Real-Time Detection and Recovery Method Against Ransomware Based on Simple Format Analysis

Jae-yeol Kim · Information · 2025

Ransomware encrypts targeted files, making recovery difficult using conventional disinfection or deletion methods, unlike other types of malware. In particular, ransomware commonly encrypts important documents as a follow-up action, and existing antivirus programs are fundamentally incapable of preventing them. In this study, we analyzed 97 real-world ransomware behaviors and found that 95.88% of them involved encryption attempts. Consequently, we propose a real-time method for determining whether critical files have been compromised through encryption and for recovering them accordingly. The proposed Simple Format Analysis (SFA) detection technique consists of three methods: Simple Format Analysis–Fixed-structure-based (SFA-F), which analyzes the file format; Simple Format Analysis–Header-based (SFA-H), which focuses on file header information; and Simple Format Analysis—Fixed-structure-and-Header-based (SFA-F-H), a hybrid method that combines both. These techniques achieved detection accuracies ranging from 95.0% (SFA-F) to 97.9% (SFA-F-H), outperforming existing detection approaches. In addition, we introduce a novel real-time recovery approach known as real-time file restoration from damage, which integrates SFA detection with pre-input/output monitoring. We expect the proposed approach to significantly contribute to ransomware mitigation in cybersecurity environments.

Read the paper · More papers on PaperTik