Ransom Access Memories: Achieving Practical Ransomware Protection in Cloud with DeftPunk

Authors: 

Zhongyu Wang, Yaheng Song, Erci Xu, Haonan Wu, Guangxun Tong, Shizhuo Sun, Haoran Li, Jincheng Liu, Lijun Ding, Rong Liu, Jiaji Zhu, and Jiesheng Wu, Alibaba Group

Abstract: 

In this paper, we focus on building a ransomware detection and recovery system for cloud block stores. We start by discussing the possibility of directly using existing methods or porting one to our scenario with modifications. These attempts, though failed, led us to identify the unique IO characteristics of ransomware, and further drove us to build DeftPunk, a block-level ransomware detection and recovery system. DeftPunk uses a two-layer classifier for fast and accurate detection, creates pre-/post-attack snapshots to avoid data loss, and leverages log-structured support for low overhead recovery. Our large-scale benchmark shows that DeftPunk can achieve nearly 100% recall across 13 types of ransomware and low runtime overhead.

OSDI '24 Open Access Sponsored by
King Abdullah University of Science and Technology (KAUST)

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX
@inproceedings {298738,
author = {Zhongyu Wang and Yaheng Song and Erci Xu and Haonan Wu and Guangxun Tong and Shizhuo Sun and Haoran Li and Jincheng Liu and Lijun Ding and Rong Liu and Jiaji Zhu and Jiesheng Wu},
title = {Ransom Access Memories: Achieving Practical Ransomware Protection in Cloud with {DeftPunk}},
booktitle = {18th USENIX Symposium on Operating Systems Design and Implementation (OSDI 24)},
year = {2024},
isbn = {978-1-939133-40-3},
address = {Santa Clara, CA},
pages = {687--702},
url = {https://www.usenix.org/conference/osdi24/presentation/wang-zhongyu},
publisher = {USENIX Association},
month = jul
}

Presentation Video