Analysis of Decoy Strategies for Detecting Ransomware
Byron Denham, Dale R. Thompson · 2023
As the capabilities of malware threats evolve, defense methods must evolve accordingly. The increasing use of polymorphism in malware makes signature-based prevention techniques much less likely to be effective and the ability to make malware that accomplishes its goals in a unique fashion makes traditional behavioral analysis difficult. Amongst malware, the threat posed by ransomware is one of the most unique and difficult challenges in cybersecurity today. Malware defense is typically divided into prevention, detection, mitigation, and recovery. Because it uses modern encryption techniques to leverage the victim into paying a ransom, recovery from ransomware is extremely difficult if not impossible. Along with this, ransomware does not have a specific method of infection that is broadly used, meaning that there is no prevention method that works specifically for ransomware. Because of this, detection and subsequent mitigation are particularly important in ransomware defense. There are many approaches that can be taken to the detection of ransomware. One newer example of this that is starting to gain some attention is using decoys placed throughout the filesystem. Currently, there exists a discussion of the generation of these decoy files, as well as several solutions that use this detection technique. However, the existing body of work on decoy-based deception focuses primarily on creating algorithms that generate the optimal placement of decoys while assuming other traits regarding the decoys should be static. Specifically, most prior works on decoy-based detection of ransomware assume that the decoy objects are files that are being monitored for write access. This paper presents an evaluation on the best type of filesystem object to be used as a decoy, as well as the best way to monitor the decoy for the detection of ransomware.