{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,31]],"date-time":"2026-01-31T09:55:05Z","timestamp":1769853305594,"version":"3.49.0"},"reference-count":45,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2024,10,1]],"date-time":"2024-10-01T00:00:00Z","timestamp":1727740800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"National Science Foundation","award":["2225424-CNS"],"award-info":[{"award-number":["2225424-CNS"]}]},{"name":"National Science Foundation","award":["1928349-CNS"],"award-info":[{"award-number":["1928349-CNS"]}]},{"name":"National Science Foundation","award":["2043022-DGE"],"award-info":[{"award-number":["2043022-DGE"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>In the history of access control, nearly every system designed has relied on the operating system (OS) to enforce the access control protocols. However, if the OS (and specifically root access) is compromised, there are few if any solutions that can get users back into their system efficiently. In this work, we have proposed a novel approach that allows secure and efficient rollback of file access control after an adversary compromises the OS and corrupts the access control metadata. Our key observation is that the underlying flash memory typically performs out-of-place updates. Taking advantage of this unique feature, we can extract the \u201cstale data\u201d specific for OS access control, by performing low-level disk forensics over the raw flash memory. This allows efficiently rolling back the OS access control to a state pre-dating the compromise. To justify the feasibility of the proposed approach, we have implemented it in a computing device using file system EXT2\/EXT3 and open-sourced flash memory firmware OpenNFM. We also evaluated the potential impact of our design on the original system. Experimental results indicate that the performance of the affected drive is not significantly impacted.<\/jats:p>","DOI":"10.3390\/jcp4040038","type":"journal-article","created":{"date-parts":[[2024,10,1]],"date-time":"2024-10-01T11:08:47Z","timestamp":1727780927000},"page":"805-822","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Reversing File Access Control Using Disk Forensics on Low-Level Flash Memory"],"prefix":"10.3390","volume":"4","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-8978-2684","authenticated-orcid":false,"given":"Caleb","family":"Rother","sequence":"first","affiliation":[{"name":"Department of Computer Science, Michigan Technological University, Houghton, MI 49931, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9372-9607","authenticated-orcid":false,"given":"Bo","family":"Chen","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Michigan Technological University, Houghton, MI 49931, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2024,10,1]]},"reference":[{"key":"ref_1","unstructured":"Foundation, T.L. (2024, May 22). Understanding Linux Permissions. Available online: https:\/\/www.linuxfoundation.org\/blog\/blog\/classic-sysadmin-understanding-linux-file-permissions."},{"key":"ref_2","unstructured":"(2024, May 06). Critical RCE Vulnerability in Linux Kernel Let Hackers Compromise the Entire Systems Remotely. Available online: https:\/\/cybersecuritynews.com\/linux-kernel-bug-3\/."},{"key":"ref_3","unstructured":"Microsoft (2024, May 21). CVE-2021-34535. Available online: https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34535."},{"key":"ref_4","unstructured":"NIST (2024, May 23). CVE-2018-4121, Available online: https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-4121."},{"key":"ref_5","unstructured":"(2024, May 21). Man Chmod. Available online: https:\/\/linux.die.net\/man\/1\/chmod."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Gupta, A., Kim, Y., and Urgaonkar, B. (2009). DFTL: A flash translation layer employing demand-based selective caching of page-level address mappings. Proceedings of the ACM, ACM.","DOI":"10.1145\/1508244.1508271"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Hardock, S., Petrov, I., Gottstein, R., and Buchmann, A. (2017, January 14\u201319). From In-Place Updates to In-Place Appends: Revisiting Out-of-Place Updates on Flash. Proceedings of the 2017 ACM International Conference on Management of Data, New York, NY, USA. SIGMOD \u201917.","DOI":"10.1145\/3035918.3035958"},{"key":"ref_8","unstructured":"Wirzenius, L., Oja, J., Stafford, S., and Weeks, A. (2024, May 22). Filesystems. Available online: https:\/\/tldp.org\/LDP\/sag\/html\/filesystems.html."},{"key":"ref_9","unstructured":"(2024, May 21). OSDev Wiki. Available online: https:\/\/wiki.osdev.org\/Ext2."