Proactive Damage Prevention from Zero-Day Ransomwares

Hiroshi Fujinoki, Lasya Manukonda · 2023

As most of the existing crypto ransomwares being computer viruses, detecting zero-day ransomwares before they cause any damage is hard while any malicious encryption of production data is fatal especially to those who rely on their computer systems for their commercial uses. We propose a proactive solution (PDPZR) that does not depend on prior detections. Instead, our solution eliminates the risks from zero-day crypto ransomwares using a backup-based approach. Our contributions in this work are two-fold. We first identified the two essential requirements for backup-based solutions to be safe and effective: (1) immediate backup for every update to production data and (2) an algorithm to truncate unnecessary good old backup copies, which is not an easy task where attackers possibly use “data obfuscation” to avoid detections. We assess the potential of the proposed solution using simulation experiments. Our simulation experiments show that PDPZR will eliminate the risk of damages especially from zero-day ransomwares while it keeps the length of a backup list under control. We observed that PDPZR reduced the length of a backup list by more than 50% in a heavy update load, while we observed that the list length grew in linear. Under heavy updates, different protection scrums kicked in at different phases in the amount of updates to dynamically and adaptively prevent uncontrolled increases in the length of a backup list. These results suggest that PDPZR will be a safe and effective proactive damage prevention from zero-day ransomwares.

Read the paper · More papers on PaperTik