返回
Shared file protection against unauthorised encryption using a Buffer-Based Signature Verification Method
DOI:10.1016/j.jisa.2024.103873.png)
摘要
En 中文
Understanding the attributes of critical data and implementing suitable security measures help organisations bolster their data-protection strategies and diminish the potential impacts of ransomware incidents. Unauthorised extraction and acquisition of data are the principal objectives of most cyber invasions. We underscore the severity of this issue using a recent attack by the Clop ransomware group, which exploited the MOVEit Transfer vulnerability and bypassed network-detection mechanisms to exfiltrate data via a Command and Control server. As a countermeasure, we propose a method called Buffer-Based Signature Verification (BBSV). This approach involves embedding 32-byte tags into files prior to their storage in the cloud, thus offering enhanced data protection. The BBSV method can be integrated into software like MOVEit Secure Managed File Transfer, thereby thwarting attempts by ransomware to exfiltrate data. Empirically tested using a BBSV prototype, our approach was able to successfully halt the encryption process for 80 ransomware instances from 70 ransomware families. BBSV not only stops the encryption but also prevents data exfiltration when data are moved or written from the original location by adversaries. We further develop a hypothetical exploit scenario in which an adversary manages to bypass the BBSV, illicitly transmits data to a Command and Control server, and then removes files from the original location. We construct an extended state space, in which each state represents a tuple that integrates user authentication and system components at the filesystem level.
Keyword:
Ransomware
Data encryption
Signature embedding
Storage-level signature validation
Trusted Platform Module
Coloured Petri net
Data protection
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
3.7
论文数:
1.9K
被引数:
4.9K
机构
引用论文
Bismuth(III) coordination compounds. Synthesis, characterization, and X-ray structures of [Bi(Cl)(μ-Cl)2(THF)2]∞, Bi(O2CMe)3(Solv)x (Solv = py, x = 2 or MeIm, x = 4) [1], and [Bi(μ-OCH2CMe3)(OCH2CMe3)2(Solv)]2 (Solv = HOCH2CMe3 or py)
Polyhedron
IF0
A Study on Formal Methods to Generalize Heterogeneous Mobile Malware Propagation and Their Impacts
IEEE ACCESS
IF3.6
Safeguarding a formalized Blockchain-enabled identity-authentication protocol by applying security risk-oriented patterns
COMPUTERS & SECURITY
IF5.4
Rcryptect: Real-time detection of cryptographic function in the user-space filesystem
COMPUTERS & SECURITY
IF5.4

