{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T21:48:35Z","timestamp":1780091315720,"version":"3.54.0"},"publisher-location":"Cham","reference-count":36,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319687100","type":"print"},{"value":"9783319687117","type":"electronic"}],"license":[{"start":{"date-parts":[[2017,1,1]],"date-time":"2017-01-01T00:00:00Z","timestamp":1483228800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2017]]},"DOI":"10.1007\/978-3-319-68711-7_21","type":"book-chapter","created":{"date-parts":[[2017,10,4]],"date-time":"2017-10-04T04:23:40Z","timestamp":1507091020000},"page":"397-417","source":"Crossref","is-referenced-by-count":38,"title":["On the Economics of Ransomware"],"prefix":"10.1007","author":[{"given":"Aron","family":"Laszka","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sadegh","family":"Farhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jens","family":"Grossklags","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2017,10,4]]},"reference":[{"key":"21_CR1","doi-asserted-by":"crossref","unstructured":"Acquisti, A., Grossklags, J.: What can behavioral economics teach us about privacy? In: Digital Privacy: Theory, Technologies, and Practices, pp. 363\u2013379. Auerbach Publications (2007)","DOI":"10.1201\/9781420052183.ch18"},{"key":"21_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"382","DOI":"10.1007\/978-3-319-26362-5_18","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"N Andronio","year":"2015","unstructured":"Andronio, N., Zanero, S., Maggi, F.: HelDroid: Dissecting and detecting mobile ransomware. In: Bos, H., Monrose, F., Blanc, G. (eds.) RAID 2015. LNCS, vol. 9404, pp. 382\u2013404. Springer, Cham (2015). doi: 10.1007\/978-3-319-26362-5_18"},{"key":"21_CR3","unstructured":"Backblaze: Backup awareness survey, our 10th year, industry report. https:\/\/www.backblaze.com\/blog\/backup-awareness-survey\/"},{"key":"21_CR4","unstructured":"Baddeley, M.: Information security: Lessons from behavioural economics. In: Workshop on the Economics of Information Security (WEIS) (2011)"},{"issue":"2","key":"21_CR5","doi-asserted-by":"crossref","first-page":"169","DOI":"10.1086\/259394","volume":"76","author":"G Becker","year":"1968","unstructured":"Becker, G.: Crime and punishment: an economic approach. J. Polit. Econ. 76(2), 169\u2013217 (1968)","journal-title":"J. Polit. Econ."},{"key":"21_CR6","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1016\/j.ejpoleco.2016.05.004","volume":"44","author":"P Brandt","year":"2016","unstructured":"Brandt, P., George, J., Sandler, T.: Why concessions should not be made to terrorist kidnappers. Eur. J. Polit. Econ. 44, 41\u201352 (2016)","journal-title":"Eur. J. Polit. Econ."},{"key":"21_CR7","unstructured":"Bruskin Research: Nearly one in four computer users have lost content to blackouts, viruses and hackers according to new national survey, survey conducted for Iomega Corporation (2001)"},{"issue":"3","key":"21_CR8","doi-asserted-by":"crossref","first-page":"481","DOI":"10.1007\/s11127-013-0108-4","volume":"160","author":"A Fink","year":"2014","unstructured":"Fink, A., Pingle, M.: Kidnap insurance and its impact on kidnapping outcomes. Public Choice 160(3), 481\u2013499 (2014)","journal-title":"Public Choice"},{"key":"21_CR9","unstructured":"Finkle, J.: Ransomware: Extortionist hackers borrow customer-service tactics (2016). http:\/\/www.reuters.com\/article\/us-usa-cyber-ransomware-idUSKCN0X917X"},{"key":"21_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"167","DOI":"10.1007\/978-3-642-03549-4_10","volume-title":"Financial Cryptography and Data Security","author":"N Fultz","year":"2009","unstructured":"Fultz, N., Grossklags, J.: Blue versus Red: towards a model of distributed security attacks. In: Dingledine, R., Golle, P. (eds.) FC 2009. LNCS, vol. 5628, pp. 167\u2013183. Springer, Heidelberg (2009). doi: 10.1007\/978-3-642-03549-4_10"},{"issue":"1","key":"21_CR11","doi-asserted-by":"crossref","first-page":"77","DOI":"10.1007\/s11416-008-0092-2","volume":"6","author":"A Gazet","year":"2010","unstructured":"Gazet, A.: Comparative analysis of various ransomware virii. J. Comput. Virol. 