{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,23]],"date-time":"2026-01-23T11:54:07Z","timestamp":1769169247976,"version":"3.49.0"},"reference-count":46,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2023,10,20]],"date-time":"2023-10-20T00:00:00Z","timestamp":1697760000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2023,12,31]]},"abstract":"<jats:p>Ransomware has evolved into one of the most severe cyberthreats against private and public sectors alike. Organizations are inundated with a barrage of intrusion attempts that ultimately morph into full-scale ransomware attacks. Efforts to combat these threats tend to primarily focus on detection and prevention, and while thwarting an attack is always the best approach, we must additionally improve our response and recovery efforts with a post-breach mindset. Assume that the defenses have failed and the risk has materialized. Are we then prepared to best salvage the situation with efficient, ransomware-specific incident response procedures? In this work, we present a ransomware response framework that can be leveraged to create highly effective ransomware response strategies. We provide a level of detail in this framework that balances adaptability versus actionability that both technical and executive stakeholders will find of use.<\/jats:p>","DOI":"10.1145\/3606022","type":"journal-article","created":{"date-parts":[[2023,6,26]],"date-time":"2023-06-26T12:27:26Z","timestamp":1687782446000},"page":"1-19","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["Know Thy Ransomware Response: A Detailed Framework for Devising Effective Ransomware Response Strategies"],"prefix":"10.1145","volume":"4","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4662-4049","authenticated-orcid":false,"given":"Pranshu","family":"Bajpai","sequence":"first","affiliation":[{"name":"Michigan State University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2415-5651","authenticated-orcid":false,"given":"Richard","family":"Enbody","sequence":"additional","affiliation":[{"name":"Michigan State University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,10,20]]},"reference":[{"key":"e_1_3_2_2_2","first-page":"1","volume-title":"2020 International Conference on Cyber Security and Protection of Digital Services (Cyber Security\u201920)","author":"Bajpai Pranshu","year":"2020","unstructured":"Pranshu Bajpai and Richard Enbody. 2020. An empirical study of key generation in cryptographic ransomware. In 2020 International Conference on Cyber Security and Protection of Digital Services (Cyber Security\u201920). IEEE, 1\u20138."},{"key":"e_1_3_2_3_2","first-page":"1","volume-title":"2020 International Conference on Cyber Security and Protection of Digital Services (Cyber Security\u201920)","author":"Bajpai Pranshu","year":"2020","unstructured":"Pranshu Bajpai and Richard Enbody. 2020. Memory forensics against ransomware. In 2020 International Conference on Cyber Security and Protection of Digital Services (Cyber Security\u201920). IEEE, 1\u20138."},{"issue":"2","key":"e_1_3_2_4_2","doi-asserted-by":"crossref","first-page":"8","DOI":"10.1016\/S1353-4858(20)30020-9","article-title":"Dissecting .NET ransomware: Key generation, encryption, and operation","volume":"2020","author":"Bajpai Pranshu","year":"2020","unstructured":"Pranshu Bajpai and Richard J. Enbody. 2020. Dissecting .NET ransomware: Key generation, encryption, and operation. Network Security 2020, 2 (2020), 8\u201315.","journal-title":"Network Security"},{"key":"e_1_3_2_5_2","first-page":"1","volume-title":"2018 APWG Symposium on Electronic Crime Research (eCrime\u201918)","author":"Bajpai Pranshu","year":"2018","unstructured":"Pranshu Bajpai, Aditya K. Sood, and Richard Enbody. 2018. A key-management-based taxonomy for ransomware. In 2018 APWG Symposium on Electronic Crime Research (eCrime\u201918). IEEE, 1\u201312."