Jump to content

User:Baker232/sandbox

From Wikipedia, the free encyclopedia
X.1220
Security framework for storage protection against malware attacks on hosts
StatusIn force (Recommendation)
Year started2023
First publishedNovember 13, 2023; 19 months ago (2023-11-13)
Latest version1.0
November 13, 2023; 19 months ago (2023-11-13)
OrganizationITU-T
CommitteeITU-T Study Group 17
SeriesX
Related standardsX.1205, X.1207, X.1218, X.1526
DomainCybersecurity, Data Security
Websitewww.itu.int/ITU-T/recommendations/rec.aspx?rec=15709

X.1220 is an International Telecommunication Union (ITU) standard for storage protection against malware. Malware, including ransomware, can hide and infect files. When a user executes a infected file, the malware spreads out to all stored files in connected network. Malware can encrypt, copy, tamper with, and delete files which damages computer systems.

This standard, X.1220, suggests a new definition "Storage Protection" to construct a new protection layer of storage. The protection layer works in a whitelist process. If a pre-registered application requests data, the protection layer gives read-write real data. Otherwise, the protection layer gives read-only fake data.[1] Malware cannot change read-only data, so users can keep network storage safe against malware.

Purpose

[edit]

The purpose of this standard is to provide a technique to protect data from malware. Malware bypasses network and endpoint protection layers by following methods.(e.g., Encrypted Traffic, Zero-Day Exploits, Polymorphic Malware, Fileless malware, human error that has been guided by Social Engineering). So this standard defines and explains the criteria of non non-bypassable extra protection layer, which is the storage protection layer.

History

[edit]
  • February 23. 2023: 3rd Revised baseline text for X.spmoh[2]
  • November 13, 2024: Redesignated as X.1220 by ITU-T.(X.spmoh) [3]

Cases of Malwares

[edit]

In 2024, ransom costs increased 5 times that of ransom bills in 2023.[6]

Process of Protection

[edit]

This security framework contains a host and a storage protection server. The storage protection server does not belong to the host like Cloud storage or File-hosting service.

References

[edit]