Seamlessly Safeguarding Data Against Ransomware Attacks

Seamlessly Safeguarding Data Against Ransomware Attacks
复制标题

DOI:
10.1109/tdsc.2022.3214781
复制
发表时间:
2023-01
影响因子:
7.3
通讯作者:
Abdulrahman Abu Elkhail;Nada Lachtar;Duha Ibdah;Rustam Aslam;Hamza Khan;Anys Bacha;Hafiz Malik
Abdulrahman Abu Elkhail;Nada Lachtar;Duha Ibdah;Rustam Aslam;Hamza Khan;Anys Bacha;Hafiz Malik
中科院分区:
计算机科学2区
文献类型:
--
作者:
Abdulrahman Abu Elkhail;Nada Lachtar;Duha Ibdah;Rustam Aslam;Hamza Khan;Anys Bacha;Hafiz Malik

文献摘要

被引文献

相似文献

加密已成为保护机密性不可或缺的技术。不幸的是,网络犯罪分子重新利用了这项技术来拒绝用户访问其数据。这一趋势引发了勒索软件攻击的猛烈攻击,导致数名受害者被勒索支付赎金,以换取恢复其恶意加密的数据。为了应对这些挑战,我们提出了一种新颖的运行时解决方案,可以无缝防御加密勒索软件。这项工作的一个关键观察是,恶意加密的数据最初缓冲在操作系统的页面缓存中,然后再刷新到底层存储设备。基于这一观察,我们开发了一种解决方案,可以有效管理内存和存储子系统之间的数据同步,以防止恶意加密的数据永久提交到底层存储。我们针对一千多个勒索软件样本广泛验证了这种方法的稳健性,并表明我们的设计可以可靠地恢复所有加密文件。此外,我们的解决方案能够抵御采用主引导记录感染和多线程攻击等技术的勒索软件。最后,对我们的概念验证实施的评估表明,在混合运行计算和 I/O 密集型应用程序时,性能影响极小。
Encryption has become an indispensable technology for preserving confidentiality. Unfortunately, cybercriminals have re-purposed this technology to deny users access to their data. This trend has sparked an onslaught of ransomware attacks, that resulted in several victims being extorted to pay ransoms in return for restoring their maliciously encrypted data. In response to these challenges, we propose a novel runtime solution that seamlessly defends against cryptographic ransomware. A key observation made by this work is that maliciously encrypted data is initially buffered in the OS's page cache before it is flushed to the underlying storage device. Based on this observation, we develop a solution that efficiently manages data synchronization between the memory and storage subsystems to prevent maliciously encrypted data from being permanently committed to the underlying storage. We extensively validate the robustness of this approach against more than one thousand ransomware samples and show that our design reliably restores all encrypted files. Furthermore, our solution is resilient to ransomware that employ techniques including master boot record infection and multi-threaded attacks. Finally, an evaluation of our proof-of-concept implementation shows minimal performance impact while running a mix of compute and I/O bound applications.