论文标题

一个两个市场的故事:调查勒索软件支付经济

A Tale of Two Markets: Investigating the Ransomware Payments Economy

论文作者

Oosthoek, Kris, Cable, Jack, Smaragdakis, Georgios

论文摘要

勒索软件攻击是最严重的网络威胁之一。近年来,他们通过威胁政府,关键基础设施和公司的运作来成为头条新闻。收集和分析勒索软件数据是了解勒索软件和设计有效的防御和缓解机制的传播的重要步骤。我们报告了经营Ransomwhere的经验,这是一个开放的众包勒索软件支付跟踪器,以收集勒索软件攻击受害者的信息。有了勒索到达,我们已经收集了13.5万勒索的赎金,向87多个勒索软件犯罪分子演员付款,总付款超过1.01亿美元。利用比特币的透明性质,用于大多数勒索软件支付的加密货币,我们表征了不断发展的勒索软件犯罪结构和勒索洗钱策略。我们的分析表明,有两个并行勒索软件犯罪市场:商品勒索软件和勒索软件作为服务(RAAS)。我们注意到,这两个市场之间存在着明显的差异,即使用加密货币资源,每笔交易的收入以及勒索洗钱效率。尽管识别商品勒索软件支付活动中的扼流圈相对容易,但对于RAAS来说,要做同样的事情更加困难。

Ransomware attacks are among the most severe cyber threats. They have made headlines in recent years by threatening the operation of governments, critical infrastructure, and corporations. Collecting and analyzing ransomware data is an important step towards understanding the spread of ransomware and designing effective defense and mitigation mechanisms. We report on our experience operating Ransomwhere, an open crowdsourced ransomware payment tracker to collect information from victims of ransomware attacks. With Ransomwhere, we have gathered 13.5k ransom payments to more than 87 ransomware criminal actors with total payments of more than $101 million. Leveraging the transparent nature of Bitcoin, the cryptocurrency used for most ransomware payments, we characterize the evolving ransomware criminal structure and ransom laundering strategies. Our analysis shows that there are two parallel ransomware criminal markets: commodity ransomware and Ransomware as a Service (RaaS). We notice that there are striking differences between the two markets in the way that cryptocurrency resources are utilized, revenue per transaction, and ransom laundering efficiency. Although it is relatively easy to identify choke points in commodity ransomware payment activity, it is more difficult to do the same for RaaS.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源