},{"key":"e_1_3_2_6_2","article-title":"Cybersecurity framework profile for ransomware risk management","volume":"8374","author":"Barker William C.","year":"2021","unstructured":"William C. Barker, Karen Scarfone, William Fisher, and Murugiah Souppaya. 2021. Cybersecurity framework profile for ransomware risk management. National Institute of Standards and Technology. Preliminary Draft NISTIR 8374 (2021).","journal-title":"National Institute of Standards and Technology. Preliminary Draft NISTIR"},{"key":"e_1_3_2_7_2","first-page":"164","volume-title":"Computer Science On-line Conference","author":"Bello Abubakar","year":"2020","unstructured":"Abubakar Bello and Alana Maurushat. 2020. Technical and behavioural training and awareness solutions for mitigating ransomware attacks. In Computer Science On-line Conference. Springer, 164\u2013176."},{"issue":"1","key":"e_1_3_2_8_2","doi-asserted-by":"crossref","first-page":"tyz009","DOI":"10.1093\/cybsec\/tyz009","article-title":"To pay or not: Game theoretic models of ransomware","volume":"5","author":"Cartwright Edward","year":"2019","unstructured":"Edward Cartwright, Julio Hernandez Castro, and Anna Cartwright. 2019. To pay or not: Game theoretic models of ransomware. Journal of Cybersecurity 5, 1 (2019), tyz009.","journal-title":"Journal of Cybersecurity"},{"key":"e_1_3_2_9_2","first-page":"454","volume-title":"2017 16th IEEE International Conference on Machine Learning and Applications (ICMLA\u201917)","author":"Chen Qian","year":"2017","unstructured":"Qian Chen and Robert A. Bridges. 2017. Automated behavioral analysis of malware: A case study of WannaCry ransomware. In 2017 16th IEEE International Conference on Machine Learning and Applications (ICMLA\u201917). 454\u2013460. https:\/\/doi.org\/10.1109\/ICMLA.2017.0-119"},{"key":"e_1_3_2_10_2","unstructured":"Paul Cichonski Tom Millar Tim Grance and Karen Scarfone. 2012. Computer security incident handling guide. NIST Special Publication 800 61 (2012) 1\u2013147."},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/2991079.2991110"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-019-00338-7"},{"key":"e_1_3_2_13_2","unstructured":"Debabrata Dey and Atanu Lahiri. 2021. Should we outlaw ransomware payments? Proceedings of the 54th Hawaii International Conference on System Sciences . Retrieved July 10 2023 from http:\/\/hdl.handle.net\/10125\/71414."},{"key":"e_1_3_2_14_2","article-title":"The extortion economy: How insurance companies are fueling a rise in ransomware attacks","author":"Dudley Renee","year":"2019","unstructured":"Renee Dudley. 2019. The extortion economy: How insurance companies are fueling a rise in ransomware attacks. Pro Publica (2019).","journal-title":"Pro Publica"},{"key":"e_1_3_2_15_2","doi-asserted-by":"crossref","first-page":"234","DOI":"10.1007\/978-3-319-93411-2_11","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment: 15th International Conference Proceedings (DIMVA\u201918)","author":"Gen\u00e7 Ziya Alper","year":"2018","unstructured":"Ziya Alper Gen\u00e7, Gabriele Lenzini, and Peter Y. A. Ryan. 2018. No random, no ransom: A key to stop cryptographic ransomware. In Detection of Intrusions and Malware, and Vulnerability Assessment: 15th International Conference Proceedings (DIMVA\u201918). Springer, 234\u2013255."},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.11.019"},{"key":"e_1_3_2_17_2","article-title":"The untold story of NotPetya, the most devastating cyberattack in history","volume":"22","author":"Greenberg Andy","year":"2018","unstructured":"Andy Greenberg. 2018. The untold story of NotPetya, the most devastating cyberattack in history. Wired, August 22, 2018.","journal-title":"Wired,"},{"key":"e_1_3_2_18_2","unstructured":"Ben Herzog and Yaniv Balmas. 2016. Great crypto failures. Virus Bulletin Conference (2016)."