🤖 AI Summary
This study addresses the challenge of determining optimal trigger points for real-time backups during ransomware attacks, where balancing recoverability against storage overhead remains difficult. Adopting a file lifecycle perspective, this work systematically quantifies, for the first time, the protective efficacy and associated costs of four file operations—open, read, write, and rename—as backup triggers. A ROFBS-style prototype was implemented atop the XFS file system and evaluated through simulated attacks using five representative ransomware samples, including Conti. The experimental results elucidate the trade-offs between security and performance across different triggering strategies. Ultimately, these findings provide critical design guidelines for constructing efficient, ransomware-resilient real-time backup systems.
📝 Abstract
Ransomware continues to encrypt files during the interval between attack onset and detection. Real-time backups can mitigate this damage by preserving files before they are modified. The previously proposed Real-Time Open-File Backup System (ROFBS) triggers backups primarily on file-open events. However, the file lifecycle offers several candidate trigger points, including open, read, write, and rename operations. Triggering backups too early may create unnecessary backup files, whereas triggering them too late may allow ransomware writes to race with backup creation and prevent the preservation of clean file contents. Consequently, it remains unclear which trigger timing best balances recoverability and the number of backups created. In this study, we design and evaluate real-time backup triggers for mitigating ransomware damage from a file-lifecycle perspective. Specifically, we compare four strategies: Open-time backup, Read-time backup, Write-time backup, and Rename-time backup. We implement these strategies in an ROFBS-style prototype on XFS and evaluate them using five ransomware samples: Conti, Sodinokibi, AvosLocker, REvil, and HelloKitty. Our results clarify how trigger timing affects both damage mitigation and the number of backups created, providing design guidance for selecting effective triggers in real-time backup systems against ransomware.