{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T23:43:04Z","timestamp":1784331784650,"version":"3.55.0"},"reference-count":58,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2022,4,7]],"date-time":"2022-04-07T00:00:00Z","timestamp":1649289600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>In recent years, various platforms have witnessed an unprecedented increase in the number of ransomware attacks targeting hospitals, governments, enterprises, and end-users. The purpose of this is to maliciously encrypt documents and files on infected machines, depriving victims of access to their data, whereupon attackers would seek some sort of a ransom in return for restoring access to the legitimate owners; hence the name. This cybersecurity threat would inherently cause substantial financial losses and time wastage for affected organizations and users. A great deal of research has taken place across academia and around the industry to combat this threat and mitigate its danger. These ongoing endeavors have resulted in several detection and prevention schemas. Nonetheless, these approaches do not cover all possible risks of losing data. In this paper, we address this facet and provide an efficient solution that would ensure an efficient recovery of XML documents from ransomware attacks. This paper proposes a self-healing version-aware ransomware recovery (SH-VARR) framework for XML documents. The proposed framework is based on the novel idea of using the link concept to maintain file versions in a distributed manner while applying access-control mechanisms to protect these versions from being encrypted or deleted. The proposed SH-VARR framework is experimentally evaluated in terms of storage overhead, time requirement, CPU utilization, and memory usage. Results show that the snapshot size increases proportionately with the original size; the time required is less than 120 ms for files that are less than 1 MB in size; and the highest CPU utilization occurs when using the bzip2. Moreover, when the zip and gzip are used, the memory usage is almost fixed (around 6.8 KBs). In contrast, it increases to around 28 KBs when the bzip2 is used.<\/jats:p>","DOI":"10.3390\/fi14040115","type":"journal-article","created":{"date-parts":[[2022,4,7]],"date-time":"2022-04-07T13:39:51Z","timestamp":1649338791000},"page":"115","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":12,"title":["Ransomware-Resilient Self-Healing XML Documents"],"prefix":"10.3390","volume":"14","author":[{"given":"Mahmoud","family":"Al-Dwairi","sequence":"first","affiliation":[{"name":"Department of Computer Engineering, Jordan University of Science and Technology, P.O. Box 3030, Irbid 22110, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6239-3298","authenticated-orcid":false,"given":"Ahmed S.","family":"Shatnawi","sequence":"additional","affiliation":[{"name":"Department of Software Engineering, Jordan University of Science and Technology, P.O. Box 3030, Irbid 22110, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Osama","family":"Al-Khaleel","sequence":"additional","affiliation":[{"name":"Department of Computer Engineering, Jordan University of Science and Technology, P.O. Box 3030, Irbid 22110, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Basheer","family":"Al-Duwairi","sequence":"additional","affiliation":[{"name":"Depatment of Network Engineering & Security, Jordan University of Science and Technology, P.O. Box 3030, Irbid 22110, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,4,7]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Mashtalyar, N., Ntaganzwa, U.N., Santos, T., Hakak, S., and Ray, S. (2021). Social Engineering Attacks: Recent Advances and Challenges, HCI for Cybersecurity, Privacy and Trust, Springer.","DOI":"10.1007\/978-3-030-77392-2_27"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Fong, S., Dey, N., and Joshi, A. (2022). Cyber Threats Landscape Overview Under the New Normal. ICT Analysis and Applications, Springer. Lecture Notes in Networks and Systems.","DOI":"10.1007\/978-981-16-5655-2"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Djenna, A., Harous, S., and Saidouni, D.E. (2021). Internet of Things Meet Internet of Threats: New Concern Cyber Security Issues of Critical Cyber Infrastructure. Appl. Sci., 11.","DOI":"10.3390\/app11104580"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"973","DOI":"10.1016\/j.jcss.2014.02.005","article-title":"A survey of emerging threats in cybersecurity","volume":"80","author":"Nepal","year":"2014","journal-title":"J. Comput. Syst. Sci."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Zong, S., Ritter, A., Mueller, G., and Wright, E. (2019). Analyzing the Perceived Severity of Cybersecurity Threats Reported on Social Media. arXiv.","DOI":"10.18653\/v1\/N19-1140"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"1145","DOI":"10.1109\/COMST.2016.2636078","article-title":"A Survey of Stealth Malware Attacks, Mitigation Measures, and Steps Toward Autonomous Open World Solutions","volume":"19","author":"Rudd","year":"2017","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_7","unstructured":"Nakashima, E.U.S. (2021, October 19). Aims to Thwart Ransomware Attacks by Cracking Down on Crypto Payments. The Washington Post, Available online: https:\/\/www.washingtonpost.com\/business\/2021\/09\/17\/biden-sanctions-ransomware-crypto."