Bending the Curve: Operational Cyber Epidemiology for Ransomware

📅 2026-07-31
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the critical gap in existing ransomware response strategies, which predominantly emphasize detection while overlooking the epidemic-like lateral propagation dynamics that lead to delayed interventions. To bridge this gap, the work introduces a network epidemiology framework grounded in the SEIR model, explicitly defining exposed and infected states. It integrates interoperable case definitions and an information ontology aligned with emergency response standards such as ISO/IEC 5477:2023, and employs the basic and effective reproduction numbers (R₀ and Re) as near real-time decision metrics to decouple observed telemetry from true propagation states. This approach establishes a common language linking technical telemetry to containment decisions under resource constraints, proposing a universal Re < 1 protection threshold and tool-agnostic response playbooks. Validation against real-world incidents like WannaCry and NotPetya demonstrates significantly enhanced capabilities for security operations centers to perform early isolation, credential control, and recovery prioritization under partial observability.
📝 Abstract
Ransomware is often treated as a detection problem, but the most disruptive incidents behave more like outbreaks. A single foothold can spread through identities, administrative tools, and shared services while responders make time-critical decisions with incomplete visibility. This paper presents an operational cyber epidemiology framework that adapts the Susceptible-Exposed-Infectious-Removed (SEIR) model to ransomware incident management. In this ontology, Exposed denotes latent compromise and staging, including the dwell period before confirmed secondary compromise, while Infectious denotes active lateral propagation. Drawing on ISO 5477:2023 guidance for public health emergency preparedness and response information management and the 2025 UNDRR-ISC Hazard Information Profiles, the framework defines interoperable ransomware case definitions and Essential Elements of Information for cross-incident comparison. Basic and effective reproduction numbers, R0 and Re, are used as directional, near-real-time decision aids for security operations centers. Propagation state is separated from observation status to avoid confusing spread dynamics with detection capability. Publicly reported incidents, including WannaCry, NotPetya, SolarWinds, and MGM and Caesars, illustrate how outbreak-style measures can support earlier isolation, credential containment, and restoration sequencing. The paper also derives practical protection-threshold heuristics aimed at reducing Re below 1 and provides a tool-agnostic playbook card linking operational information to explicit action triggers. The primary contribution is a shared language that connects technical telemetry to containment decisions under resource constraints.
Problem

Research questions and friction points this paper is trying to address.

ransomware
cyber epidemiology
incident response
lateral propagation
containment decision
Innovation

Methods, ideas, or system contributions that make the work stand out.

cyber epidemiology
SEIR model
ransomware incident response
effective reproduction number
operational playbook
🔎 Similar Papers
No similar papers found.
S
Stephen V Flowerday
School of Computer and Cyber Sciences, Augusta University
N
Nikolay Lipskiy
Center for Applied Medical AI (CAMA), Atlanta, GA, US
Steven Furnell
Steven Furnell
University of Nottingham
Cyber SecurityInformation SecurityIT SecurityComputer Security
C
Callum E Flowerday
Department of Chemistry and Biochemistry, Brigham Young University, US
John Hale
John Hale
University of Tulsa
Information securitybiomedical informatics