Nowadays ransomware has become a new profitable form of attack. This type of malware acts as a form of extortion which encrypts the files in a victim's computer and forces the victim to pay the ransom to have the data recovered. Even companies and tech savvy people must use extensive resources to maintain backups for recovery or else they will lose valuable data, not mentioning average users. Unfortunately, not any recovery tool can effectively defend various types of ransomware. To address this challenge, we propose a novel ransomware defense mechanism that can be easily deployed in modern Windows system to recover the data and mitigate a ransomware attack. The uniqueness of our approach is to fight the virus like a virus. We leverage Alternative Data Streams which are sometimes used by malicious applications, to develop a data protection method that misleads the ransomware to attack only file 'shells' instead of the actual file content. We evaluated different file encrypting ransomware and demonstrate usability, efficiency and effectiveness of our approach.
翻译:现在,赎金软件已成为一种新的有利可图的攻击形式。这种恶意软件作为一种敲诈形式,将文件加密在受害人的计算机中,迫使受害人支付赎金以收回数据。即使是公司和技术专家,他们也必须使用大量资源来维持恢复备份,否则他们就会丢失有价值的数据,而不提及普通用户。不幸的是,任何回收工具都无法有效保护各种类型的赎金软件。为了应对这一挑战,我们提议了一个新的赎金软件防御机制,可以很容易地在现代的Windows系统中安装,以恢复数据并减轻赎金软件袭击。我们的方法的独特性是像病毒一样抗击病毒。我们利用有时被恶意应用的替代数据流,开发一种数据保护方法,误导赎金软件只输入“壳牌”而不是实际文件内容。我们评估了不同的文件加密赎金软件,并展示了我们方法的可用性、效率和有效性。