},{"key":"ref_8","unstructured":"Kumar, M., Ben-Othman, J., and Srinivasagan, K. (2018, January 25\u201328). An Investigation on Wannacry Ransomware and its Detection. Proceedings of the 2018 IEEE Symposium on Computers and Communications (ISCC), Natal, Brazil."},{"key":"ref_9","unstructured":"Stallings, W. (2016). Network Security Essentials: Applications and Standards, Pearson."},{"key":"ref_10","unstructured":"Peter, A., Peter, S., and Van Ekert, L. (2004). An ontology for network security attacks. Proceedings of the 2nd Asian Applied Computing Conference (AACC\u201904), LNCS 3285, Springer."},{"key":"ref_11","first-page":"10","article-title":"Ransomware: Evolution, mitigation and prevention","volume":"13","author":"Richardson","year":"2017","journal-title":"Int. Manag. Rev."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"8","DOI":"10.1016\/S1361-3723(16)30036-7","article-title":"Ransomware: To pay or not to pay?","volume":"2016","author":"Everett","year":"2016","journal-title":"Comput. Fraud Secur."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"444","DOI":"10.1016\/j.comnet.2017.09.003","article-title":"The rise of ransomware and emerging security challenges in the Internet of Things","volume":"129","author":"Yaqoob","year":"2017","journal-title":"Comput. Netw."},{"key":"ref_14","unstructured":"Shashank, M., and Agrawal, A.K. (2022, March 10). Multi Pronged Approach for Ransomware Analysis. Available online: https:\/\/deliverypdf.ssrn.com\/delivery.php?ID=529106093087077008125066087007008126061069029053059024023024048119007044109100058011016111014009004006028061086001098107006013106127099006095000116044119113035023073115003083030043113078009059098044124031019004068007115065011000084085080125073117006075066113004076094086068087090001095082&EXT=pdf&INDEX=TRUE."},{"key":"ref_15","unstructured":"(2022, March 10). What You Need to Know about the WannaCry Ransomware. Available online: https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/wannacry-ransomware-attack."},{"key":"ref_16","unstructured":"Leong, R., Beek, C., Cochin, C., Cowie, N., and Schmugar, C. (2022, March 10). Understanding Ransomware and Strategies to Defeat It. Available online: https:\/\/www.mcafee.com\/enterprise\/en-us\/assets\/white-papers\/wp-understanding-ransomware-strategies-defeat.pdf."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"144","DOI":"10.1016\/j.cose.2018.01.001","article-title":"Ransomware threat success factors, taxonomy, and countermeasures: A survey and research directions","volume":"74","author":"Maarof","year":"2018","journal-title":"Comput. Secur."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"24","DOI":"10.1145\/3097347","article-title":"Cryptovirology: The birth, neglect, and explosion of ransomware","volume":"60","author":"Young","year":"2017","journal-title":"Commun. ACM"},{"key":"ref_19","unstructured":"Young, A., and Yung, M. (1996, January 6\u20138). Cryptovirology: Extortion-based security threats and countermeasures. Proceedings of the 1996 IEEE Symposium on Security and Privacy, Oakland, CA, USA."},{"key":"ref_20","first-page":"195","article-title":"Awareness education as the key to ransomware prevention","volume":"16","author":"Luo","year":"2007","journal-title":"Inf. Syst. Secur."},{"key":"ref_21","unstructured":"Gostev, A., Unuchek, R., Garnaeva, M., Makrushin, D., and Ivanov, A. (2022, March 10). IT Threat Evolution in Q1 2016. Available online: https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2018\/03\/07192617\/Q1_2016_MW_report_FINAL_eng.pdf."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Thao, C., and Munson, E. (2011, January 19\u201322). Version-aware XML documents. Proceedings of the 11th ACM Symposium on Document Engineering, Mountain View, CA, USA.","DOI":"10.1145\/2034691.2034713"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Coakley, S., Mischka, J., and Thao, C. (2014, January 16). Version-Aware Word Documents. Proceedings of the 2nd International Workshop on (Document) Changes: Modeling, Detection, Storage and Visualization, Fort Collins, CO, USA.","DOI":"10.1145\/2723147.2723152"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Shatnawi, A., Ethan, V.M., and Cheng, T. (2017, January 4\u20137). Maintaining integrity and non-repudiation in secure offline documents. Proceedings of the 2017 ACM Symposium on Document Engineering, Valletta, Malta.","DOI":"10.1145\/3103010.3121038"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Shatnawi, A.S., and Ethan, V.M. (2019, January 23\u201326). Enhanced Automated Policy Enforcement eXchange framework (eAPEX). Proceedings of the ACM Symposium on Document Engineering 2019, Berlin, Germany.","DOI":"10.1145\/3342558.3345408"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"77","DOI":"10.1007\/s11416-008-0092-2","article-title":"Comparative analysis of various ransomware virii","volume":"6","author":"Gazet","year":"2010","journal-title":"J. Comput. Virol."