Fight Virus Like a Virus: A New Defense Method Against File-Encrypting Ransomware
Joshua Morris, Dan Lin, Marcellus Smith

TL;DR
This paper introduces a novel ransomware defense mechanism that uses data streams to mislead ransomware, allowing data recovery and attack mitigation on Windows systems.
Contribution
A new ransomware defense method leveraging Alternative Data Streams to deceive ransomware into attacking non-essential file parts.
Findings
Effective against various ransomware types
Demonstrates usability and efficiency
Successfully mitigates ransomware attacks
Abstract
Nowadays ransomware has become a new profitable form of attack. This type of malware acts as a form of extortion which encrypts the files in a victim's computer and forces the victim to pay the ransom to have the data recovered. Even companies and tech savvy people must use extensive resources to maintain backups for recovery or else they will lose valuable data, not mentioning average users. Unfortunately, not any recovery tool can effectively defend various types of ransomware. To address this challenge, we propose a novel ransomware defense mechanism that can be easily deployed in modern Windows system to recover the data and mitigate a ransomware attack. The uniqueness of our approach is to fight the virus like a virus. We leverage Alternative Data Streams which are sometimes used by malicious applications, to develop a data protection method that misleads the ransomware to attack…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Network Security and Intrusion Detection · Security and Verification in Computing
