Protecting a NAS Device from Ransomware

Protecting NAS Systems from Cryptoviruses (Ransomware)

The 3-2-1 Rule for Data Backup

Note: The strategy presented here is universal for Synology DiskStation devices running DSM 7.x. The settings have been tested in practice on Synology DS223j.

Table of Contents

  1. Understanding the Threat
  2. Basic Protective Measures
  3. Snapshot Protection (Most Important!)
  4. 3-2-1 Backup Strategy
  5. Network Security
  6. Access Control
  7. Monitoring and Alerts
  8. Recovery Plan

1. Understanding the Threat

How Do Crypto Viruses Work?

Crypto viruses typically infect a NAS in the following ways:

  1. Infected computer — a virus on your Windows/Mac computer encrypts the files on the NAS
  2. Open ports — direct access to the NAS from the internet
  3. Weak passwords — brute-force attacks
  4. Malicious applications — installed unofficial packages
  5. Phishing — theft of the admin password

What happens during an attack?

  • All files are encrypted (photos, documents, videos)
  • Extensions such as .locked, .encrypted, and .crypted are added
  • A ransom is demanded in cryptocurrency
  • RAID 1 DOES NOT HELP - The virus encrypts both drives simultaneously!

2. Key Protective Measures

Step 1: Strong Passwords and 2FA

Changing Passwords:

  1. Control Panel > Users & Groups
  2. Select each user > Edit
  3. Set a STRONG password:
    • At least 12–16 characters
    • Upper- and lowercase letters
    • Numbers and special characters
    • Example: M@gicN4S!2025&Secure
    • Use a password manager (Bitwarden, 1Password)

Enabling two-factor authentication (2FA):

  1. Control Panel > Users & Groups
  2. Select a user > Edit
  3. Go to the “2-factor Authentication” tab
  4. Enable 2FA
  5. Scan the QR code with an app such as:
    • Google Authenticator
    • Microsoft Authenticator
    • Authy

Step 2: Automatically block attacks

Account Protection:

  1. Control Panel > Security > Account
  2. Enable account protection: YES
  3. Enable auto block: YES
  4. Settings:
    • Login attempts: 5
    • Within (minutes): 5
    • Block for (minutes): 60 or permanently
  5. Apply

Trusted IP list (optional):

  • Add the IP addresses of your devices
  • This way, you won’t be blocked accidentally

Step 3: Firewall

Enabling the Firewall:

  1. Control Panel > Security > Firewall
  2. Enable firewall: YES
  3. Tabs: “Firewall Profile” > Edit Default Profile

Recommended rules:


Port | Protocol | Allowed/Blocked | Description |
---------------------------------------------------------------------------+
5000-5001 | TCP | Allow (LAN only)    | DSM Web Interface (HTTP/HTTPS)|
22 | TCP | Deny (or LAN only) | SSH |
21 | TCP | Deny | FTP |
139,445   | TCP | Allow (LAN only)    | SMB/CIFS |
All other | All | Deny | Block everything else from the WAN  |
---------------------------------------------------------------------------+

Important:

  • Allow access ONLY from the local network
  • Block all ports from the Internet (WAN)
  • If you need external access → use QuickConnect or VPN

Step 4: Disable Unnecessary Services

Control Panel > File Services:

  • FTP: Disable (if you don’t need it)
  • FTPS: Disable (if you don’t need it)
  • SMB: Enable (required for Windows sharing)
    • Minimum SMB version: SMB2 or higher (not SMB1!)
  • AFP: Disable (legacy Mac sharing)
  • NFS: Disable (if you’re not using Linux/Unix clients)

Control Panel > Terminal & SNMP:

  • SSH: Disable (or change the port and allow access only from specific IP addresses)
  • Telnet: Disable (NEVER enable it!)

Step 5: Updates

Automatic Updates:

  1. Control Panel > Update & Restore
  2. DSM Update:
    • Install the latest DSM update automatically: YES
    • Send me email notifications of available updates: YES
  3. Check for package updates regularly:
    • Package Center > Settings
    • Auto-update important packages: YES

3. Snapshot Protection (MOST IMPORTANT!)

Why are Snapshots Critical?

Snapshots are THE MOST POWERFUL protection against ransomware! They are snapshots of the file system that:

  • Are created in seconds
  • Take up minimal space (only the changes)
  • Allow recovery to a specific point in time before the attack
  • Ransomware CANNOT encrypt them (if they are configured correctly)

Configuring Snapshots

Prerequisite:

  • You must use the Btrfs file system
  • If you were using ext4, you must recreate the volume (data will be lost!)

Step 1: Enable Snapshot Replication

  1. Package Center
  2. Install “Snapshot Replication”
  3. Launch the application

Step 2: Create a Snapshot Schedule

  1. Snapshot Replication > Snapshots
  2. Select the shared folder (e.g., “Documents”)
  3. Create > Snapshot Schedule

Recommended configuration:

For critical folders (Documents, Photos):

Frequency:

  • Hourly: the last 24 hours (keep 24 snapshots)
  • Daily: the last 7 days (keep 7 snapshots)
  • Weekly: the last 4 weeks (save 4 snapshots)
  • Monthly: the last 3 months (save 3 snapshots)

For less critical folders (Downloads, Temp):

Frequency:

  • Daily: the last 7 days
  • Weekly: the last 4 weeks

Step 3: Lock the Snapshots (IMPORTANT!)

  1. Settings > Advanced
  2. Enable: “Lock snapshots”
  3. Retention period: select a lock period (e.g., 30 days)

This makes the snapshots read-only, and even the administrator cannot delete them!

Step 4: Hiding Snapshot Directories

  1. Snapshot Replication > Settings > Advanced
  2. Disable: “Make snapshot visible”

This hides the #snapshot folder from users and viruses!

Checking Snapshots

Check regularly:

  1. Snapshot Replication > Snapshots
  2. Check to see if snapshots are being created correctly
  3. Check the space used

Restore test:

  • Once a month, try to restore a file from a snapshot
  • This confirms that the process is working

4. 3-2-1 Backup Strategy

The 3-2-1 Rule:

  • 3 copies of the data
  • 2 different types of media
  • 1 offsite copy

Option A: Hyper Backup (recommended)

Installation:

  1. Package Center > Hyper Backup
  2. Install

Option 1: Backup to a USB drive

  1. Connect an external USB drive to the DS223j
  2. Hyper Backup > + (Create backup task)
  3. Select “Local Folder & USB”
  4. Select the USB drive
  5. Select the folders to back up
  6. Encryption: REQUIRED!
    • Set a strong password
    • Save it in a password manager
  7. Schedule:
    • Daily backup during the night (e.g., 3:00 AM)
    • Compression: Enable
    • Intelligent versioning: Enable (keep 256 versions)

Option 2: Cloud backup

  1. Hyper Backup > + (Create)
  2. Select a cloud service:
    • Synology C2 Storage (paid, but native)
    • Google Drive (free up to 15GB)
    • Dropbox
    • OneDrive
    • Backblaze B2 (inexpensive, $6/TB/month)
  3. Set up connection
  4. Select the folders
  5. Encryption: REQUIRED!
  6. Schedule: Weekly or Daily

Option 3: Backup to another NAS (if you have one)

  1. Hyper Backup > +
  2. Remote NAS Device
  3. