Mitigating ransomware activity of a host system using a kernel monitor
A kernel monitor can be used to mitigate ransomware activity of a host system. In some aspects, a computing system can use the kernel monitor to monitor a set of system calls generated by the host system within a time window to perform a functionality. The kernel monitor can include a respective kernel program monitoring each system call in the set of system calls. The set of system calls can be filtered by the kernel monitor to identify a subset of system calls associated with encrypting a filesystem of the host system. The computing system can determine that the subset of system calls is indicative of ransomware activity associated with the host system based on the subset of system calls exceeding a predefined threshold. Subsequently, the computing system can perform a mitigation operation to mitigate the ransomware activity.
1 . A system comprising:
a processing device; and
a memory device including instructions that are executable by the processing device for causing the processing device to perform operations comprising:
monitoring, using a kernel monitor of a host system, a set of system calls generated by the host system within a time window to perform a functionality, the kernel monitor comprising a respective kernel program assigned to each system call in the set of system calls to monitor the set of system calls, wherein each kernel program of the kernel monitor is configured to alert the kernel monitor in response to an execution of a corresponding system call;
filtering, by the kernel monitor, the set of system calls to identify a subset of system calls associated with encrypting a filesystem of the host system;
determining that the subset of system calls is indicative of ransomware activity associated with the host system based on the subset of system calls exceeding a predefined threshold; and
subsequent to determining that the subset of system calls is indicative of the ransomware activity, performing a mitigation operation to mitigate the ransomware activity by isolating at least a portion of the host system, the mitigation operation comprising generating a virtual host system to emulate the host system, wherein the virtual host system is configured to replace the host system to perform the functionality.
2 . The system of claim 1 , wherein the operation of performing the mitigation operation to mitigate the ransomware activity further comprises:
initiating a handover process configured to transfer responsibility of the functionality performed by the host system to the virtual host system, wherein the virtual host system is configured to operate offline; and
subsequent to initiating the handover process configured to transfer the responsibility of the functionality performed by the host system to the virtual host system, regaining, by the host system, control of performing the functionality from the virtual host system.
3 . The system of claim 1 , wherein the operation of determining that the subset of system calls is indicative of the ransomware activity associated with the host system further comprises:
generating an affinity score associated with the set of system calls by applying a similarity search to compare a system call pattern corresponding to the set of system calls to a ransomware pattern corresponding to historical ransomware activity, wherein the affinity score quantifies similarity between the system call pattern and the ransomware pattern;
determining whether the affinity score is above a predefined tolerance used to control a write access to the filesystem of the host system; and
in response to determining that the affinity score is above the predefined tolerance, preventing the write access to the filesystem of the host system as part of the mitigation operation to mitigate the ransomware activity.
4 . The system of claim 3 , wherein the operations further comprise:
buffering one or more write operations associated with the filesystem of the host system, wherein the one or more write operations are part of the set of system calls generated within the time window; and
in response to determining that the affinity score is above the predefined tolerance, preventing the write access to the filesystem by blocking an execution of the one or more write operations.
5 . The system of claim 1 , wherein the operations further comprise, subsequent to the operation of filtering the set of system calls:
identifying an encrypted file corresponding to the subset of system calls associated with encrypting the filesystem of the host system, wherein the encrypted file is part of the filesystem of the host system and indicative of the ransomware activity; and
generating a ransomware pattern based on the encrypted file, wherein the ransomware pattern is used to identify the ransomware activity.
6 . The system of claim 1 , wherein the predefined threshold is a first predefined threshold corresponding to a first subset of system calls generated within a first time window, and wherein the operations further comprise, subsequent to the operation of determining that the first subset of system calls exceeds the first predefined threshold:
monitoring, by the kernel monitor, a second set of system calls generated by the host system within a second time window extending past the first time window;
filtering the second set of system calls to identify a second subset of system calls associated with encrypting the filesystem of the host system;
determining that the second subset of system calls generated within the second time window exceeds a second predefined threshold indicative of a ransomware attack of the host system; and
subsequent to determining that the second subset of system calls generated within the second time window exceeds the second predefined threshold, performing the mitigation operation to mitigate the ransomware attack.