},{"key":"ref_10","unstructured":"(2024, May 21). ext3 Filesystem. Available online: https:\/\/docs.kernel.org\/filesystems\/ext3.html."},{"key":"ref_11","unstructured":"(2024, May 21). ext4 Filesystem. Available online: https:\/\/www.kernel.org\/doc\/html\/v4.19\/filesystems\/ext4\/index.html."},{"key":"ref_12","unstructured":"Arpaci-Dusseau, R.H., and Arpaci-Dusseau, A.C. (2023). Operating Systems: Three Easy Pieces, Arpaci-Dusseau Books. Chapter 3."},{"key":"ref_13","unstructured":"(2024, May 20). OSDev Wiki. Available online: https:\/\/wiki.osdev.org\/MBR."},{"key":"ref_14","unstructured":"Gruenbacher, A. (2003, January 9\u201314). POSIX Access Control Lists on Linux. Proceedings of the 2003 USENIX Annual Technical Conference (USENIX ATC 03), San Antonio, TX, USA."},{"key":"ref_15","unstructured":"Govindavajhala, S., and Appel, A.W. (2006). Windows Access Control Demystified, Princeton University."},{"key":"ref_16","unstructured":"Liu, Z. (2024, May 22). SSD and HDD Statistics from EaseUS. Available online: https:\/\/www.tomshardware.com\/news\/ssd-and-hdd-statistics-from-easeus."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"1666","DOI":"10.1109\/JPROC.2017.2713127","article-title":"Error Characterization, Mitigation, and Recovery in Flash-Memory-Based Solid-State Drives","volume":"105","author":"Cai","year":"2017","journal-title":"Proc. IEEE"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"480","DOI":"10.1108\/IJICC-02-2021-0034","article-title":"Flash translation layer: A review and bibliometric analysis","volume":"14","author":"Luo","year":"2021","journal-title":"Int. J. Intell. Comput. Cybern."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"366","DOI":"10.1109\/TCE.2002.1010143","article-title":"A space-efficient flash translation layer for compactflash systems","volume":"48","author":"Kim","year":"2002","journal-title":"IEEE Trans. Consum. Electron."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"332","DOI":"10.1016\/j.sysarc.2009.03.005","article-title":"A survey of Flash Translation Layer","volume":"55","author":"Chung","year":"2009","journal-title":"J. Syst. Archit."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Guan, L., Jia, S., Chen, B., Zhang, F., Luo, B., Lin, J., Liu, P., Xing, X., and Xia, L. (2017, January 4\u20138). Supporting Transparent Snapshot for Bare-metal Malware Analysis on Mobile Devices. Proceedings of the 33rd Annual Computer Security Applications Conference, Orlando, FL, USA.","DOI":"10.1145\/3134600.3134647"},{"key":"ref_22","unstructured":"Wei, M.Y.C., Grupp, L.M., Spada, F.E., and Swanson, S. (2011, January 15\u201317). Reliably erasing data from flash-based solid state drives. Proceedings of the 9th USENIX Conference on File and Storage Technologies (FAST 11), San Jose, CA, USA."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Huang, J., Xu, J., Xing, X., Liu, P., and Qureshi, M.K. (November, January 30). FlashGuard: Leveraging Intrinsic Flash Properties to Defend Against Encryption Ransomware. Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, Dallas, TX, USA.","DOI":"10.1145\/3133956.3134035"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Wang, P., Jia, S., Chen, B., Xia, L., and Liu, P. (2019, January 25\u201327). Mimosaftl: Adding secure and practical ransomware defense strategy to flash translation layer. Proceedings of the Ninth ACM Conference on Data and Application Security and Privacy, Richardson, TX, USA.","DOI":"10.1145\/3292006.3300041"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Baek, S., Jung, Y., Mohaisen, A., Lee, S., and Nyang, D. (2018, January 2\u20136). Ssd-insider: Internal defense of solid-state drive against ransomware with perfect data recovery. Proceedings of the 2018 IEEE 38th International Conference on Distributed Computing Systems (ICDCS), Vienna, Austria.","DOI":"10.1109\/ICDCS.2018.00089"},{"key":"ref_26","first-page":"1762","article-title":"SSD-assisted ransomware detection and data recovery techniques","volume":"70","author":"Baek","year":"2020","journal-title":"IEEE Trans. Comput."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Chen, N., Dafoe, J., and Chen, B. (2022, January 7\u201311). Poster: Data Recovery from Ransomware Attacks via File System Forensics and Flash Translation Layer Data Extraction. Proceedings of the 2022 ACM Conference on Computer and Communications Security, Los Angeles, CA, USA.","DOI":"10.1145\/3548606.3563538"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"245","DOI":"10.1109\/LCA.2018.2883431","article-title":"Amoeba: An autonomous backup and recovery ssd for ransomware attack defense","volume":"17","author":"Min","year":"2018","journal-title":"IEEE Comput. Archit. Lett."