Enhanced Ransomware Detection and Response Using Programmable Data Infrastructure
Authors/Creators
Description
This paper presents the design and implementation of a managed detec- tion and response (MDR) system for ransomware threats targeting relational databases. The solution is built on top of Delphix, leveraging its capabilities as a Programmable Data Infrastructure to enable a fast, flexible, and fully automated control process. The development is based on the client’s existing infrastructure, where highly confidential database records are replicated across multiple testing environ- ments within a CI/CD pipeline. These environments reside in a less isolated network segment, accessible by heterogeneous identities by design, introduc- ing inherent security risks. The paper begins with a background and motivation section, outlining key concepts necessary to understand the solution and its alignment with busi- ness requirements. The discussion is risk-driven, starting with critical vul- nerabilities and documented attack kill chains in CI/CD pipelines, followed by security constraints in complex cloud environments, and culminating in an analysis of the most pervasive and damaging threat, the ransomware. Next, the project chapter details the state-of-the-art solution, covering the final infrastructure design, control logic, data flows, and critical software com- ponents. The execution workflow of these components is explored through code snippets, highlighting key design and implementation choices that es- tablish the solution as a flexible framework for enforcing various security controls across heterogeneous environments.
Files
Tesi_Triennale_Diego_Gobbetti.pdf
Additional details
Software
- Repository URL
- https://github.com/diekgbbtt/ransomcontrolorchestration
- Programming language
- Python , Java
- Development Status
- Abandoned