},{"issue":"1","key":"e_1_3_2_19_2","first-page":"1","article-title":"Ransomware deployment methods and analysis: Views from a predictive model and human responses","volume":"8","author":"Hull Gavin","year":"2019","unstructured":"Gavin Hull, Henna John, and Budi Arief. 2019. Ransomware deployment methods and analysis: Views from a predictive model and human responses. Crime Science 8, 1 (2019), 1\u201322.","journal-title":"Crime Science"},{"issue":"1","key":"e_1_3_2_20_2","first-page":"80","article-title":"Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains","volume":"1","author":"Hutchins Eric M.","year":"2011","unstructured":"Eric M. Hutchins, Michael J. Cloppert, Rohan M. Amin, et\u00a0al. 2011. Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains. Leading Issues in Information Warfare & Security Research 1, 1 (2011), 80.","journal-title":"Leading Issues in Information Warfare & Security Research"},{"key":"e_1_3_2_21_2","first-page":"1","volume-title":"2019 IEEE 12th International Conference on Global Security, Safety and Sustainability (ICGS3\u201919)","author":"Ibarra Jaime","year":"2019","unstructured":"Jaime Ibarra, Usman Javed Butt, Anh Do, Hamid Jahankhani, and Arshad Jamal. 2019. Ransomware impact to SCADA systems and its scope to critical infrastructure. In 2019 IEEE 12th International Conference on Global Security, Safety and Sustainability (ICGS3\u201919). IEEE, 1\u201312."},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00500-018-3257-z"},{"issue":"4","key":"e_1_3_2_23_2","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1093\/itnow\/bww103","article-title":"Ransomware recovery","volume":"58","author":"Kenyon Bridget","year":"2016","unstructured":"Bridget Kenyon and James McCafferty. 2016. Ransomware recovery. Itnow 58, 4 (2016), 32\u201333.","journal-title":"Itnow"},{"key":"e_1_3_2_24_2","first-page":"757","volume-title":"25th USENIX Security Symposium (USENIX Security\u201916)","author":"Kharraz Amin","year":"2016","unstructured":"Amin Kharraz, Sajjad Arshad, Collin Mulliner, William Robertson, and Engin Kirda. 2016. UNVEIL: A large-scale, automated approach to detecting ransomware. In 25th USENIX Security Symposium (USENIX Security\u201916). 757\u2013772."},{"key":"e_1_3_2_25_2","doi-asserted-by":"crossref","first-page":"98","DOI":"10.1007\/978-3-319-66332-6_5","volume-title":"International Symposium on Research in Attacks, Intrusions, and Defenses","author":"Kharraz Amin","year":"2017","unstructured":"Amin Kharraz and Engin Kirda. 2017. Redemption: Real-time protection against ransomware at end-hosts. In International Symposium on Research in Attacks, Intrusions, and Defenses. Springer, 98\u2013119."},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053035"},{"key":"e_1_3_2_27_2","doi-asserted-by":"crossref","first-page":"397","DOI":"10.1007\/978-3-319-68711-7_21","volume-title":"International Conference on Decision and Game Theory for Security","author":"Laszka Aron","year":"2017","unstructured":"Aron Laszka, Sadegh Farhang, and Jens Grossklags. 2017. On the economics of ransomware. In International Conference on Decision and Game Theory for Security. Springer, 397\u2013417."},{"issue":"2","key":"e_1_3_2_28_2","doi-asserted-by":"crossref","first-page":"103","DOI":"10.69554\/FARC5224","article-title":"Cyber security: A critical examination of information sharing versus data sensitivity issues for organisations at risk of cyber attack","volume":"7","author":"Mallinder Jason","year":"2014","unstructured":"Jason Mallinder and Peter Drabwell. 2014. Cyber security: A critical examination of information sharing versus data sensitivity issues for organisations at risk of cyber attack. Journal of Business Continuity & Emergency Planning 7, 2 (2014), 103\u2013111.","journal-title":"Journal of Business Continuity & Emergency Planning"},{"issue":"9","key":"e_1_3_2_29_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3479393","article-title":"Ransomware mitigation in the modern era: A comprehensive review, research challenges, and future directions","volume":"54","author":"McIntosh Timothy","year":"2021","unstructured":"Timothy McIntosh, A. S. M. Kayes, Yi-Ping Phoebe Chen, Alex Ng, and Paul Watters. 