View : 360 Download: 0

SSD-Assisted Ransomware Detection and Data Recovery Techniques

Title
SSD-Assisted Ransomware Detection and Data Recovery Techniques
Authors
Baek, SunghaJung, YoungdonMohaisen, DavidLee, SungjinNyang, Daehun
Ewha Authors
양대헌
SCOPUS Author ID
양대헌scopus
Issue Date
2021
Journal Title
IEEE TRANSACTIONS ON COMPUTERS
ISSN
0018-9340JCR Link

1557-9956JCR Link
Citation
IEEE TRANSACTIONS ON COMPUTERS vol. 70, no. 10, pp. 1762 - 1776
Keywords
Ransomwaremalware detectiondata recoveryflash-based SSDs
Publisher
IEEE COMPUTER SOC
Indexed
SCIE; SCOPUS WOS scopus
Document Type
Article
Abstract
As ransomware attacks have been prevalent, it becomes crucial to make anti-ransomware solutions that defend against ransomwares. In this article, we propose a new ransomware defense system, called SSD-Insider++, which prevents users' files from being damaged by ransomware attacks. SSD-Insider++ is embedded into an SSD controller as a form of firmware. By being separated from a host machine, it not only provides more robust data protection than software-based ones which are vulnerable to evasion attacks, but also offers interoperability with various platforms. SSD-Insider++ is composed of two novel features, ransomware detection and perfect data recovery, which are tightly integrated with each other. The detection algorithm observes I/O patterns of a host system and decides whether the host is being attacked by ransomwares in an early stage. Once an encryption attack is detected, the recovery algorithm is triggered to recover original files by leveraging a delayed deletion feature of an SSD at a low cost. Our experimental results show that SSD-Insider++ achieves high accuracy of detecting ransomwares with 0 percent FRR/FAR in most cases and provides an instant data recovery with 0 percent data loss. The overhead of running SSD-Insider++ is negligible - only 80 ns and 226 ns are spent more for handling 4-KB reads and writes, respectively.
DOI
10.1109/TC.2020.3011214
Appears in Collections:
인공지능대학 > 사이버보안학과 > Journal papers
Files in This Item:
There are no files associated with this item.
Export
RIS (EndNote)
XLS (Excel)
XML


qrcode

BROWSE