7 . The system of claim 1 , wherein the operation of performing the mitigation operation further comprises:
providing a system call log generated by the kernel monitor as input to a machine-learning model, wherein the machine-learning model is trained to use the system call log to generate an output used to identify a ransomware file associated with the ransomware activity;
identifying, based on the output of the machine-learning model, the ransomware file stored in the filesystem; and
in response to identifying the ransomware file, isolating the ransomware file by moving the ransomware file to a separate storage system, wherein the separate storage system is disconnected from the host system.
8 . A method comprising:
monitoring, using a kernel monitor of a host system, a set of system calls generated by the host system within a time window to perform a functionality, the kernel monitor comprising a respective kernel program assigned to each system call in the set of system calls to monitor the set of system calls, wherein each kernel program of the kernel monitor alerts the kernel monitor in response to an execution of a corresponding system call;
filtering, by the kernel monitor, the set of system calls to identify a subset of system calls associated with encrypting a filesystem of the host system;
determining that the subset of system calls is indicative of ransomware activity associated with the host system based on the subset of system calls exceeding a predefined threshold; and
subsequent to determining that the subset of system calls is indicative of the ransomware activity, performing a mitigation operation to mitigate the ransomware activity by isolating at least a portion of the host system, the mitigation operation comprising generating a virtual host system to emulate the host system, wherein the virtual host system performs the functionality in place of the host system.
9 . The method of claim 8 , wherein performing the mitigation operation to mitigate the ransomware activity further comprises:
initiating a handover process to transfer responsibility of the functionality performed by the host system to the virtual host system, wherein the virtual host system operates offline; and
subsequent to initiating the handover process to transfer the responsibility of the functionality performed by the host system to the virtual host system, regaining, by the host system, control of performing the functionality from the virtual host system.
10 . The method of claim 8 , wherein determining that the subset of system calls is indicative of the ransomware activity associated with the host system further comprises:
generating an affinity score associated with the set of system calls by applying a similarity search to compare a system call pattern corresponding to the set of system calls to a ransomware pattern corresponding to historical ransomware activity, wherein the affinity score quantifies similarity between the system call pattern and the ransomware pattern;
determining whether the affinity score is above a predefined tolerance used to control a write access to the filesystem of the host system; and
in response to determining that the affinity score is above the predefined tolerance, preventing the write access to the filesystem of the host system as part of the mitigation operation to mitigate the ransomware activity.
11 . The method of claim 10 , further comprising:
buffering one or more write operations associated with the filesystem of the host system, wherein the one or more write operations are part of the set of system calls generated within the time window; and
in response to determining that the affinity score is above the predefined tolerance, preventing the write access to the filesystem by blocking an execution of the one or more write operations.
12 . The method of claim 8 , further comprising, subsequent to filtering the set of system calls:
identifying an encrypted file corresponding to the subset of system calls associated with encrypting the filesystem of the host system, wherein the encrypted file is part of the filesystem of the host system and indicative of the ransomware activity; and
generating a ransomware pattern based on the encrypted file, wherein the ransomware pattern is used to identify the ransomware activity.
13 . The method of claim 8 , wherein the predefined threshold is a first predefined threshold corresponding to a first subset of system calls generated within a first time window, and wherein the method further comprise, subsequent to determining that the first subset of system calls exceeds the first predefined threshold:
monitoring, by the kernel monitor, a second set of system calls generated by the host system within a second time window extending past the first time window;
filtering the second set of system calls to identify a second subset of system calls associated with encrypting the filesystem of the host system;
determining that the second subset of system calls generated within the second time window exceeds a second predefined threshold indicative of a ransomware attack of the host system; and
subsequent to determining that the second subset of system calls generated within the second time window exceeds the second predefined threshold, performing the mitigation operation to mitigate the ransomware attack.