6(1), 77\u201390 (2010)","journal-title":"J. Comput. Virol."},{"key":"21_CR12","doi-asserted-by":"crossref","unstructured":"Grossklags, J., Christin, N., Chuang, J.: Secure or insure?: A game-theoretic analysis of information security games. In: Proceedings of the 17th International World Wide Web Conference, pp. 209\u2013218 (2008)","DOI":"10.1145\/1367497.1367526"},{"key":"21_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1007\/978-3-319-08506-7_5","volume-title":"Privacy Enhancing Technologies","author":"J Grossklags","year":"2014","unstructured":"Grossklags, J., Barradale, N.J.: Social status and the demand for security and privacy. In: De Cristofaro, E., Murdoch, S.J. (eds.) PETS 2014. LNCS, vol. 8555, pp. 83\u2013101. Springer, Cham (2014). doi: 10.1007\/978-3-319-08506-7_5"},{"key":"21_CR14","unstructured":"IBM: IBM study: Businesses more likely to pay ransomware than consumers, industry report (2016). http:\/\/www-03.ibm.com\/press\/us\/en\/pressrelease\/51230.wss"},{"key":"21_CR15","unstructured":"Kabooza: Global backup survey: About backup habits, risk factors, worries and data loss of home PCs, January 2009. http:\/\/www.kabooza.com\/globalsurvey.html"},{"key":"21_CR16","unstructured":"Kharraz, A., Arshad, S., Mulliner, C., Robertson, W., Kirda, E.: UNVEIL: A large-scale, automated approach to detecting ransomware. In: Proceedings of the 25th USENIX Security Symposium (USENIX Security), pp. 757\u2013772 (2016)"},{"key":"21_CR17","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-319-20550-2_1","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"A Kharraz","year":"2015","unstructured":"Kharraz, A., Robertson, W., Balzarotti, D., Bilge, L., Kirda, E.: Cutting the Gordian Knot: A look under the hood of ransomware attacks. In: Almgren, M., Gulisano, V., Maggi, F. (eds.) DIMVA 2015. LNCS, vol. 9148, pp. 3\u201324. Springer, Cham (2015). doi: 10.1007\/978-3-319-20550-2_1"},{"key":"21_CR18","unstructured":"KnowBe4: The 2017 endpoint protection ransomware effectiveness report, industry report (2017). https:\/\/www.knowbe4.com\/hubfs\/Endpoint%20Protection%20Ransomware%20Effectiveness%20Report.pdf"},{"issue":"2","key":"21_CR19","doi-asserted-by":"crossref","first-page":"23:1","DOI":"10.1145\/2635673","volume":"47","author":"A Laszka","year":"2014","unstructured":"Laszka, A., Felegyhazi, M., Buttyan, L.: A survey of interdependent information security games. ACM Comput. Surv. 47(2), 23:1\u201323:38 (2014)","journal-title":"ACM Comput. Surv."},{"key":"21_CR20","unstructured":"Laszka, A., Farhang, S., Grossklags, J.: On the economics of ransomware. CoRR abs\/1707.06247 (2017). http:\/\/arxiv.org\/abs\/1707.06247"},{"key":"21_CR21","doi-asserted-by":"crossref","unstructured":"Liao, K., Zhao, Z., Doup\u00e9, A., Ahn, G.J.: Behind closed doors: Measurement and analysis of CryptoLocker ransoms in Bitcoin. In: Proceedings of the 2016 APWG Symposium on Electronic Crime Research (eCrime) (2016)","DOI":"10.1109\/ECRIME.2016.7487938"},{"issue":"4","key":"21_CR22","doi-asserted-by":"crossref","first-page":"195","DOI":"10.1080\/10658980701576412","volume":"16","author":"X Luo","year":"2007","unstructured":"Luo, X., Liao, Q.: Awareness education as the key to ransomware prevention. Inf. Syst. Secur. 16(4), 195\u2013202 (2007)","journal-title":"Inf. Syst. Secur."},{"key":"21_CR23","doi-asserted-by":"crossref","unstructured":"Luo, X., Liao, Q.: Ransomware: A new cyber hijacking threat to enterprises. In: Gupta, J., Sharma, S. (eds.) Handbook of Research on Information Security and Assurance, pp. 1\u20136. IGI Global (2009)","DOI":"10.4018\/978-1-59904-855-0.ch001"},{"issue":"1","key":"21_CR24","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1257\/aer.89.1.103","volume":"89","author":"T O\u2019Donoghue","year":"1999","unstructured":"O\u2019Donoghue, T., Rabin, M.: Doing it now or later. Am. Econ. Rev. 89(1), 103\u2013124 (1999)","journal-title":"Am. Econ. Rev."