Comments on Securing Cloud Storage from Ransomware

thecommissar

Level 1
Thread author
Verified
May 10, 2016
20
I know its not especially common, but in theory of course Ransomware can attack any drives the OS has write access to; these include everything from attached storage to network drives to cloud drives mounted to the OS as a volume (like Windows' integrated OneDrive, amongst others).

1. I'm wondering if there are best practices to securing these drives. Of course what I want is 'cold cloud storage' which is completely detached and never exposed to the host OS. The simple method is a Dropbox-esque web interface, and there are various services like that. A more complicated solution which I prefer is to use Amazon CloudDrive and link it to a desktop program like Arq for management.

Arq support tells me the drive never mounts to the OS and is essentially managed through the Amazon web API. In theory this should be secure from Ransomware/illicit write actions.

2. What I'm now worried about though is that a lot of the files getting put into these cloud services for storage could themselves be infected with say Ransomware or even malware more generally. Say its hiding in a PDF or an Excel Macro, something like that.

Of course it will be dormant in the storage system and unable to execute without a host. But lets say I one day retrieve that file... it could infect the machine.

3. Am I correct to understand that the best/only real way to deal with this is to scan every file that goes into the 'cloud storage' and hope that's sufficient? (Assuming all other security precautions, AV, anti-malware, anti-exploit, best practices, etc. etc. are taken).
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
Cloud storage security provide almost a full protection and encryption however since ransomware and other threats are so good to hide through its identity hence chance of infection. Which why steer away on any multi connected networks to avoid the spread of viruses immediately.

Yes in order to deal it is by scan them, as much as possible multi engines to have second opinion.
 

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
I know its not especially common, but in theory of course Ransomware can attack any drives the OS has write access to; these include everything from attached storage to network drives to cloud drives mounted to the OS as a volume (like Windows' integrated OneDrive, amongst others).

1. I'm wondering if there are best practices to securing these drives. Of course what I want is 'cold cloud storage' which is completely detached and never exposed to the host OS. The simple method is a Dropbox-esque web interface, and there are various services like that. A more complicated solution which I prefer is to use Amazon CloudDrive and link it to a desktop program like Arq for management.

Arq support tells me the drive never mounts to the OS and is essentially managed through the Amazon web API. In theory this should be secure from Ransomware/illicit write actions.

2. What I'm now worried about though is that a lot of the files getting put into these cloud services for storage could themselves be infected with say Ransomware or even malware more generally. Say its hiding in a PDF or an Excel Macro, something like that.

Of course it will be dormant in the storage system and unable to execute without a host. But lets say I one day retrieve that file... it could infect the machine.

3. Am I correct to understand that the best/only real way to deal with this is to scan every file that goes into the 'cloud storage' and hope that's sufficient? (Assuming all other security precautions, AV, anti-malware, anti-exploit, best practices, etc. etc. are taken).
1/ my best solution: right click on onedrive/dropbox tray icon -> pause syncing and exit them if you want. Just sync when you need them. Letting these always syncing in background is not good for your HDD or general pc performance
if your pc gets attacked, encrypted/infected files won't be synced
2/ install a light antivirus with enhanced custom settings, adblockers and a web filter (bitdefender trafficlight or avira)
3/ anti-executable if you want (voodooshield free)
 
  • Like
Reactions: DJ Panda

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top