arXiv · 2610.07854
Lifecycle-Based Design and Evaluation of Real-Time Backup Triggers for Ransomware Damage Mitigation
Abstract
Ransomware continues to encrypt files during the interval between attack onset and detection. Real-time backups can mitigate this damage by preserving files before they are modified. The previously proposed Real-Time Open-File Backup System (ROFBS) triggers backups primarily on file-open events. However, the file lifecycle offers several candidate trigger points, including open, read, write, and rename operations. Triggering backups too early may create unnecessary backup files, whereas triggering them too late may allow ransomware writes to race with backup creation and prevent the preservation of clean file contents. Consequently, it remains unclear which trigger timing best balances recoverability and the number of backups created. In this study, we design and evaluate real-time backup triggers for mitigating ransomware damage from a file-lifecycle perspective. Specifically, we compare four strategies: Open-time backup, Read-time backup, Write-time backup, and Rename-time backup. We implement these strategies in an ROFBS-style prototype on XFS and evaluate them using five ransomware samples: Conti, Sodinokibi, AvosLocker, REvil, and HelloKitty. Our results clarify how trigger timing affects both damage mitigation and the number of backups created, providing design guidance for selecting effective triggers in real-time backup systems against ransomware.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Kosuke Higuchi, Ryotaro Kobayashi. 2026-10-06. Lifecycle-Based Design and Evaluation of Real-Time Backup Triggers for Ransomware Damage Mitigation. https://arxiv.org/abs/2610.07854
Cite the original work for its findings. Save a collection to share your selection of sources.