Location

Online

Event Website

https://hicss.hawaii.edu/

Start Date

4-1-2021 12:00 AM

End Date

9-1-2021 12:00 AM

Description

Recently, there has been an upsurge in ransomware attacks. A ransomware attacker encrypts a user's files and then demands a ransom in exchange for the decryption key. While paying the ransom allows the user to quickly unlock the locked files and avoid potentially larger losses, it also strengthens the hands of the attacker and increases the chance of a future attack. We study this dilemma of the victims using a game-theoretic model and the resulting equilibrium. This leads to several interesting insights such as that legally prohibiting ransom payments may not always have the desired economic effects---in some cases, a ban is effective in addressing the economic externality but, in others, it may reduce overall welfare. We explain when and why a ban may help and when it may not. Our findings have important implications for policymakers who are currently debating laws that, if enacted, will ban payments to attackers.

Share

COinS
 
Jan 4th, 12:00 AM Jan 9th, 12:00 AM

Should We Outlaw Ransomware Payments?

Online

Recently, there has been an upsurge in ransomware attacks. A ransomware attacker encrypts a user's files and then demands a ransom in exchange for the decryption key. While paying the ransom allows the user to quickly unlock the locked files and avoid potentially larger losses, it also strengthens the hands of the attacker and increases the chance of a future attack. We study this dilemma of the victims using a game-theoretic model and the resulting equilibrium. This leads to several interesting insights such as that legally prohibiting ransom payments may not always have the desired economic effects---in some cases, a ban is effective in addressing the economic externality but, in others, it may reduce overall welfare. We explain when and why a ban may help and when it may not. Our findings have important implications for policymakers who are currently debating laws that, if enacted, will ban payments to attackers.

https://aisel.aisnet.org/hicss-54/os/sites/13