arXiv:2502.04421cs.CRcs.AI2025-02被引 1

基于受害者数据预测哪类勒索软件最可能攻击你,提前防御。

Assessing and Prioritizing Ransomware Risk Based on Historical Victim Data

  • 用大模型分析勒索软件公告,构建攻击者能力画像
  • 结合真实受害者数据,预测特定组织被攻击概率
  • 适合安全团队用于优先应对高风险勒索软件威胁

我们提出一种方法,识别哪些勒索软件团伙最可能针对特定实体,帮助其制定更有效的防护策略。勒索软件以牟利为目的,攻击频繁且公开施压,2023年约三分之二的组织遭遇过攻击。本研究利用受害者公开披露信息,通过大型语言模型(LLM)结合链式思维与多示例提示,从勒索软件公告、威胁报告和新闻中提取攻击者SKRAM(技能、知识、资源、权限、动机)特征。分析融合公开受害者数据,并引入启发式合成数据生成机制以增强代表性。最终构建机器学习模型,根据攻击者战术、技术与程序(TTP),协助组织优先应对最可能的勒索软件威胁并制定防御措施。

原文摘要 · Abstract (English)

We present an approach to identifying which ransomware adversaries are most likely to target specific entities, thereby assisting these entities in formulating better protection strategies. Ransomware poses a formidable cybersecurity threat characterized by profit-driven motives, a complex underlying economy supporting criminal syndicates, and the overt nature of its attacks. This type of malware has consistently ranked among the most prevalent, with a rapid escalation in activity observed. Recent estimates indicate that approximately two-thirds of organizations experienced ransomware attacks in 2023 \cite{Sophos2023Ransomware}. A central tactic in ransomware campaigns is publicizing attacks to coerce victims into paying ransoms. Our study utilizes public disclosures from ransomware victims to predict the likelihood of an entity being targeted by a specific ransomware variant. We employ a Large Language Model (LLM) architecture that uses a unique chain-of-thought, multi-shot prompt methodology to define adversary SKRAM (Skills, Knowledge, Resources, Authorities, and Motivation) profiles from ransomware bulletins, threat reports, and news items. This analysis is enriched with publicly available victim data and is further enhanced by a heuristic for generating synthetic data that reflects victim profiles. Our work culminates in the development of a machine learning model that assists organizations in prioritizing ransomware threats and formulating defenses based on the tactics, techniques, and procedures (TTP) of the most likely attackers.

勒索软件威胁情报LLM应用风险预测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。