Introduction to the Special Issue on Ransomware

Introduction to the Special Issue on Ransomware
复制标题

勒索软件特刊简介

DOI:
10.1145/3629999
复制
发表时间:
2023
期刊:
Research and Practice
影响因子:
--
通讯作者:
Arief B
Arief B
中科院分区:
--
文献类型:
--
作者:
Arief B

文献摘要

相似文献

在过去的几年里,勒索软件已经成为我们社会中最令人担忧和破坏性的网络威胁之一。勒索软件不仅改变了我们保护组织的方式,还彻底改变了地下经济,以至于现在大多数网络犯罪活动都围绕着支持勒索软件操作展开。虽然勒索软件在过去几年中不断出现在新闻中,但我们对它的大部分了解都来自技术报告。无论这些报告是来自供应商还是学术报告,它们本质上仍然主要是技术性的。本期特刊的目的是从各种角度和学科更好地了解勒索软件。心理学和犯罪学的观点将会加深我们对勒索软件犯罪的理解,并可能提出威慑机制,以及提高我们对勒索软件罪犯和受害者的认识。从经济角度来看,最近的分析将限制勒索软件的盈利能力。法律途径将有助于改善目前的监管环境。这次联合行动的最终目的是找到更有效地打击勒索软件犯罪的机制。本期特刊征集了与勒索软件有关的所有领域的论文。每份投稿都经过至少三次双盲评审,在某些情况下通过多轮评审,以确保入选的论文是可靠的,并为本期特刊提供了真正的贡献。最后,我们挑选了六篇论文,涵盖了广泛的主题,包括COVID-19爆发期间勒索软件的演变,勒索软件受害与人类人格特征之间潜在联系的探索,攻击期间防止数据泄露措施的自动化,勒索软件行为建模,勒索软件经济学以及勒索软件特定事件响应程序。第一篇论文《勒索软件不断演变的威胁:大流行前和大流行中期攻击的比较分析》,重点介绍了自COVID-19爆发以来勒索软件策略的演变。根据39次大流行前和大流行中期勒索软件攻击的定性数据,作者确定了几个因素,这些因素使黑客能够利用新冠病毒时代特有的漏洞。首先,由于员工在家工作,攻击者可能会利用扩展的攻击面。随后,黑客可以利用远程连接设备、个人机器的漏洞,以及在家工作环境中缺乏典型的办公流程和实践。接下来,利用人们的恐惧,黑客可能会在网络钓鱼邮件中使用社会工程技术,向公众提供各种令人安慰的解决方案,以击败和/或保护他们免受病毒的侵害,但实际上,提供的链接和附件可能包含勒索软件。此外,这篇论文强调了勒索软件进化过程中一个非常重要的点,即黑客不仅可以加密,还可以窃取受害者的数据,从而增加额外的刺痛。这种新策略过去和现在都对个人隐私产生了深远的影响。这组作者发现,大流行前和大流行中期的攻击的关键根本原因是拙劣的组织实践和未能注意基本的安全卫生。本文最后提出了一系列预防和应对新冠病毒时代出现的勒索软件攻击的建议。
In the past few years, ransomware has become one of the most concerning and disruptive cyber threats in our society. Not only has ransomware changed how we defend our organizations, it has completely altered the underground economy, to a point where most cybercriminal activities now revolve around supporting ransomware operations. While ransomware has been in the news constantly over the past few years, most of our understanding of it comes through technical reports. Whether those reports originate from vendors or academic reporting, they are still primarily technical in nature.The aim of this special issue was to get a better understanding of ransomware from a variety of lenses and disciplines. Psychological and criminological perspectives will enhance our understanding of ransomware crime and potentially suggest deterrence mechanisms, as well as improve our knowledge on ransomware offenders and victims. An economic point of view will expand on recent analysis to limit ransomware profitability. The legal approach will help advance the current regulatory environment. The ultimate purpose of this combined effort is to find mechanisms to fight ransomware crime more effectively. This special issue solicited papers on all areas related to ransomware. Each submission was assessed by at least three double-blind reviews, in some cases through multiple rounds of review to make sure that the selected papers are robust and provide real contributions to this special issue. In the end, we picked six papers covering a wide spectrum of topics, including the evolution of ransomware during the COVID-19 outbreak, the exploration of potential links between ransomware victimization and human personality traits, the automation of measures to prevent data exfiltration during attacks, the modeling of ransomware behavior, the economics of ransomware, and the ransomware-specific incident response procedures. The first paper,“The Evolving Menace of Ransomware: A Comparative Analysis of Pre-Pandemic and Mid-Pandemic Attacks,” focuses on how ransomware tactics have evolved since the COVID-19 outbreak. Drawing on the qualitative data from thirty-nine pre-pandemic and mid-pandemic ransomware attacks, the authors identify several factors that allowed hackers to exploit vulnerabilities specific to the COVID era. First, attackers might take advantage of the extended attack surface due to employees working from home. Subsequently, hackers could exploit remote connection devices, vulnerabilities in personal machines, and the lack of the typical office processes and practices in the work-at-home environment. Next, feeding on people’s fear, hackers might use social engineering techniques in phishing emails by offering the public various comforting solutions to defeat and/or to protect them from the virus, but in reality, the provided links and attachments would harbor ransomware. Furthermore, the paper highlights a very important point in the ransomware evolution, whereby hackers might add an extra sting by not only encrypting but also stealing victims’ data. This new tactic had and continues to have profound implications on individuals’ privacy. The authors found that the key underlying cause for both pre-pandemic and mid-pandemic attacks was shoddy organizational practices and the failure to attend to basic security hygiene. This paper concludes with a set of recommendations to prevent and respond to ransomware attacks that emerged in the COVID era.