2021. Ransomware mitigation in the modern era: A comprehensive review, research challenges, and future directions. ACM Computing Surveys (CSUR) 54, 9 (2021), 1\u201336.","journal-title":"ACM Computing Surveys (CSUR)"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103162"},{"issue":"2","key":"e_1_3_2_31_2","doi-asserted-by":"crossref","first-page":"300","DOI":"10.1080\/08850607.2020.1780062","article-title":"Cyber threat intelligence: A product without a process?","volume":"34","author":"Oosthoek Kris","year":"2021","unstructured":"Kris Oosthoek and Christian Doerr. 2021. Cyber threat intelligence: A product without a process? International Journal of Intelligence and Counterintelligence 34, 2 (2021), 300\u2013315.","journal-title":"International Journal of Intelligence and Counterintelligence"},{"key":"e_1_3_2_32_2","first-page":"331","volume-title":"20th European Conference on Cyber Warfare and Security (ECCWS\u201921)","author":"Payne Bryson","year":"2021","unstructured":"Bryson Payne and Edward Mienie. 2021. Multiple-extortion ransomware: The case for active cyber threat intelligence. In 20th European Conference on Cyber Warfare and Security (ECCWS\u201921). Academic Conferences Inter Ltd., 331."},{"key":"e_1_3_2_33_2","article-title":"Malpedia: A collaborative effort to inventorize the malware landscape","author":"Plohmann Daniel","year":"2017","unstructured":"Daniel Plohmann, M. Clau\u00df, S. Enders, and E. Padilla. 2017. Malpedia: A collaborative effort to inventorize the malware landscape. In Proceedings of the Botconf.","journal-title":"Proceedings of the Botconf"},{"key":"e_1_3_2_34_2","unstructured":"Kulkarni Pooja Prakash Tabrez Nafis and Sidhartha Sankar Biswas. 2017. Preventive measures and incident response for locky ransomware. International Journal of Advanced Research in Computer Science 8 5 (2017) 392\u2013395."},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3160748"},{"key":"e_1_3_2_36_2","first-page":"303","volume-title":"2016 IEEE 36th International Conference on Distributed Computing Systems (ICDCS\u201916)","author":"Scaife Nolen","year":"2016","unstructured":"Nolen Scaife, Henry Carter, Patrick Traynor, and Kevin R. B. Butler. 2016. Cryptolock (and drop it): Stopping ransomware attacks on user data. In 2016 IEEE 36th International Conference on Distributed Computing Systems (ICDCS\u201916). IEEE, 303\u2013312."},{"key":"e_1_3_2_37_2","unstructured":"Nina-Birte Schirrmacher Jan Ondrus and Felix Ter Chian Tan. 2018. Towards a response to ransomware: Examining digital capabilities of the WannaCry attack. In Proceedings of the 22nd Pacific Asia Conference on Information Systems - Opportunities and Challenges for the Digitized Society: Are We Ready? (PACIS\u201918) M. Tanabu and D. Senoo (Eds.). Association for Information Systems."},{"key":"e_1_3_2_38_2","volume-title":"Framework for Improving Critical Infrastructure Cybersecurity, Version 1.0","author":"Sedgewick Adam","year":"2014","unstructured":"Adam Sedgewick. 2014. Framework for Improving Critical Infrastructure Cybersecurity, Version 1.0. Technical Report."},{"key":"e_1_3_2_39_2","volume-title":"Ransomware Incident Response for Law Enforcement","author":"Smith Jammie","year":"2017","unstructured":"Jammie Smith. 2017. Ransomware Incident Response for Law Enforcement. Ph. D. Dissertation. Utica College."},{"key":"e_1_3_2_40_2","doi-asserted-by":"crossref","first-page":"97","DOI":"10.1007\/978-3-642-15512-3_6","volume-title":"International Workshop on Recent Advances in Intrusion Detection","author":"Srivastava Abhinav","year":"2010","unstructured":"Abhinav Srivastava and Jonathon Giffin. 