Paik, Joon-Young, Choi, Joong-Hyun, Jin, Rize, Wang, Jianming, Cho, Eun-Sun.  2018.  A Storage-level Detection Mechanism Against Crypto-Ransomware. Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security. :2258–2260.
Ransomware represents a significant threat to both individuals and organizations. Moreover, the emergence of ransomware that exploits kernel vulnerabilities poses a serious detection challenge. In this paper, we propose a novel ransomware detection mechanism at a storage device, especially a flash-based storage device. To this end, we design a new buffer management policy that allows our detector to identify ransomware behaviors. Our mechanism detects a realistic ransomware sample with little negative impacts on the hit ratios of the buffers internally located in a storage device.