Lifecycle-Based Design and Evaluation of Real-Time Backup Triggers for Ransomware Damage Mitigation
This study addresses the challenge of determining optimal trigger points for real-time backups during ransomware attacks, where balancing recoverability against storage overhead remains difficult. Adopting a file lifecycle perspective, this work systematically quantifies, for the first time, the protective efficacy and associated costs of four file operations—open, read, write, and rename—as backup triggers. A ROFBS-style prototype was implemented atop the XFS file system and evaluated through simulated attacks using five representative ransomware samples, including Conti. The experimental results elucidate the trade-offs between security and performance across different triggering strategies. Ultimately, these findings provide critical design guidelines for constructing efficient, ransomware-resilient real-time backup systems.