FlashGuard: Leveraging Intrinsic Flash Properties to Defend Against Encryption Ransomware
Jian Huang, Jun Xu, Xinyu Xing, Peng Liu, Moinuddin K. Qureshi
Abstract
Encryption ransomware is a malicious software that stealthily encrypts user files and demands a ransom to provide access to these files. Several prior studies have developed systems to detect ransomware by monitoring the activities that typically occur during a ransomware attack. Unfortunately, by the time the ransomware is detected, some files already undergo encryption and the user is still required to pay a ransom to access those files. Furthermore, ransomware variants can obtain kernel privilege, which allows them to terminate software-based defense systems, such as anti-virus. While periodic backups have been explored as a means to mitigate ransomware, such backups incur storage overheads and are still vulnerable as ransomware can obtain kernel privilege to stop or destroy backups. Ideally, we would like to defend against ransomware without relying on software-based solutions and without incurring the storage overheads of backups. To that end, this paper proposes FlashGuard, a ransomware tolerant Solid State Drive (SSD) which has a firmware-level recovery system that allows quick and effective recovery from encryption ransomware without relying on explicit backups. FlashGuard leverages the observation that the existing SSD already performs out-of-place writes in order to mitigate the long erase latency of flash memories. Therefore, when a page is updated or deleted, the older copy of that page is anyway present in the SSD. FlashGuard slightly modifies the garbage collection mechanism of the SSD to retain the copies of the data encrypted by ransomware and ensure effective data recovery. Our experiments with 1,447 manually labeled ransomware samples show that FlashGuard can efficiently restore files encrypted by ransomware. In addition, we demonstrate that FlashGuard has a negligible impact on the performance and lifetime of the SSD.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4e11578a-4f99-4a57-a6ff-ee7bdfce7c37Cited by top-tier papers9
- TEE-aided Write Protection Against Privileged Data TamperingLianying Zhao, Mohammad MannanNDSS 2019 · 17 citations
- Travelling the Hypervisor and SSD: A Tag-Based Approach Against Crypto Ransomware with Fine-Grained Data RecoveryBoyang Ma, Yilin Yang, Jinku Li, Fengwei Zhang et al.CCS 2023 · 10 citations
- An Empirical Study of Data Disruption by Ransomware AttacksYiwei Hou, Lihua Guo, Chijin Zhou, Yiwen Xu et al.ICSE 2024 · 10 citations
- Ransom Access Memories: Achieving Practical Ransomware Protection in Cloud with DeftPunkZhongyu Wang, Yaheng Song, Erci Xu, Haonan Wu et al.OSDI 2024 · 10 citations
- Preventing Disruption of System Backup against Ransomware AttacksYiwei Hou, Lihua Guo, Chijin Zhou, Quan Zhang et al.ISSTA 2025 · 1 citation
Builds on2
- Cryptographic Function Detection in Obfuscated Binaries via Bit-Precise Symbolic Loop MappingDongpeng Xu, Jiang Ming, Dinghao WuS&P 2017 · 83 citations
- UNVEIL: A Large-Scale, Automated Approach to Detecting RansomwareAmin Kharraz, Sajjad Arshad, Collin Mulliner, William K. Robertson et al.USENIX Security 2016
Related papers
- RSSD: defend against ransomware with hardware-isolated network-storage codesign and post-attack analysisBenjamin Reidys, Peng Liu, Jian HuangASPLOS 2022 · 28 citations
- Ransomware Detection through Temporal Correlation between Encryption and I/O BehaviorLihua Guo, Yiwei Hou, Chijin Zhou, Quan Zhang et al.FSE 2025
- ERW-Radar: An Adaptive Detection System against Evasive Ransomware by Contextual Behavior Detection and Fine-grained Content AnalysisLingbo Zhao, Yuhui Zhang, Zhilu Wang, Fengkai Yuan et al.NDSS 2025
- GuardedErase: Extending SSD Lifetimes by Protecting Weak WordlinesDuwon Hong, Myungsuk Kim, Geonhee Cho, Dusol Lee et al.FAST 2022 · 28 citations
- Limits of I/O Based Ransomware Detection: An Imitation Based AttackChijin Zhou, Lihua Guo, Yiwei Hou, Zhenya Ma et al.S&P 2023
