Time Machine: An Efficient and Backend-Migratable Architecture for Defending Against Ransomware in the Hypervisor

Jian Syue Huang, Tsung Han Liu, Yi Hsien Chen, Hsuan Yu Peng, Tse Wei Huang, Chin Laung Lei, Chun Ying Huang

研究成果: Conference contribution同行評審

摘要

Ransomware has caused escalating financial losses for individuals and companies, increasing annually. To combat this, we present Time Machine, a real-time, fine-grained sector-level live view navigation solution designed to safeguard filesystems from ransomware attacks at the hypervisor level. Time Machine offers several key advancements over existing solutions. Operating at the hypervisor level minimizes the risk of bypassing via privilege escalation and eliminates reliance on hardware-based solutions. Time Machine redirects I/O operations without altering the original storage disk. Utilizing local or cloud-based key-value store backends, it offers flexible storage spaces for live view navigation and the capability of backend migration. This approach ensures comprehensive filesystem protection without data loss, allowing users to browse and recover data to any specific timestamp. Time Machine is designed to operate independently of detection algorithms but can also integrate with them for enhanced protection. Evaluation results demonstrate that our prototype effectively safeguards the filesystem with minimal overhead. With a 256MB memory cache and affordable storage, Time Machine successfully defends against 12 ransomware variants on Windows and Linux platforms, incurring an average runtime overhead of less than 5%.

原文English
主出版物標題CCSW 2024 - Proceedings of the 2024 Cloud Computing Security Workshop, Co-Located with
主出版物子標題CCS 2024
發行者Association for Computing Machinery, Inc
頁面66-79
頁數14
ISBN(電子)9798400712340
DOIs
出版狀態Published - 19 11月 2024
事件15th ACM Cloud Computing Security Workshop, CCSW 2024 - Salt Lake City, 美國
持續時間: 14 10月 202418 10月 2024

出版系列

名字CCSW 2024 - Proceedings of the 2024 Cloud Computing Security Workshop, Co-Located with: CCS 2024

Conference

Conference15th ACM Cloud Computing Security Workshop, CCSW 2024
國家/地區美國
城市Salt Lake City
期間14/10/2418/10/24

指紋

深入研究「Time Machine: An Efficient and Backend-Migratable Architecture for Defending Against Ransomware in the Hypervisor」主題。共同形成了獨特的指紋。

引用此