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Kharraz, A., and Kirda, E. (2017). Redemption: Real-time protection against ransomware at end-hosts. International Symposium on Research in Attacks, Intrusions, and Defenses, Springer.","DOI":"10.1007\/978-3-319-66332-6_5"},{"key":"ref_28","unstructured":"Bayer, U., Kruegel, C., and Kirda, E. (2022, March 10). TTAnalyze: A Tool for Analyzing Malware. Available online: https:\/\/citeseerx.ist.psu.edu\/viewdoc\/download?doi=10.1.1.60.7584&rep=rep1&type=pdf."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1109\/MNET.2016.1600110NM","article-title":"Using software-defined networking for ransomware mitigation: The case of cryptowall","volume":"30","author":"Cabaj","year":"2016","journal-title":"IEEE Netw."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Yen, T., Heorhiadi, V., Oprea, A., Reiter, M., and Juels, A. (2014, January 3\u20137). An epidemiological study of malware encounters in a large enterprise. Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, Scottsdale, AZ, USA.","DOI":"10.1145\/2660267.2660330"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"10","DOI":"10.1109\/JIOT.2014.2302386","article-title":"Defending connected vehicles against malware: Challenges and a solution framework","volume":"1","author":"Zhang","year":"2014","journal-title":"IEEE Internet Things J."},{"key":"ref_32","first-page":"44","article-title":"Ransomware behavioural analysis on windows platforms","volume":"40","author":"Hampton","year":"2018","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Subedi, K., Budhathoki, D., and Dasgupta, D. (2018, January 24). Forensic analysis of ransomware families using static and dynamic analysis. Proceedings of the 2018 IEEE Security And Privacy Workshops (SPW), San Francisco, CA, USA.","DOI":"10.1109\/SPW.2018.00033"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1016\/S1353-4858(17)30062-4","article-title":"Leaks and ransoms\u2013the key threats to healthcare organisations","volume":"2017","year":"2017","journal-title":"Netw. Secur."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Kolodenker, E., Koch, W., Stringhini, G., and Egele, M. (2017, January 2\u20136). PayBreak: Defense against cryptographic ransomware. Proceedings of the 2017 ACM on Asia Conference on Computer And Communications Security, Abu Dhabi, United Arab Emirates.","DOI":"10.1145\/3052973.3053035"},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Continella, A., Guagnelli, A., Zingaro, G., De Pasquale, G., Barenghi, A., Zanero, S., and Maggi, F. (2016, January 5\u20138). ShieldFS: A self-healing, ransomware-aware filesystem. Proceedings of the 32nd Annual Conference on Computer Security Applications, Los Angeles, CA, USA.","DOI":"10.1145\/2991079.2991110"},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"389","DOI":"10.1016\/j.cose.2017.11.019","article-title":"R-Locker: Thwarting ransomware action through a honeyfile-based approach","volume":"73","author":"Gonzalez","year":"2018","journal-title":"Comput. Secur."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Sathyanarayan, V., Kohli, P., and Bruhadeshwar, B. (2008). Signature generation and detection of malware families. Australasian Conference on Information Security And Privacy, Springer.","DOI":"10.1007\/978-3-540-70500-0_25"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Scaife, N., Carter, H., Traynor, P., and Butler, K. (2016, January 27\u201330). Cryptolock (and drop it): Stopping ransomware attacks on user data. Proceedings of the 2016 IEEE 36th International Conference On Distributed Computing Systems (ICDCS), Nara, Japan.","DOI":"10.1109\/ICDCS.2016.46"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Shafiq, M., Khayam, S., and Farooq, M. (2008, January 12\u201316). Improving accuracy of immune-inspired malware detectors by using intelligent features. Proceedings of the 10th Annual Conference On Genetic And Evolutionary Computation, Atlanta, GA, USA.","DOI":"10.1145\/1389095.1389112"},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Y\u00fcksel, \u00d6., Hartog, J., and Etalle, S. (2016). Towards useful anomaly detection for back office networks. International Conference on Information Systems Security, Springer.","DOI":"10.1007\/978-3-319-49806-5_30"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Hurtuk, J., Chovanec, M., Ki\u010dina, M., and Billik, R. (2018, January 15\u201316). Case Study of Ransomware Malware Hiding Using Obfuscation Methods. Proceedings of the 2018 16th International Conference on Emerging ELearning Technologies and Applications (ICETA), Stary Smokovec, Slovakia.","DOI":"10.1109\/ICETA.2018.8572218"},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Lim, C., and