Abstract
Double extortion ransomware attacks consist of an attack where victims files are both encrypted and exfiltrated for extortion purposes. There is empirical evidence this leads to an increased willingness to pay a ransom, and higher ransoms, compared to encryption-only attacks, depending on the value of the exfiltrated files. However, there seem to be two complications: First, victims are uncertain whether data is exfiltrated, due to for example misconfigured monitoring systems. Second, it is hard for attackers to estimate the value of compromised files. Thus, victims have an incentive to hide what they know and attackers an incentive to find out information. The goal of this study is to use game theory to explore the payoff consequences for attackers of victims having private information. We analyse a signaling game with double-sided information asymmetry: (1) attackers know whether data is exfiltrated and victims do not, and (2) victims know the value of data if it is exfiltrated, but the attackers do not. Our analysis of the game indicates that private information substantially lowers the return to attackers. These results imply that victims should be careful to not reveal the value of files during negotiations.
Author supplied keywords
Cite
CITATION STYLE
Meurs, T., Cartwright, E., & Cartwright, A. (2023). Double-Sided Information Asymmetry in Double Extortion Ransomware. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 14167 LNCS, pp. 311–328). Springer Science and Business Media Deutschland GmbH. https://doi.org/10.1007/978-3-031-50670-3_16
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.