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"2038","DOI":"10.1109\/TCAD.2021.3099084","article-title":"A content-based ransomware detection and backup solid-state drive for ransomware defense","volume":"41","author":"Min","year":"2021","journal-title":"IEEE Trans. Comput.-Aided Des. Integr. Circuits Syst."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Park, J., Jung, Y., Won, J., Kang, M., Lee, S., and Kim, J. (2019, January 2\u20136). RansomBlocker: A low-overhead ransomware-proof SSD. Proceedings of the 56th Annual Design Automation Conference 2019, Las Vegas, NV, USA.","DOI":"10.1145\/3316781.3317889"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"311","DOI":"10.3390\/jcp2020017","article-title":"Defending against OS-Level Malware in Mobile Devices via Real-Time Malware Detection and Storage Restoration","volume":"2","author":"Chen","year":"2022","journal-title":"J. Cybersecur. Priv."},{"key":"ref_32","unstructured":"Xie, W., Chen, N., and Chen, B. (2022, January 17\u201319). Enabling Accurate Data Recovery for Mobile Devices against Malware Attacks. Proceedings of the 18th EAI International Conference on Security and Privacy in Communication Networks, Virtual Event."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"1193","DOI":"10.1016\/j.peva.2011.07.010","article-title":"ShiftFlash: Make flash-based storage more resilient and robust","volume":"68","author":"Huang","year":"2011","journal-title":"Perform. Eval."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Son, Y., Choi, J., Jeon, J., Min, C., Kim, S., Yeom, H.Y., and Han, H. (2017, January 19\u201322). SSD-Assisted Backup and Recovery for Database Systems. Proceedings of the 2017 IEEE 33rd International Conference on Data Engineering (ICDE), San Diego, CA, USA.","DOI":"10.1109\/ICDE.2017.88"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Dafoe, J., Singh, H., Chen, N., and Chen, B. (2023, January 12\u201313). Enabling Real-Time Restoration of Compromised ECU Firmware in Connected and Autonomous Vehicles. Proceedings of the 2023 EAI International Conference on Security and Privacy in Cyber Physical Systems and Smart Vehicles, Chicago, IL, USA.","DOI":"10.1007\/978-3-031-51630-6_2"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1016\/j.sysarc.2014.11.002","article-title":"Data loss recovery for power failure in flash memory storage systems","volume":"61","author":"Jung","year":"2015","journal-title":"J. Syst. Archit."},{"key":"ref_37","unstructured":"Code, G. (2024, September 27). OpenNFM. Available online: https:\/\/github.com\/IMCG\/opennfm."},{"key":"ref_38","unstructured":"(2024, May 20). Olimex LPC-H3131. Available online: https:\/\/www.olimex.com\/Products\/ARM\/NXP\/LPC-H3131\/."},{"key":"ref_39","unstructured":"(2024, May 20). Intel Core I9-10900KF. Available online: https:\/\/ark.intel.com\/content\/www\/us\/en\/ark\/products\/199331\/intel-core-i9-10900kf-processor-20m-cache-up-to-5-30-ghz.html."},{"key":"ref_40","unstructured":"Tankasala, D., Chen, N., and Chen, B. (2024, May 20). Creating A Testbed for Flash Memory Research via LPC-H3131 and OpenNFM\u2014Linux Version. Available online: https:\/\/snp.cs.mtu.edu\/outreach\/OpenNFM-LPC-Ubuntu.pdf."},{"key":"ref_41","unstructured":"Firmianay (2024, May 21). Chapter 16: The Page Cache and Page Writeback. Available online: https:\/\/github.com\/firmianay\/Life-long-Learner\/blob\/master\/linux-kernel-development\/chapter-16.md."},{"key":"ref_42","unstructured":"Microsoft (2024, May 21). How NTFS Works. Available online: https:\/\/learn.microsoft.com\/en-us\/previous-versions\/windows\/it-pro\/windows-server-2003\/cc781134(v=ws.10)."},{"key":"ref_43","unstructured":"(2024, May 21). FAT File Systems. Available online: https:\/\/www.ntfs.com\/fat_systems.htm."},{"key":"ref_44","unstructured":"ELMChan (2024, May 22). exFAT filesystem. Available online: http:\/\/elm-chan.org\/docs\/exfat_e.html."},{"key":"ref_45","unstructured":"(2024, May 05). OSDev Wiki. Available online: https:\/\/wiki.osdev.org\/FAT."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/4\/4\/38\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T16:08:46Z","timestamp":1760112526000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/4\/4\/38"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,1]]},"references-count":45,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2024,12]]}},"alternative-id":["jcp4040038"],"URL":"https:\/\/doi.org\/10.3390\/jcp4040038","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,10,1]]}}}