Preventing Disruption of System Backup against Ransomware Attacks
Yiwei Hou, Lihua Guo, Chijin Zhou, Quan Zhang, Wenhuan Liu, Chengnian Sun, Yu Jiang
Abstract
The ransomware threat to the software ecosystem has grown rapidly in recent years. Despite being wellstudied, new ransomware variants continually emerge, designed to evade existing encryption-based detection mechanisms. This paper introduces Remembrall, a new perspective to defend against ransomware by monitoring and preventing system backup disruptions. Focusing on deletion actions of volume shadow copies (VSC) in Windows, Remembrall captures related malicious events and identifies all ransomware traces as a real-time defense tool. To ensure no ransomware is missing, we conduct a comprehensive investigation to classify all potential attack actions that can be used to delete VSCs throughout the application layer, OS layer, and hardware layer. Based on the analysis, Remembrall is designed to retrieve system event information and accurately identify ransomware without false negatives. We evaluate Remembrall on recent ransomware samples. Remembrall achieves 4.31%-87.55% increase in F1-score compared to other state-of-the-art antiransomware tools across 60 ransomware families. Remembrall has also detected eight zero-day ransomware samples in the experiment. CCS Concepts: • Security and privacy → Software and application security; Malware and its mitigation; • Software and its engineering → Software functional properties.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5852bab7-11da-4ab7-8d3e-4c3f4a1e8c71Builds on9
- The Circle Of Life: A Large-Scale Study of The IoT Malware LifecycleOmar Alrawi, Charles Lever, Kevin Valakuzhy, Ryan Court et al.USENIX Security 2021 · 109 citations
- FlashGuard: Leveraging Intrinsic Flash Properties to Defend Against Encryption RansomwareJian Huang, Jun Xu, Xinyu Xing, Peng Liu et al.CCS 2017 · 94 citations
- RSSD: defend against ransomware with hardware-isolated network-storage codesign and post-attack analysisBenjamin Reidys, Peng Liu, Jian HuangASPLOS 2022 · 28 citations
- Travelling the Hypervisor and SSD: A Tag-Based Approach Against Crypto Ransomware with Fine-Grained Data RecoveryBoyang Ma, Yilin Yang, Jinku Li, Fengwei Zhang et al.CCS 2023 · 10 citations
- An Empirical Study of Data Disruption by Ransomware AttacksYiwei Hou, Lihua Guo, Chijin Zhou, Yiwen Xu et al.ICSE 2024 · 10 citations
Related papers
- Ransomware Detection through Temporal Correlation between Encryption and I/O BehaviorLihua Guo, Yiwei Hou, Chijin Zhou, Quan Zhang et al.FSE 2025
- CanCal: Towards Real-time and Lightweight Ransomware Detection and Response in Industrial EnvironmentsShenao Wang, Feng Dong, Hangfeng Yang, Jingheng Xu et al.CCS 2024 · 10 citations
- UNVEIL: A Large-Scale, Automated Approach to Detecting RansomwareAmin Kharraz, Sajjad Arshad, Collin Mulliner, William K. Robertson et al.USENIX Security 2016
- ERW-Radar: An Adaptive Detection System against Evasive Ransomware by Contextual Behavior Detection and Fine-grained Content AnalysisLingbo Zhao, Yuhui Zhang, Zhilu Wang, Fengkai Yuan et al.NDSS 2025
- Detecting Ransomware Despite I/O Overhead: A Practical Multi-Staged ApproachChristian van Sloun, Vincent Woeste, Konrad Wolsing, Jan Pennekamp et al.NDSS 2025
