Return
The organizational anatomy of cybercrime: a multilayer framework for modeling resilience
D
C
L
DOI:10.1093/cybsec/tyag014.png)
Abstract
En 中文
Online crime has evolved from attention-seeking individuals to organized criminal enterprises. Recognizing this fact, we offer a timely application of organizational science to better illuminate modern cybercrime groups. Drawing upon multiple theories, we propose a framework for the resilience of cybercrime entities or Cybercrime-as-a-Service (CaaS), treating them as organizations rather than gangs, forums, or communities. We argue that CaaS groups should be viewed as conventional, commodity-based businesses, and invite scholars to adopt our proposed framework of resilience for studying the organizational systems of CaaS. In particular, we suggest examining cybercrime in five key organizational factors: structure, specialization, shared goals, rules and norms, and relationships We also argue that such factors support the resilience of cybercrime organizations across functional, operational, and strategic dimensions. We introduce the framework and describe its applicability to cybercrime research more broadly, reviewing literature from computer security, criminology, and cybersecurity reports. We present an application of this framework to a long-lived and resilient ransomware operator, Conti, using information from their leaked internal communications and documentation and applying computational methods for quantifying and measuring organizational dimensions. Additionally, we detail the framework with a modeling methodology that integrates network science, organizational theory, and discourse analysis, with a focus on online textual communications—often accessible to security researchers through collaborations with law enforcement or obtained via infiltration of such groups (e.g. Conti, BlackBasta, and LockBit). Specifically, we propose to model a group as a multidimensional social graph, where members’ relationships and roles are derived through systematic discourse analysis based on linguistic analysis and speech acts. We conclude that the current approach to cybercrime as a craft or art can be moved to a more systematic basis with the application of the proposed framework.
Journal
J
IF:
3.2
Papers:
52
Citations:
0
