Fight Virus Like a Virus: A New Defense Method Against File-Encrypting Ransomware

03/19/2021
by   Joshua Morris, et al.
0

Nowadays ransomware has become a new profitable form of attack. This type of malware acts as a form of extortion which encrypts the files in a victim's computer and forces the victim to pay the ransom to have the data recovered. Even companies and tech savvy people must use extensive resources to maintain backups for recovery or else they will lose valuable data, not mentioning average users. Unfortunately, not any recovery tool can effectively defend various types of ransomware. To address this challenge, we propose a novel ransomware defense mechanism that can be easily deployed in modern Windows system to recover the data and mitigate a ransomware attack. The uniqueness of our approach is to fight the virus like a virus. We leverage Alternative Data Streams which are sometimes used by malicious applications, to develop a data protection method that misleads the ransomware to attack only file 'shells' instead of the actual file content. We evaluated different file encrypting ransomware and demonstrate usability, efficiency and effectiveness of our approach.

READ FULL TEXT

page 1

page 6

page 7

research
07/26/2023

Open Image Content Disarm And Reconstruction

With the advance in malware technology, attackers create new ways to hid...
research
06/27/2023

MTFS: a Moving Target Defense-Enabled File System for Malware Mitigation

Ransomware has remained one of the most notorious threats in the cyberse...
research
02/21/2021

A Ransomware Classification Framework Based on File-Deletion and File-Encryption Attack Structures

Ransomware has emerged as an infamous malware that has not escaped a lot...
research
04/23/2018

Forensic Analysis of the exFAT artefacts

Although keeping some basic concepts inherited from FAT32, the exFAT fil...
research
09/25/2022

Scrapbook: Screenshot-Based Bookmarks for Effective Digital Resource Curation across Applications

Modern knowledge workers typically need to use multiple resources, such ...
research
06/28/2021

Differential Area Analysis for Ransomware Attack Detection within Mixed File Datasets

The threat from ransomware continues to grow both in the number of affec...
research
01/20/2022

NapierOne: A modern mixed file data set alternative to Govdocs1

It was found when reviewing the ransomware detection research literature...

Please sign up or login with your details

Forgot password? Click here to reset