2010. Automatic discovery of parasitic malware. In International Workshop on Recent Advances in Intrusion Detection. Springer, 97\u2013117."},{"key":"e_1_3_2_41_2","article-title":"Mitre att&ck: Design and philosophy","author":"Strom Blake E.","year":"2018","unstructured":"Blake E. Strom, Andy Applebaum, Doug P. Miller, Kathryn C. Nickels, Adam G. Pennington, and Cody B. Thomas. 2018. Mitre att&ck: Design and philosophy. Technical Report (2018).","journal-title":"Technical Report"},{"key":"e_1_3_2_42_2","unstructured":"Amanda Tanner Alex Hinchliffe and Doel Santos. 2022. Threat assessment: Blackcat ransomware. Retrieved July 10 2023 from https:\/\/unit42.paloaltonetworks.com\/blackcat-ransomware\/."},{"issue":"3","key":"e_1_3_2_43_2","first-page":"1","article-title":"Individual cyber security: Empowering employees to resist spear phishing to prevent identity theft and ransomware attacks","volume":"12","author":"Thomas Jason","year":"2018","unstructured":"Jason Thomas. 2018. Individual cyber security: Empowering employees to resist spear phishing to prevent identity theft and ransomware attacks. International Journal of Business Management 12, 3 (2018), 1\u201323.","journal-title":"International Journal of Business Management"},{"key":"e_1_3_2_44_2","first-page":"45","article-title":"The transnational cybercrime extortion landscape and the pandemic: Changes in ransomware offender tactics, attack scalability and the organisation of offending","author":"Wall David S","year":"2022","unstructured":"David S Wall. 2022. The transnational cybercrime extortion landscape and the pandemic: Changes in ransomware offender tactics, attack scalability and the organisation of offending. Special Issue 5 Eur. Police Sci. & Res. Bull. (2022), 45. https:\/\/heinonline.org\/HOL\/LandingPage?handle=hein.journals\/elerb5000&div=8&id=&page=.","journal-title":"Special Issue 5 Eur. Police Sci. & Res. Bull."},{"key":"e_1_3_2_45_2","doi-asserted-by":"crossref","first-page":"129","DOI":"10.1109\/SECPRI.1996.502676","volume-title":"Proceedings 1996 IEEE Symposium on Security and Privacy","author":"Young Adam","year":"1996","unstructured":"Adam Young and Moti Yung. 1996. Cryptovirology: Extortion-based security threats and countermeasures. In Proceedings 1996 IEEE Symposium on Security and Privacy. IEEE, 129\u2013140."},{"key":"e_1_3_2_46_2","doi-asserted-by":"crossref","unstructured":"Adam L. Young. 2006. Cryptoviral extortion using Microsoft\u2019s Crypto API. Int. J. Inf. Secur. 5 2 (April 2006) 67\u201376. https:\/\/doi.org\/10.1007\/s10207-006-0082-7","DOI":"10.1007\/s10207-006-0082-7"},{"key":"e_1_3_2_47_2","first-page":"1061","volume-title":"27th USENIX Security Symposium (USENIX Security\u201918)","author":"Zhang-Kennedy Leah","year":"2018","unstructured":"Leah Zhang-Kennedy, Hala Assal, Jessica Rocheleau, Reham Mohamed, Khadija Baig, and Sonia Chiasson. 2018. The aftermath of a crypto-ransomware attack at a large academic institution. In 27th USENIX Security Symposium (USENIX Security\u201918). 1061\u20131078."}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3606022","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3606022","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:36:20Z","timestamp":1750178180000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3606022"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,20]]},"references-count":46,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2023,12,31]]}},"alternative-id":["10.1145\/3606022"],"URL":"https:\/\/doi.org\/10.1145\/3606022","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"value":"2692-1626","type":"print"},{"value":"2576-5337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,10,20]]},"assertion":[{"value":"2022-01-28","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-06-08","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-10-20","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}