Crypto-ransomware has caused an unprecedented scope of impact in recent years, with an evolving level of sophistication. An extensive range of studies have been conducted on defending against ransomware and reviewing the efficacy of various protections. However, for practical defenses, deployability holds equal significance as detection accuracy. Therefore, in this study, we review 117 published ransomware defense works, categorize them by the level they are implemented, and discuss the deployability. API-based solutions are easy to deploy, and most existing works focus on machine learning-based classification. To provide more insights, we quantitatively characterize the runtime behaviors of real-world ransomware samples. Based on our experimental findings, we present a possible future detection direction with our consistency analysis and API-contrast-based refinement. Moreover, we experimentally evaluate various commercial defenses and identify the security gaps. Our findings help the field understand the deployability of ransomware defenses and create more effective, practical solutions.
Song et al. (Mon,) studied this question.