the decryption key [1]. The mobile malware encrypts data retrieved from a vulnerable device and then holds this data for ransom. Disaster recovery is critical to virtually any organization, given the continuous pressure placed on organizations today to restore their lost data and systems as much as possible and in the shortest time possible to avoid significant losses. It may be tempting to deal with cyber criminals to ‘get the job done’ quickly, but it poses questions that are pretty difficult to answer [2]. In other words, it could be seen that paying for the ransom might be equivalent to financing the criminals, and this might contravene legal prohibitions or restrictive measures. There are arguments concerning using funds that hackers and similar undesirable elements would use to finance such malice toward others. Paying the ransom may lead to even more reckless attacks since the perpetrators know this is an effective way to get what they want. However, as they decide not to pay the ransom, most of the victims may lose data permanently, which may lead to the crippling of operations for good. This chapter investigates these compounding factors to provide leadership direction for the process. In considering potential and actual issues and dilemmas, we consider real-life cases, legal provisions and the common law, ethical theories, and opinions from practitioners and scholars. Thus, the above-mentioned complex analysis aims to provide the toolkit that would help organizations analyze their particular case and make the proper decision rationally, as well as minimize the motivations for future ransomware activities.