GuardFS: a File System for Integrated Detection and Mitigation of Linux-based Ransomware

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: von der Assen, Jan, Feng, Chao, Celdrán, Alberto Huertas, Oleš, Róbert, Bovet, Gérôme, Stiller, Burkhard
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866913217229357056
author von der Assen, Jan
Feng, Chao
Celdrán, Alberto Huertas
Oleš, Róbert
Bovet, Gérôme
Stiller, Burkhard
author_facet von der Assen, Jan
Feng, Chao
Celdrán, Alberto Huertas
Oleš, Róbert
Bovet, Gérôme
Stiller, Burkhard
contents Although ransomware has received broad attention in media and research, this evolving threat vector still poses a systematic threat. Related literature has explored their detection using various approaches leveraging Machine and Deep Learning. While these approaches are effective in detecting malware, they do not answer how to use this intelligence to protect against threats, raising concerns about their applicability in a hostile environment. Solutions that focus on mitigation rarely explore how to prevent and not just alert or halt its execution, especially when considering Linux-based samples. This paper presents GuardFS, a file system-based approach to investigate the integration of detection and mitigation of ransomware. Using a bespoke overlay file system, data is extracted before files are accessed. Models trained on this data are used by three novel defense configurations that obfuscate, delay, or track access to the file system. The experiments on GuardFS test the configurations in a reactive setting. The results demonstrate that although data loss cannot be completely prevented, it can be significantly reduced. Usability and performance analysis demonstrate that the defense effectiveness of the configurations relates to their impact on resource consumption and usability.
format Preprint
id arxiv_https___arxiv_org_abs_2401_17917
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle GuardFS: a File System for Integrated Detection and Mitigation of Linux-based Ransomware
von der Assen, Jan
Feng, Chao
Celdrán, Alberto Huertas
Oleš, Róbert
Bovet, Gérôme
Stiller, Burkhard
Cryptography and Security
Although ransomware has received broad attention in media and research, this evolving threat vector still poses a systematic threat. Related literature has explored their detection using various approaches leveraging Machine and Deep Learning. While these approaches are effective in detecting malware, they do not answer how to use this intelligence to protect against threats, raising concerns about their applicability in a hostile environment. Solutions that focus on mitigation rarely explore how to prevent and not just alert or halt its execution, especially when considering Linux-based samples. This paper presents GuardFS, a file system-based approach to investigate the integration of detection and mitigation of ransomware. Using a bespoke overlay file system, data is extracted before files are accessed. Models trained on this data are used by three novel defense configurations that obfuscate, delay, or track access to the file system. The experiments on GuardFS test the configurations in a reactive setting. The results demonstrate that although data loss cannot be completely prevented, it can be significantly reduced. Usability and performance analysis demonstrate that the defense effectiveness of the configurations relates to their impact on resource consumption and usability.
title GuardFS: a File System for Integrated Detection and Mitigation of Linux-based Ransomware
topic Cryptography and Security
url https://arxiv.org/abs/2401.17917