Introduction to the Special Issue on Ransomware
Introduction to the Special Issue on Ransomware
复制标题
勒索软件特刊简介
DOI:
10.1145/3629999
复制
发表时间:
2023
期刊:
影响因子:
--
通讯作者:
Arief B
中科院分区:
文献类型:
--
作者:
Arief B
In the past few years, ransomware has become one of the most concerning and disruptive cyber threats in our society. Not only has ransomware changed how we defend our organizations, it has completely altered the underground economy, to a point where most cybercriminal activities now revolve around supporting ransomware operations. While ransomware has been in the news constantly over the past few years, most of our understanding of it comes through technical reports. Whether those reports originate from vendors or academic reporting, they are still primarily technical in nature.The aim of this special issue was to get a better understanding of ransomware from a variety of lenses and disciplines. Psychological and criminological perspectives will enhance our understanding of ransomware crime and potentially suggest deterrence mechanisms, as well as improve our knowledge on ransomware offenders and victims. An economic point of view will expand on recent analysis to limit ransomware profitability. The legal approach will help advance the current regulatory environment. The ultimate purpose of this combined effort is to find mechanisms to fight ransomware crime more effectively. This special issue solicited papers on all areas related to ransomware. Each submission was assessed by at least three double-blind reviews, in some cases through multiple rounds of review to make sure that the selected papers are robust and provide real contributions to this special issue. In the end, we picked six papers covering a wide spectrum of topics, including the evolution of ransomware during the COVID-19 outbreak, the exploration of potential links between ransomware victimization and human personality traits, the automation of measures to prevent data exfiltration during attacks, the modeling of ransomware behavior, the economics of ransomware, and the ransomware-specific incident response procedures. The first paper,“The Evolving Menace of Ransomware: A Comparative Analysis of Pre-Pandemic and Mid-Pandemic Attacks,” focuses on how ransomware tactics have evolved since the COVID-19 outbreak. Drawing on the qualitative data from thirty-nine pre-pandemic and mid-pandemic ransomware attacks, the authors identify several factors that allowed hackers to exploit vulnerabilities specific to the COVID era. First, attackers might take advantage of the extended attack surface due to employees working from home. Subsequently, hackers could exploit remote connection devices, vulnerabilities in personal machines, and the lack of the typical office processes and practices in the work-at-home environment. Next, feeding on people’s fear, hackers might use social engineering techniques in phishing emails by offering the public various comforting solutions to defeat and/or to protect them from the virus, but in reality, the provided links and attachments would harbor ransomware. Furthermore, the paper highlights a very important point in the ransomware evolution, whereby hackers might add an extra sting by not only encrypting but also stealing victims’ data. This new tactic had and continues to have profound implications on individuals’ privacy. The authors found that the key underlying cause for both pre-pandemic and mid-pandemic attacks was shoddy organizational practices and the failure to attend to basic security hygiene. This paper concludes with a set of recommendations to prevent and respond to ransomware attacks that emerged in the COVID era.