首页> 外文期刊>Computer and Information Science >Improving Backup System Evaluations in Information Security Risk Assessments to Combat Ransomware
【24h】

Improving Backup System Evaluations in Information Security Risk Assessments to Combat Ransomware

机译:在信息安全风险评估中改进备份系统评估,以对抗勒索软件

获取原文
       

摘要

Ransomware is the fastest growing malware threat and accounts for the majority of extortion based malware threats causing billions of dollars in losses for organizations around the world. Ransomware is a global epidemic that afflicts all types of organizations that utilize computing infrastructure. Once systems are infected and storage is encrypted, victims have little choice but to pay the ransom and hope their data is released or start over and rebuild their systems. Either remedy can be costly and time consuming. However, backups can be used to restore data and systems to a known good state prior to ransomware infection. This makes backups the last line of defense and most effective remedy in combating ransomware. Accordingly, information security risk assessments should evaluate backup systems and their ability to address ransomware threats. Yet, NIST SP-800-30 does not list ransomware as a specific threat. This study reviews the ransomware process, functional backup architecture paradigms, their ability to address ransomware attacks, and provides suggestions to improve the guidance in NIST SP-800-30 and information security risk assessments to better address ransomware threats.
机译:勒索软件是增长最快的恶意软件威胁,占基于勒索的恶意软件威胁的大部分,对全世界的组织造成数十亿美元的损失。勒索软件是一种全球性流行病,困扰着使用计算基础架构的所有类型的组织。一旦系统被感染并且存储被加密,受害者别无选择,只能支付赎金,希望他们的数据被释放或重新开始并重建他们的系统。任何一种补救措施都可能是昂贵且费时的。但是,在勒索软件感染之前,可以使用备份将数据和系统还原到已知的良好状态。这使备份成为抵御勒索软件的最后一道防线和最有效的补救措施。因此,信息安全风险评估应评估备份系统及其应对勒索软件威胁的能力。但是,NIST SP-800-30并未将勒索软件列为特定威胁。这项研究回顾了勒索软件的过程,功能性备份体系结构范式,其应对勒索软件攻击的能力,并提出了一些建议,以改进NIST SP-800-30中的指南以及信息安全风险评估,以更好地应对勒索软件威胁。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号