14 . The method of claim 8 , wherein performing the mitigation operation further comprises:
providing a system call log generated by the kernel monitor as input to a machine-learning model, wherein the machine-learning model is trained to use the system call log to generate an output used to identify a ransomware file associated with the ransomware file;
identifying, based on the output of the machine-learning model, the ransomware file stored in the filesystem; and
in response to identifying the ransomware file, isolating the ransomware file by moving the ransomware file to a separate storage system, wherein the separate storage system is disconnected from the host system.
15 . A non-transitory computer-readable medium comprising program code executable by a processing device for causing the processing device to perform operations comprising:
monitoring, using a kernel monitor of a host system, a set of system calls generated by the host system within a time window to perform a functionality, the kernel monitor comprising a respective kernel program assigned to each system call in the set of system calls to monitor the set of system calls, wherein each kernel program of the kernel monitor is configured to alert the kernel monitor in response to an execution of a corresponding system call;
filtering, by the kernel monitor, the set of system calls to identify a subset of system calls associated with encrypting a filesystem of the host system;
determining that the subset of system calls is indicative of ransomware activity associated with the host system based on the subset of system calls exceeding a predefined threshold; and
subsequent to determining that the subset of system calls is indicative of the ransomware activity, performing a mitigation operation to mitigate the ransomware activity by isolating at least a portion of the host system, the mitigation operation comprising generating a virtual host system to emulate the host system, wherein the virtual host system is configured to replace the host system to perform the functionality.
16 . The non-transitory computer-readable medium of claim 15 , wherein the operation of performing the mitigation operation to mitigate the ransomware activity further comprises:
initiating a handover process configured to transfer responsibility of the functionality performed by the host system to the virtual host system, wherein the virtual host system is configured to operate offline; and
subsequent to initiating the handover process configured to transfer the responsibility of the functionality performed by the host system to the virtual host system, regaining, by the host system, control of performing the functionality from the virtual host system.
17 . The non-transitory computer-readable medium of claim 15 , wherein the operation of determining that the subset of system calls is indicative of the ransomware activity associated with the host system further comprises:
generating an affinity score associated with the set of system calls by applying a similarity search to compare a system call pattern corresponding to the set of system calls to a ransomware pattern corresponding to historical ransomware activity, wherein the affinity score quantifies similarity between the system call pattern and the ransomware pattern;
determining whether the affinity score is above a predefined tolerance used to control a write access to the filesystem of the host system; and
in response to determining that the affinity score is above the predefined tolerance, preventing the write access to the filesystem of the host system as part of the mitigation operation to mitigate the ransomware activity.
18 . The non-transitory computer-readable medium of claim 17 , wherein the operations further comprise:
buffering one or more write operations associated with the filesystem of the host system, wherein the one or more write operations are part of the set of system calls generated within the time window; and
in response to determining that the affinity score is above the predefined tolerance, preventing the write access to the filesystem by blocking an execution of the one or more write operations.
19 . The non-transitory computer-readable medium of claim 15 , wherein the operations further comprise, subsequent to the operation of filtering the set of system calls:
identifying an encrypted file corresponding to the subset of system calls associated with encrypting the filesystem of the host system, wherein the encrypted file is part of the filesystem of the host system and indicative of the ransomware activity; and
generating a ransomware pattern based on the encrypted file, wherein the ransomware pattern is used to identify the ransomware activity.
20 . The non-transitory computer-readable medium of claim 15 , wherein the predefined threshold is a first predefined threshold corresponding to a first subset of system calls generated within a first time window, and wherein the operations further comprise, subsequent to the operation of determining that the first subset of system calls exceeds the first predefined threshold:
monitoring, by the kernel monitor, a second set of system calls generated by the host system within a second time window extending past the first time window;
filtering the second set of system calls to identify a second subset of system calls associated with encrypting the filesystem of the host system;
determining that the second subset of system calls generated within the second time window exceeds a second predefined threshold indicative of a ransomware attack of the host system; and
subsequent to determining that the second subset of system calls generated within the second time window exceeds the second predefined threshold, performing the mitigation operation to mitigate the ransomware attack.