Travelling the Hypervisor and SSD: A Tag-Based Approach Against Crypto Ransomware with Fine-Grained Data Recovery
Boyang Ma, Yilin Yang, Jinku Li, Fengwei Zhang, Wenbo Shen, Yajin Zhou, Jianfeng Ma
Abstract
Ransomware has evolved from an economic nuisance to a national security threat nowadays, which poses a significant risk to users. To address this problem, we propose RansomTag, a tag-based approach against crypto ransomware with fine-grained data recovery. Compared to state-of-the-art SSD-based solutions, RansomTag makes progress in three aspects. First, it decouples the ransomware detection functionality from the firmware of the SSD and integrates it into a lightweight hypervisor of Type I. Thus, it can leverage the powerful computing capability of the host system and the rich context information, which is introspected from the operating system, to achieve accurate detection of ransomware attacks and defense against potential targeted attacks on SSD characteristics. Further, RansomTag is readily deployed onto desktop personal computers due to its parapass-through architecture. Second, RansomTag bridges the semantic gap between the hypervisor and the SSD through the tag-based approach proposed by us. Third, RansomTag is able to keep 100% of the user data overwritten or deleted by ransomware, and restore any single or multiple user files to any versions based on timestamps. To validate our approach, we implement a prototype of RansomTag and collect 3,123 recent ransomware samples to evaluate it. The evaluation results show that our prototype effectively protects user data with minimal scale data backup and acceptable performance overhead. In addition, all the attacked files can be completely restored in fine-grained.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 76e828db-41c0-41de-b254-0e1564571877Cited by top-tier papers5
- An Empirical Study of Data Disruption by Ransomware AttacksYiwei Hou, Lihua Guo, Chijin Zhou, Yiwen Xu et al.ICSE 2024 · 10 citations
- CanCal: Towards Real-time and Lightweight Ransomware Detection and Response in Industrial EnvironmentsShenao Wang, Feng Dong, Hangfeng Yang, Jingheng Xu et al.CCS 2024 · 10 citations
- Preventing Disruption of System Backup against Ransomware AttacksYiwei Hou, Lihua Guo, Chijin Zhou, Quan Zhang et al.ISSTA 2025 · 1 citation
- Ransomware Detection through Temporal Correlation between Encryption and I/O BehaviorLihua Guo, Yiwei Hou, Chijin Zhou, Quan Zhang et al.FSE 2025
- ERW-Radar: An Adaptive Detection System against Evasive Ransomware by Contextual Behavior Detection and Fine-grained Content AnalysisLingbo Zhao, Yuhui Zhang, Zhilu Wang, Fengkai Yuan et al.NDSS 2025
Builds on5
- Tracking Ransomware End-to-endDanny Yuxing Huang, Maxwell Matthaios Aliapoulios, Vector Guo Li, Luca Invernizzi et al.S&P 2018 · 208 citations
- FlashGuard: Leveraging Intrinsic Flash Properties to Defend Against Encryption RansomwareJian Huang, Jun Xu, Xinyu Xing, Peng Liu et al.CCS 2017 · 94 citations
- DEFTL: Implementing Plausibly Deniable Encryption in Flash Translation LayerShijie Jia, Luning Xia, Bo Chen, Peng LiuCCS 2017 · 44 citations
- RSSD: defend against ransomware with hardware-isolated network-storage codesign and post-attack analysisBenjamin Reidys, Peng Liu, Jian HuangASPLOS 2022 · 28 citations
- UNVEIL: A Large-Scale, Automated Approach to Detecting RansomwareAmin Kharraz, Sajjad Arshad, Collin Mulliner, William K. Robertson et al.USENIX Security 2016
Related papers
- Ransom Access Memories: Achieving Practical Ransomware Protection in Cloud with DeftPunkZhongyu Wang, Yaheng Song, Erci Xu, Haonan Wu et al.OSDI 2024 · 10 citations
- Limits of I/O Based Ransomware Detection: An Imitation Based AttackChijin Zhou, Lihua Guo, Yiwei Hou, Zhenya Ma et al.S&P 2023
- Cryptographic Function Detection in Obfuscated Binaries via Bit-Precise Symbolic Loop MappingDongpeng Xu, Jiang Ming, Dinghao WuS&P 2017 · 83 citations
- TEE-aided Write Protection Against Privileged Data TamperingLianying Zhao, Mohammad MannanNDSS 2019 · 17 citations
- Detecting Ransomware Despite I/O Overhead: A Practical Multi-Staged ApproachChristian van Sloun, Vincent Woeste, Konrad Wolsing, Jan Pennekamp et al.NDSS 2025
