Heuristic approach to ransomware detection and prevention at software or hardware level

Bogomil Alexandrov, Lyubomir Gotsev, Milena Petkova, Vladimira Vladimirova Petkova · 2023

Ransomware attacks have grown to a great extent over the past few years and have attracted a lot of attention, not just because they cost a lot in both payouts and data loss, but due to the fact that the new attack vectors and improved algorithms used by any such malicious software are becoming more and more innovative. Therefore we have looked at a new and feasible way of protecting against ransomware attack at a completely different angel, without even targeting any individual ransomware family in particular, but rather detecting the misbehavior of any such software.The proposed novel approach at protecting against ransomware encryption malicious software proposes a model for a system protection driver that intercepts file system I/O operations. Any such interception is to handle file read and writes without any slowing down of the protected system, but will only interfere at file open and closes, thus minimizing any real-time overhead compared to most other systems that implement real-time protection against malware and more specifically ransomware. The proposed model relies on a look-up table of predefined meta data types for the various file extensions and monitor any such changes, which are not supposed to occur under normal circumstances of everyday use of workstations or servers. Any such detected activity of a tampered specific meta data of any file is to be considered an act of a malicious software, which could be further quarantined to prevent any further damage. Using a caching control mechanism with no additional overhead whatsoever will allow the restoration of any data that an attempt on to corrupt it has been made.

Read the paper · More papers on PaperTik