Ramli, K. (2014, January 19\u201321). Mal-ONE: A unified framework for fast and efficient malware detection. Proceedings of the 2014 2nd International Conference on Technology, Informatics, Management, Engineering & Environment, Bandung, Indonesia.","DOI":"10.1109\/TIME-E.2014.7011581"},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Poudyal, S., Subedi, K., and Dasgupta, D. (2018, January 18\u201321). A Framework for Analyzing Ransomware using Machine Learning. Proceedings of the 2018 IEEE Symposium Series on Computational Intelligence (SSCI), Bangalore, India.","DOI":"10.1109\/SSCI.2018.8628743"},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Cusack, G., Michel, O., and Keller, E. (2018, January 21). Machine learning-based detection of ransomware using sdn. Proceedings of the 2018 ACM International Workshop on Security In Software Defined Networks & Network Function Virtualization, Tempe, AZ, USA.","DOI":"10.1145\/3180465.3180467"},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Andronio, N., Zanero, S., and Maggi, F. (2015). Heldroid: Dissecting and detecting mobile ransomware. International Symposium On Recent Advances in Intrusion Detection, Springer.","DOI":"10.1007\/978-3-319-26362-5_18"},{"key":"ref_47","unstructured":"Stokkel, M. (2020, January 20). Ransomware Detection with bro. Talk at BroCon \u201816. Available online: https:\/\/old.zeek.org\/brocon2016\/brocon2016_abstracts.html#toc-top."},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Cuzzocrea, A., Martinelli, F., and Mercaldo, F. (2018, January 8\u201313). A Novel Structural-Entropy-based Classification Technique for Supporting Android Ransomware Detection and Analysis. Proceedings of the 2018 IEEE International Conference On Fuzzy Systems (FUZZ-IEEE), Rio de Janeiro, Brazil.","DOI":"10.1109\/FUZZ-IEEE.2018.8491637"},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Takeuchi, Y., Sakai, K., and Fukumoto, S. (2018, January 13\u201316). Detecting ransomware using support vector machines. Proceedings of the 47th International Conference on Parallel Processing Companion, Eugene, OR, USA.","DOI":"10.1145\/3229710.3229726"},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Urooj, U., Al-rimy, B.A.S., Zainal, A., Ghaleb, F.A., and Rassam, M.A. (2022). Ransomware Detection Using the Dynamic Analysis and Machine Learning: A Survey and Research Directions. Appl. Sci., 12.","DOI":"10.3390\/app12010172"},{"key":"ref_51","first-page":"40","article-title":"Towards data resilience: The analytical case of crypto ransomware data recovery techniques","volume":"10","author":"Zimba","year":"2018","journal-title":"Int. J. Inf. Technol. Comput. Sci."},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Berrueta Irigoyen, E., Morat\u00f3 Os\u00e9s, D., Maga\u00f1a Lizarrondo, E., and Izal Azc\u00e1rate, M. (2018, January 24\u201326). Ransomware encrypted your files but you restored them from network traffic. Proceedings of the 2018 2nd Cyber Security in Networking Conference, CSnet 2018, Paris, France.","DOI":"10.1109\/CSNET.2018.8602978"},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Thomas, J., and Galligher, G. (2018). Improving backup system evaluations in information security risk assessments to combat ransomware. Comput. Inf. Sci., 11.","DOI":"10.5539\/cis.v11n1p14"},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Subedi, K.P., Budhathoki, D.R., Chen, B., and Dasgupta, D. (December, January 27). RDS3: Ransomware defense strategy by using stealthily spare space. Proceedings of the 2017 IEEE Symposium Series on Computational Intelligence (SSCI), Honolulu, HI, USA.","DOI":"10.1109\/SSCI.2017.8280842"},{"key":"ref_55","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1016\/S1361-3723(20)30087-7","article-title":"Facing ransomware: An approach with private cloud and sentinel software","volume":"2020","year":"2020","journal-title":"Comput. Fraud. Secur."},{"key":"ref_56","doi-asserted-by":"crossref","unstructured":"Kim, G., Kim, S., Kang, S., and Kim, J. (2022). A Method for Decrypting Data Infected with Hive Ransomware. arXiv.","DOI":"10.1016\/j.jisa.2022.103387"},{"key":"ref_57","unstructured":"Ye, H., Dai, W., and Huang, X. (2016). File Backup to Combat Ransomware. (9,317,686), U.S. Patent."},{"key":"ref_58","unstructured":"(2019, December 30). 90 Percent of Ransomware Can Execute without Administrator Rights-Business Reporter. Available online: https:\/\/engageemployee.com\/90-per-cent-ransomware-can-execute-without-administrator-rights\/."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/4\/115\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T22:50:02Z","timestamp":1760136602000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/4\/115"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,4,7]]},"references-count":58,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2022,4]]}},"alternative-id":["fi14040115"],"URL":"https:\/\/doi.org\/10.3390\/fi14040115","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,4,7]]}}}