An Asset-Based Approach to Mitigate Zero-Day Ransomware Attacks

Farag Azzedin*, Husam Suwad, Md Mahfuzur Rahman

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

7 Scopus citations

Abstract

This article presents an asset-based security system where security practitioners build their systems based on information they own and not solicited by observing attackers' behavior. Current security solutions rely on information coming from attackers. Examples are current monitoring and detection security solutions such as intrusion prevention/detection systems and firewalls. This article envisions creating an imbalance between attackers and defenders in favor of defenders. As such, we are proposing to flip the security game such that it will be led by defenders and not attackers. We are proposing a security system that does not observe the behavior of the attack. On the contrary, we draw, plan, and follow up our own protection strategy regardless of the attack behavior. The objective of our security system is to protect assets rather than protect against attacks. Virtual machine introspection is used to intercept, inspect, and analyze system calls. The system callbased approach is utilized to detect zero-day ransomware attacks. The core idea is to take advantage of Xen andDRAKVUF for system call interception, and leverage system calls to detect illegal operations towards identified critical assets.We utilize our vision by proposing an asset-based approach to mitigate zero-day ransomware attacks. The obtained results are promising and indicate that our prototype will achieve its goals.

Original languageEnglish
Pages (from-to)3003-3020
Number of pages18
JournalComputers, Materials and Continua
Volume73
Issue number2
DOIs
StatePublished - 2022

Bibliographical note

Publisher Copyright:
© 2022 Tech Science Press. All rights reserved.

Keywords

  • Zero-day attacks
  • ransomware
  • system calls
  • virtual machine introspection

ASJC Scopus subject areas

  • Biomaterials
  • Modeling and Simulation
  • Mechanics of Materials
  • Computer Science Applications
  • Electrical and Electronic Engineering

Fingerprint

Dive into the research topics of 'An Asset-Based Approach to Mitigate Zero-Day Ransomware Attacks'. Together they form a unique fingerprint.

Cite this