4 ms·
Idea on how to prevent malware on disk level?
What if there would be part of the storage that prevents overwriting/append files, so you can write once/read many but you cannot delete or append/overwrite. This could be on very low level and you would need some very high permission to change.
So, for instance if system determines after few month of usage that you are not changing some files but you are keeping them especially photos/audio/video/docs *(not in git) it would automatically move them there (folder structure would not change but underlying file location would.)
Now, what about Databases and large files that are changing constantly. I could imagine this low level storage being in read-only chunks, and chunks would need elevate (super admin) permissions in order to delete them. As main portion of DB data is historical and would not change over time, this could work.
My question is, does anything similar already exist, and if not would it be feasible?
Please do not give me answers along the lines "yes it exist it is called backup."
- btown 5y agoIn practice, malware has numerous ways to attack files, not just writing to the filesystem itself. https://www.microsoft.com/security/blog/2018/09/27/out-of-sight-but-not-invisible-defeating-fileless-malware-with-behavior-monitoring-amsi-and-next-gen-av/ https://www.microsoft.com/security/blog/2018/09/27/out-of-si... is a good overview of some of the techniques used. Generally, you need to ensure that programs can't get other already-trusted programs to do their bidding, and that's tough. Apple has done a lot of work here, but the more you request user intervention to enable access, the more you invite a frustrated user simply clicking yes to everything, which defeats the purpose. https://tidbits.com/2018/09/10/mojaves-new-security-and-privacy-protections-face-usability-challenges/ https://tidbits.com/2018/09/10/mojaves-new-security-and-priv... is a good overview. More generally, though, for the use case of infrequently accessed personal files, a hardened mirror of your data that specifically keeps old versions of files, even if told by a corrupted system that they should be deleted or rewritten, is the type of thing you need. And systems like Dropbox are designed to do just that. If any file can be rewinded to a specific point in time at any time, is that particularly different from someone trying to answer the UX problems with permissions dialogs for filesystem access etc. by saying "if someone tries to delete/modify a file, let's just log that it happened and ensure the user can easily (in this case retroactively) prevent them from doing so?"
- dredmorbius 5y agoThis sounds as if it's specifically aimed at defeating ransomware which acts by deleting, overwriting, or encrypting (a form of overwriting) files. 1. This is only one form of malware attack, generally. 2. Backups are in fact simplest and most resilient form of defence against such attacks. Most specifically, offline backups in a secure location distinct from the system in question. 3. There are any number of tools and technologies which provide change-resistant storage. This includes: a) One-time writable media. CDROM-Writable (not rewritable), paper tape, ROM, and the like. The obvious challenge here is that this i) requires specific media formats and ii) any degree of volatility of the data rapidly makes large-scale storage extraordinarily expensive. b) Copy-on-write. When implemented as a filesystem or volume manager, this results in snapshotable filesystem. Edits are saved as new writes, old data are not actually deleted. The advantage is the ability to roll back to previous (and in the case of malware, presumably un-tainted) versions of a file. Storage overhead is less than in the one-time-writable media case. Disadvantages are performance, the face that such system don't disable all deletes, they only make deletion (or other forms of updating) separate actions. c) Versioning. This might be implemented at the filesystem or workflow level. Tools such as Git and other distributed versioning systems keep multiple copies of an entire project tree, and the edits associated with it available in multiple copies. The good news is that it's unlikely for the entire project to be deleted or corrupted from all sources at once. The bad news is that both media and OS can still corrupt or delete individual instances. For "blobs" (binary large objects, including typically media files (audio, video), version control works poorly at best. d) Malware interception. Detecting and preventing malware from being written to disk in the first place. This is how much present anti-malware systems work, the problem being that various signature-based detection tools are only partially effective at best. There's the further issue that there are many potential objectives of hacking attacks. Data deletion or destruction is only one small part of the threat. In general, the solution exists. It's called current and tested offline backups.