arrow
返回

Shared file protection against unauthorised encryption using a Buffer-Based Signature Verification Method

delete2024-11-01
delete0
delete
OA
AI
A
Arash Mahboubi *
S
Seyit Camtepe
K
Keyvan Ansari
M
Marcin Pawłowski
P
Paweł Morawiecki
H
Hamed Aboutorab
J
Josef Pieprzyk
J
Jarek Duda
DOI:10.1016/j.jisa.2024.103873delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Understanding the attributes of critical data and implementing suitable security measures help organisations bolster their data-protection strategies and diminish the potential impacts of ransomware incidents. Unauthorised extraction and acquisition of data are the principal objectives of most cyber invasions. We underscore the severity of this issue using a recent attack by the Clop ransomware group, which exploited the MOVEit Transfer vulnerability and bypassed network-detection mechanisms to exfiltrate data via a Command and Control server. As a countermeasure, we propose a method called Buffer-Based Signature Verification (BBSV). This approach involves embedding 32-byte tags into files prior to their storage in the cloud, thus offering enhanced data protection. The BBSV method can be integrated into software like MOVEit Secure Managed File Transfer, thereby thwarting attempts by ransomware to exfiltrate data. Empirically tested using a BBSV prototype, our approach was able to successfully halt the encryption process for 80 ransomware instances from 70 ransomware families. BBSV not only stops the encryption but also prevents data exfiltration when data are moved or written from the original location by adversaries. We further develop a hypothetical exploit scenario in which an adversary manages to bypass the BBSV, illicitly transmits data to a Command and Control server, and then removes files from the original location. We construct an extended state space, in which each state represents a tuple that integrates user authentication and system components at the filesystem level.
Keyword:
Ransomware
Data encryption
Signature embedding
Storage-level signature validation
Trusted Platform Module
Coloured Petri net
Data protection
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Journal of Information Security and Applications 封面图
Journal of Information Security and Applications
IF:
3.7
论文数:
1.9K
被引数:
4.9K

机构

P
Polish Academy of Sciences
学者数:
3.0W
论文数: 3.1W
被引数: 3.1W
J
jagiellonian university
学者数:
2.3W
论文数: 1.8W
被引数: 11
C
Charles Sturt University
学者数:
3.6K
论文数: 3.4K
被引数: 4.0K
C
M
Murdoch University
学者数:
5.3K
论文数: 5.4K
被引数: 8.4K
学者 查看更多机构
引用论文

引用论文

A Survey on Ransomware: Evolution, Taxonomy, and Defense Solutions
err2022-09-09
err84
errOAAI
errOz, Harun; Aris, Ahmet; Levi, Albert; Uluagac, A. Selcuk
err分享
err收藏
Ransomware detection based on machine learning using memory features
err2024-03-01
err4
errOAAI
errAljabri, Malak; Alhaidari, Fahd; Albuainain, Aminah; Alrashidi, Samiyah; Alansari, Jana; Alqahtani, Wasmiyah; Alshaya, Jana
err分享
err收藏
err分享
err收藏
Decentralized Threshold Signatures With Dynamically Private Accountability
err2024-01-01
err4
errOAAI
errLi, Meng; Ding, Hanni; Wang, Qing; Zhang, Mingwei; Meng, Weizhi; Zhu, Liehuang; Zhang, Zijian; Lin, Xiaodong
err分享
err收藏
Detecting simultaneous variant intervals in aligned sequences
err2011-06-01
err0
errOAAI
errDavid Siegmund; Benjamin Yakir; Nancy R. Zhang
err分享
err收藏
Rcryptect: Real-time detection of cryptographic function in the user-space filesystem
err2022-01-01
err8
errOAAI
errLee, Seungkwang; Jho, Nam-su; Chung, Doyoung; Kang, Yousung; Kim, Myungchul
err分享
err收藏
Ransomware early detection by the analysis of file sharing traffic
err2018-12-01
err73
errOAAI
errMorato, Daniel; Berrueta, Eduardo; Magana, Eduardo; Izal, Mikel
err分享
err收藏
学者 查看更多内容