Best Method for Protecting Backup Drive from Malware

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
First of all let's build your prevention fortress.

You need a sufficient AV protection + special component like Anti-Exe or HIPS that will prevent any leaks since that's one of the main concept [Buffer Overflow Attacks] however its an option to use like CryptoPrevent, WAR and few others but assurance of possible bypass due to different production of ransomware.

Now in the case of backup, better yet conduct numerous incremental backups + have a virtualization software in any case.
 

Quassar

Level 12
Verified
Well-known
Feb 10, 2012
585
-Best / Most secure way is to create backup on next addinonal disk and is not connected every day (just only for create next one backup or using to rollback system, your important data)

-Next important fact is your runing system which are under asking symbol "?" what's that mean or just what i want to tell you...
I mean if your system is confiused by some kind of virus and you want rollback system, Better dont do it from your current infected system (or in teory cleaned after infection)
Becasue you can harm your backup files by exsit virus which can still work on your system... :(
That why i prefer use standalone bootable system which comes with most of backup producents.

......
If are not fan of plug in/out every time harddisk or pendrive for "offline" backup and you wanna just make it from curent system to another space which work all time together with your system,
becasue you wanna to be more "elastic" use more friendly config, your data will be always under risk more than before..
And you will need software which put resctricion for improve security your data..

The best way will be use software which block read/write acess by unknow proces or such other manniers like this in system.
So you will put "SRP" Software Restriction Policies
I prefer software: AppGuard, Sandboxie-(Sandboxie is isolator"Sandbox" but he also come with advanced mode and with good/specific config he can also do it) Smart Object Blocker, WinAntiRAnsom (WinAntiRAnsom it is yet fresh project but in near time can be rly important program which improve your rest security on the system)

AV is typical scanner which come with partial blocker which moslty base on knew virus.
Unfortunly AV cant handle on time all fresh virus figured on network. That why you need more advaned programs which give you back control on your runing process/system.

HIPS or oprograms which work, use similar module based on HIPS technology (Host Intrusion Prevention System)
Program will monitor all runing process and not only and will ask you for block or allow which software what wanna to do.
In this sytuation you can block virus on 1st try taking action to harm your system.

Anti-EXE similar like HIPS also monitor action like HIPS but montor base only on monitoring process exe and not monitor aswell deep like typical HIPS. but also nice to have it.

Firewall will give you control on your network and you will be able to break connection with specific proces to prevent leak or harmd your data depend on infection.

Mostly good firewall come together with hips
I can offer you OutpostFirwall, SpyShelterFW (you can buy also standalone HIPS with out FW)
NVT ExeRadar Pro - awesome anti-exe security software i rly recomend it.
 
D

Deleted Member 333v73x

i back up using an external hard drive, once back up is complete i unplug the external hard drive! i think its safer that way!
I enable OneDrive when I need it and then disable it when finished, if ransomeware did attack it couldn't encrypt my files in OneDrive, and I do disconnect my USB as well.
 

DracusNarcrym

Level 20
Verified
Top Poster
Well-known
Oct 16, 2015
970
Other users have provided sufficient information on how to secure already existing backed up files to prevent them from being damaged/lost in any way, including but not limited to, being maliciously encrypted by ransomware.

And now I shall simply only give you an extremely important reminder:
Make sure you always have at least one, full, clean system backup image, so that you can restore your system to its exact state, as it was when you created that backup image.

You can imagine how important and how valuable a backup image like this can be, in any cases.
Backing up individual files is an entirely different step - this is for data protection.
However, if you want to secure the very functionality of your system, then obviously you also need to make sure you create the backup image which I mentioned above.
 

frogboy

In memoriam 1961-2018
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
Just do full backups on a healthy machine and keep the HDD you made the backup to disconnected after making the backup. keep several images on the HDD to be sure at least one will restore your machine to a previous good state. :)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top