On the economic significance of ransomware campaigns: A Bitcoin transactions perspective

被引:64
作者
Conti, Mauro [1 ]
Gangwal, Ankit [1 ]
Ruj, Sushmita [2 ]
机构
[1] Univ Padua, Dept Math, I-35121 Padua, Italy
[2] Indian Stat Inst, Comp & Commun Sci Div, Cryptol & Secur Res Unit, Kolkata 700108, India
基金
欧盟地平线“2020”;
关键词
Bitcoin; Cryptocurrency; Distributed ledger; Payment; Ransomware; Transaction;
D O I
10.1016/j.cose.2018.08.008
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Bitcoin cryptocurrency system enables users to transact securely and pseudo-anonymously by using an arbitrary number of aliases (Bitcoin addresses). Cybercriminals exploit these characteristics to commit immutable and presumably untraceable monetary fraud, especially via ransomware; a type of malware that encrypts files of the infected system and demands ransom for decryption. In this paper, we present our comprehensive study on all recent ransomware and report the economic impact of such ransomware from the Bitcoin payment perspective. We also present a lightweight framework to identify, collect, and analyze Bitcoin addresses managed by the same user or group of users (cybercriminals, in this case), which includes a novel approach for classifying a payment as ransom. To verify the correctness of our framework, we compared our findings on CryptoLocker ransomware with the results presented in the literature. Our results align with the results found in the previous works except for the final valuation in USD. The reason for this discrepancy is that we used the average Bitcoin price on the day of each ransom payment whereas the authors of the previous studies used the Bitcoin price on the day of their evaluation. Furthermore, for each investigated ransomware, we provide a holistic view of its genesis, development, the process of infection and execution, and characteristic of ransom demands. Finally, we also release our dataset that contains a detailed transaction history of all the Bitcoin addresses we identified for each ransomware. (C) 2018 Elsevier Ltd. All rights reserved.
引用
收藏
页码:162 / 189
页数:28
相关论文
共 45 条
[1]  
[Anonymous], TECHNICAL REPORT
[2]  
[Anonymous], CRYPTOLOCKER RANS IN
[3]  
[Anonymous], DMA LOCK 4 0 KNOWN R
[4]  
[Anonymous], AFT NOTPETYA ATT
[5]  
[Anonymous], PET RANS OUTBR HER W
[6]  
[Anonymous], NOTPETYA TECHN AN
[7]  
[Anonymous], DOUBLELOCKER INN AND
[8]  
[Anonymous], 2016, Communications of the ACM, DOI [10.1145/2504730.2504747, DOI 10.1145/2504730.2504747, DOI 10.1145/2896384, 10.1145/2896384]
[9]  
[Anonymous], 2016, NEW OS X RANSOMWARE
[10]  
[Anonymous], TESLACRYPT RANS