},{"key":"21_CR25","unstructured":"O\u2019Gorman, G., McDonald, G.: Ransomware: A growing menace. Symantec Security Response (2012)"},{"key":"21_CR26","unstructured":"Proofpoint: Threat summary: Q4 2016 & year in review, industry report. https:\/\/www.proofpoint.com\/sites\/default\/files\/proofpoint_q4_threat_report-final-cm.pdf"},{"key":"21_CR27","doi-asserted-by":"crossref","unstructured":"Scaife, N., Carter, H., Traynor, P., Butler, K.: Cryptolock (and drop it): Stopping ransomware attacks on user data. In: Proceedings of the IEEE International Conference on Distributed Computing Systems (ICDCS), pp. 303\u2013312 (2016)","DOI":"10.1109\/ICDCS.2016.46"},{"key":"21_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"122","DOI":"10.1007\/978-3-540-45126-6_9","volume-title":"Financial Cryptography","author":"SE Schechter","year":"2003","unstructured":"Schechter, S.E., Smith, M.D.: How much security is enough to stop a thief? In: Wright, R.N. (ed.) FC 2003. LNCS, vol. 2742, pp. 122\u2013137. Springer, Heidelberg (2003). doi: 10.1007\/978-3-540-45126-6_9"},{"key":"21_CR29","unstructured":"Simon, R.: Mirai, BrickerBot, Hajime attack a common IoT weakness (2017). https:\/\/securingtomorrow.mcafee.com\/mcafee-labs\/mirai-brickerbot-hajime-attack-common-iot-weakness\/"},{"key":"21_CR30","unstructured":"U.S. Department of Health & Human Service: Fact sheet: Ransomware and HIPAA (2016). https:\/\/www.hhs.gov\/sites\/default\/files\/RansomwareFactSheet.pdf"},{"key":"21_CR31","first-page":"1","volume-title":"Economics of Information Security (Advances in Information Security)","author":"H Varian","year":"2004","unstructured":"Varian, H.: System reliability and free riding. In: Camp, L., Lewis, S. (eds.) Economics of Information Security (Advances in Information Security), vol. 12, pp. 1\u201315. Kluwer Academic Publishers, Dordrecht (2004)"},{"key":"21_CR32","unstructured":"Venkat, S.: Lessons for telcos from the WannaCry ransomware attack, cerillion blog (2017). http:\/\/www.cerillion.com\/Blog\/May-2017\/Lessons-for-Telcos-from-the-WannaCry-attack"},{"key":"21_CR33","unstructured":"Verizon: 2017 Data breach investigations report: Executive summary, industry report"},{"key":"21_CR34","doi-asserted-by":"crossref","unstructured":"Yang, T., Yang, Y., Qian, K., Lo, D.C.T., Qian, Y., Tao, L.: Automated detection and analysis for Android ransomware. In: Proceedings of the 1st IEEE International Conference on Big Data Security on Cloud (DataSec), pp. 1338\u20131343. IEEE (2015)","DOI":"10.1109\/HPCC-CSS-ICESS.2015.39"},{"key":"21_CR35","doi-asserted-by":"crossref","unstructured":"Young, A., Yung, M.: Cryptovirology: Extortion-based security threats and countermeasures. In: Proceedings of the 1996 IEEE Symposium on Security and Privacy, pp. 129\u2013140 (1996)","DOI":"10.1109\/SECPRI.1996.502676"},{"issue":"7","key":"21_CR36","doi-asserted-by":"crossref","first-page":"24","DOI":"10.1145\/3097347","volume":"60","author":"A Young","year":"2017","unstructured":"Young, A., Yung, M.: Cryptovirology: The birth, neglect, and explosion of ransomware. Commun. ACM 60(7), 24\u201326 (2017)","journal-title":"Commun. ACM"}],"container-title":["Lecture Notes in Computer Science","Decision and Game Theory for Security"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-68711-7_21","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,10,4]],"date-time":"2019-10-04T02:44:22Z","timestamp":1570157062000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-68711-7_21"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017]]},"ISBN":["9783319687100","9783319687117"],"references-count":36,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-68711-7_21","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017]]}}}