Pre Attack Activity Framework and Backup Solution for Protection of Ransomware Attacks

Abstract

Digital records may be stopped by ransomware, which functions as a kind of extortion until a ransom is paid. It is thought to be a difficult effort to defend against the growing amount of ransomware attacks because of the requirement for knowledge about recently discovered malware and its ever changing families or varieties. In order to identify and prevent ransomware assaults, it is necessary to investigate effective methods for examining their behavioural traits prior to encryption. The first step of detection can be the comparison of that ransomware s signature with the known ransomware s signature before the ransomware could be launched. If there is no match due to the growing rate of constantly evolving variants then using the Pre attack API calls, these ransomwares can be credited them to known malicious families. Discovery avoidance methods are formulated by performing a series of pre-attack API calls to fingerprint the environment and dodge execution in a virtual environment. This can be the primary step towards recognizing and moderating such dangers. Furthermore, this research also can be useful in identifying ransomware and useful software at pre-encryption phase using the APIs. Prevention and recovery are also necessary to safeguard the system as there is very less information can be collected about the new or unseen ransomware. So, a mechanism for early detection of ransomware is required and needs a mechanism for data backup. So, we suggest an approach where (i) ransomware families can be classified and Ransomware or goodware like behavior is also identified by pre attack action and which can be utilized to construct successful countermeasures for detecting ransomware attacks and preventing them from causing tangible damage and (ii) an auto backup solution that provide an encrypted data backup and the system is able to recover the data iii whenever it is needed. newline

Description

Keywords

Citation

item.page.endorsement

item.page.review

item.page.supplemented

item.page.referenced