Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Ransomware protection
#1
Macrium reflect uses Image Guardian to lock images so nothing can change the image files. I don’t know how it works, if it requires a driver, how much system resources it uses, or if it’s actually needed for images stored on external disconnected ssd drive.
Are HBS backup images locked in a similar way?
Reply
#2
@zx81,

Thank you for your interest in the backup image security of Hasleo Backup Suite.

Macrium Reflect Image Guardian achieves its protection by using a kernel-mode driver to intercept application access to image files. Obviously, this does consume a small amount of system resources, but compared to the security benefits it brings, this overhead is generally negligible.

We plan to officially introduce the "Backup Image Protection" feature in the next major version of Hasleo Backup Suite. This feature will provide protection similar to Macrium Reflect Image Guardian, preventing unauthorized processes (including ransomware) from tampering with or encrypting your backup files.

If you have any further questions, please feel free to ask.

Have a nice day!

Best regards,
Reply
#3
Thank you for this information. 
How secure are these locked/protected files?
Would it be possible for someone malicious who knew what they were doing to bypass? 

I assume because it’s a driver the protection only works on the computer it’s installed on?
Locked backup images stored on an external usb SSD drive would not be protected if the drive connected to a different computer, which maybe running an O/S other than Windows.  I know that’s why backups should be encrypted, but that doesn’t stop ransomware being transferred unknowingly and the encrypted backup image being maliciously re-encrypted. Or am I just being overly paranoid as I don’t even know how prevalent ransomware actually is. Wink

How far off being released is the next major version you mentioned?
Reply
#4
@zx81,

Driver based image protection can effectively block unauthorized modifications. However, no protection is completely unbypassable in theory. For example, if an attacker gains administrator privileges, they could stop or even uninstall the driver entirely.

You are absolutely right that the driver protection only works on Windows systems where our driver is installed. When the backup drive is connected to another computer, the driver protection will not be active. For this reason, it is essential to enable encryption for important data and to physically disconnect the device once the backup is complete.

Regarding the new version, we are actively developing it, but we do not have a confirmed release date yet. This feature involves core driver development and rigorous security testing, and we must ensure it is stable and reliable.

Thanks.

Best regards,
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)