É. Leverett, E. Jardine, Erin Burns, Ankit Gangwal, Dan Geer
{"title":"Averages don’t characterise the heavy tails of ransoms","authors":"É. Leverett, E. Jardine, Erin Burns, Ankit Gangwal, Dan Geer","doi":"10.1109/eCrime51433.2020.9493256","DOIUrl":null,"url":null,"abstract":"The Bitcoin block-chain is the scoreboard of Ransomware. By mining the data in it and within the malware itself, we can understand the distribution of ransoms and characterise ransomware risk. Ransoms follow the power-law distribution in their amounts. The alpha parameter (α) of those power laws suggest they do not have a well defined average for most years in our study. Indeed, there has not been an α above 2 since 2015 and so there has not been a stable ransomware average since that time. The changing α has strong implications for cyber risk management and policy responses to ransomware attacks.","PeriodicalId":103272,"journal":{"name":"2020 APWG Symposium on Electronic Crime Research (eCrime)","volume":"29 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-11-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 APWG Symposium on Electronic Crime Research (eCrime)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/eCrime51433.2020.9493256","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Abstract
The Bitcoin block-chain is the scoreboard of Ransomware. By mining the data in it and within the malware itself, we can understand the distribution of ransoms and characterise ransomware risk. Ransoms follow the power-law distribution in their amounts. The alpha parameter (α) of those power laws suggest they do not have a well defined average for most years in our study. Indeed, there has not been an α above 2 since 2015 and so there has not been a stable ransomware average since that time. The changing α has strong implications for cyber risk management and policy responses to ransomware attacks.