arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.29444cs.CR

扭转态势:针对勒索软件的可操作网络流行病学

Bending the Curve: Operational Cyber Epidemiology for Ransomware

Stephen V Flowerday, Nikolay Lipskiy, Steven Furnell, Callum E Flowerday, John Hale

首次发表
浏览论文内容

中文总结 AI 辅助

本文提出适配勒索软件管理的可操作网络流行病学框架,参考公共卫生标准定义案例规则与信息要素,用SEIR模型及R0/Re辅助决策,通过公开事件验证其价值,核心是建立技术数据与遏制决策的通用语言。

中文摘要 AI 辅助

勒索软件常被视为检测问题,但最具破坏性的事件更像疫情暴发:单个立足点可通过身份、管理工具和共享服务传播,而响应者在可见性不足的情况下需做出时间紧迫的决策。本文提出一种可操作网络流行病学框架,将易感-暴露-感染-移除(SEIR)模型适配勒索软件事件管理,其中“暴露”指潜伏入侵与部署阶段,含确认二次入侵前的驻留期,“感染”指主动横向传播。该框架参考ISO 5477:2023公共卫生应急准备与响应信息管理指南及2025年联合国减少灾害风险办公室-国际标准化组织(UNDRR-ISC)危害信息概况,定义可互操作的勒索软件案例定义及跨事件比较的基本信息要素;用基本再生数R0和有效再生数Re作为安全运营中心的定向近实时决策辅助工具,将传播状态与观测状态分离,避免混淆传播动态与检测能力。通过WannaCry、NotPetya、SolarWinds、MGM及凯撒娱乐(Caesars)等公开报告事件,说明疫情式措施可支持更早隔离、凭证遏制及恢复排序;本文还推导实用保护阈值启发式方法,旨在将Re降至1以下,并提供与工具无关的行动触发关联操作手册卡片。主要贡献是构建在资源约束下将技术遥测数据与遏制决策关联的通用语言。

英文摘要

Ransomware is often treated as a detection problem, but the most disruptive incidents behave more like outbreaks. A single foothold can spread through identities, administrative tools, and shared services while responders make time-critical decisions with incomplete visibility. This paper presents an operational cyber epidemiology framework that adapts the Susceptible-Exposed-Infectious-Removed (SEIR) model to ransomware incident management. In this ontology, Exposed denotes latent compromise and staging, including the dwell period before confirmed secondary compromise, while Infectious denotes active lateral propagation. Drawing on ISO 5477:2023 guidance for public health emergency preparedness and response information management and the 2025 UNDRR-ISC Hazard Information Profiles, the framework defines interoperable ransomware case definitions and Essential Elements of Information for cross-incident comparison. Basic and effective reproduction numbers, R0 and Re, are used as directional, near-real-time decision aids for security operations centers. Propagation state is separated from observation status to avoid confusing spread dynamics with detection capability. Publicly reported incidents, including WannaCry, NotPetya, SolarWinds, and MGM and Caesars, illustrate how outbreak-style measures can support earlier isolation, credential containment, and restoration sequencing. The paper also derives practical protection-threshold heuristics aimed at reducing Re below 1 and provides a tool-agnostic playbook card linking operational information to explicit action triggers. The primary contribution is a shared language that connects technical telemetry to containment decisions under resource constraints.

补充信息

↑