INESC TEC showcased ransomware research at cybersecurity community event

An INESC TEC researcher presented the Institute’s work on ransomware analysis and protection to the cybersecurity community during the 12th meeting of OWASP Porto, the regional chapter of the Open Worldwide Application Security Project (OWASP) – an international organisation dedicated to improving application security through knowledge sharing, training and the development of best practices. 

Tânia Esteves, INESC TEC researcher specialising in distributed and operating systems, presented the Institute’s ongoing research into the behaviour of different ransomware families, as well as the evaluation of existing mechanisms for preventing attacks and recovering compromised data. 

Speaking to an audience of around 80 participants, the researcher outlined the protection techniques currently available, their limitations and the key measures organisations should consider when defending against this type of threat; the presentation also explored future research directions, particularly the need to develop protection mechanisms against attacks that not only encrypt information but also steal data from organisations. Moreover, she presented the Rescueware and INOCULUM projects, highlighting how INESC TEC is exploring new approaches to data recovery and the development of systems that are more resilient to ransomware attacks. 

“Participating in this event allowed us to showcase our research to the cybersecurity community while gathering valuable insights from professionals working in the field about the current challenges and needs in this area,” said Tânia Esteves. 

The 12th OWASP Porto meeting took place on 15 July at the facilities of 42 Porto. Organised by the local OWASP Porto chapter, the event aimed to promote knowledge sharing in application security while bringing together researchers, professionals and cybersecurity enthusiasts. The programme also featured a presentation by Luís Fontes, from Xapo, on attacks targeting software developers, followed by a networking session for all participants. 

INOCULUM established the next steps 

Also in July, the partners involved in INOCULUM, one of the projects presented during the OWASP Porto meeting, met to align the project’s ongoing activities and define the next steps. The project seeks to explore secure-by-design storage solutions capable of effectively resisting crypto-ransomware attacks. 

In this type of attack, an organisation’s systems are compromised, and critical data are encrypted, preventing access to information and potentially disrupting services until a ransom is paid. INOCULUM aims to ensure that, even if an attack is successful, no compromised data become permanently unrecoverable. 

“The project will explore different storage solutions to ensure that security and data recovery capabilities are built into their design from the outset, rather than being added later to existing systems,” explained João Paulo, an INESC TEC researcher specialising in distributed and storage systems and a lecturer at the School of Engineering of the University of Minho. 

Once these guarantees have been established, the research will explore emerging hardware technologies and new storage libraries, towards improving system performance while ensuring these solutions can be deployed in infrastructures that manage large volumes of digital information. 

The project’s goals include new scientific publications and conference presentations, the organisation of workshops and the development of open-source prototypes – as well as initiatives aimed at industry and society, raising awareness of the impact of ransomware attacks among different audiences, while promoting best practices for strengthening cyber resilience.

PHP Code Snippets Powered By : XYZScripts.com
EnglishPortugal