Skip to main navigation Skip to search Skip to main content

A Game Theoretic Approach to the Design of Mitigation Strategies for Generic Ransomware

  • Illinois State University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

1 Scopus citations

Abstract

Recently, ransomware attacks have become widespread and are causing unprecedented damage to cyber-physical systems. Although there are various types of ransomware, this paper focuses on a generic version and analyzes it using game theory. When attacked, victims are often faced with the dilemma of deciding whether or not to pay a ransom. To assist victims in making this decision, we develop a game-theoretic model that examines the attack environment and determines the conditions under which the defender has an advantage in neutralizing the attack. We introduce two new parameters to the game model to aid in decision-making when confronted with a ransomware attack. Additionally, we present game models that depict both rational and irrational attacker behavior. We perform a sensitivity analysis on the game model in cases where the attacker behaves rationally, and demonstrate the impact of the parameters on the decision-making process and equilibrium strategies. Ultimately, we explore how the model’s outcomes can assist defenders in designing an effective defense system to prevent and mitigate future attacks of a similar nature. This also, prepares the ground for analysis of more advanced form of malware.

Original languageEnglish
Title of host publicationInformation Systems Security and Privacy - 7th International Conference, ICISSP 2021, and 8th International Conference, ICISSP 2022, Revised Selected Papers
EditorsPaolo Mori, Gabriele Lenzini, Steven Furnell
PublisherSpringer Science and Business Media Deutschland GmbH
Pages104-124
Number of pages21
ISBN (Print)9783031378065
DOIs
StatePublished - 2023
Event7th and 8th International Conferences on Information Systems Security and Privacy, ICISSP 2021 and ICISSP 2022 - Virtual, Online
Duration: Feb 9 2022Feb 11 2022

Publication series

NameCommunications in Computer and Information Science
Volume1851 CCIS
ISSN (Print)1865-0929
ISSN (Electronic)1865-0937

Conference

Conference7th and 8th International Conferences on Information Systems Security and Privacy, ICISSP 2021 and ICISSP 2022
CityVirtual, Online
Period02/9/2202/11/22

Keywords

  • Computer security
  • Cryptography
  • Cybersecurity
  • Game theory
  • Ransomware

Fingerprint

Dive into the research topics of 'A Game Theoretic Approach to the Design of Mitigation Strategies for Generic Ransomware'. Together they form a unique fingerprint.

Cite this