CryptoDrop: Are you willing to sacrifice some of your files to save the rest before they get encrypted by a modern ransomware?
The answer from most victims is probably “YES” in uppercase. This is exactly the function of CryptoDrop.
It is a new anti-ransomware solution that apparently works seamlessly with various anti-virus programs that are circulating. It was created by a team of researchers from the University of Florida and Villanova University.
It works like an early warning system, and sacrifices some files so it can detect and stop the action of ransomware.
Detects characteristic actions of ransomware such as: mass modification, new file types, file deletion, detects significant differences between files, sudden appearance of a large number of files of the same type, etc.
Unfortunately the solution still exists only as a prototype. Researchers are looking for a sponsor who will help them turn it into a commercial product.
Without a doubt, however, the new security solution is quite effective.
Watch the presentation video (uploaded to the University's channel):
“We ran our scanner with several hundred ransomware samples and it detected 100% of them, as they had only encrypted 10 files” says Nolen Scaife, a PhD student at the University of Florida and one of the researchers of CryptoDrop.
Mr. Patrick Traynor's colleague, an associate professor in the Department of Computer Engineering and Computer Science at the University of Florida, reports that only about one tenth of 1% of the files were lost, but the tool gains an advantage and becomes much more flexible.
