Skip to main navigation Skip to search Skip to main content

Ransomware Negotiation: Dynamics and Privacy-Preserving Mechanism Design

  • Haohui Zhang
  • , Sirui Shen
  • , Xinyu Hu
  • , Chenglu Jin
  • University of Twente
  • Centrum Wiskunde & Informatica

Research output: Chapter or section in a book/report/conference proceedingChapter in a published conference proceeding

1   Link opens in a new tab Citation (SciVal)

Abstract

Ransomware attacks have become a pervasive and costly form of cybercrime, causing tens of millions of dollars in losses as organizations increasingly pay ransoms to mitigate operational disruptions and financial risks. While prior research has largely focused on proactive defenses, the post-infection negotiation dynamics between attackers and victims remains underexplored. This paper presents a formal analysis of attacker–victim interactions in modern ransomware incidents using a finite-horizon alternating-offers bargaining game model. Our analysis demonstrates how bargaining alters the optimal strategies of both parties. In practice, incomplete information—attackers lacking knowledge of victims’ data valuations and victims lacking knowledge of attackers’ reservation ransoms—can prolong negotiations and increase victims’ business interruption costs. To address this, we design a Bayesian incentive-compatible mechanism that facilitates rapid agreement on a fair ransom without requiring either party to disclose private valuations. We further implement this mechanism using secure two-party computation based on garbled circuits, thereby eliminating the need for trusted intermediaries and preserving the privacy of both parties throughout the negotiation. To the best of our knowledge, this is the first automated, privacy-preserving negotiation mechanism grounded in a formal analysis of ransomware negotiation dynamics.

Original languageEnglish
Title of host publicationGame Theory and AI for Security - 16th International Conference, GameSec 2025, Proceedings
EditorsJohn S. Baras, Symeon Papavassiliou, Eirini Eleni Tsiropoulou, Muhammed O. Sayin
PublisherSpringer Science and Business Media Deutschland GmbH
Pages235-255
Number of pages21
ISBN (Electronic)9783032080646
ISBN (Print)9783032080639
DOIs
Publication statusPublished - 12 Oct 2025
Event16th International Conference on Game Theory and AI for Security, GameSec 2025 - Athens, Greece
Duration: 13 Oct 202515 Oct 2025

Publication series

NameLecture Notes in Computer Science
Volume16223 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference16th International Conference on Game Theory and AI for Security, GameSec 2025
Country/TerritoryGreece
CityAthens
Period13/10/2515/10/25

Bibliographical note

Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Switzerland AG 2026.

UN SDGs

This output contributes to the following UN Sustainable Development Goals (SDGs)

  1. SDG 16 - Peace, Justice and Strong Institutions
    SDG 16 Peace, Justice and Strong Institutions

Fingerprint

Dive into the research topics of 'Ransomware Negotiation: Dynamics and Privacy-Preserving Mechanism Design'. Together they form a unique fingerprint.

Cite this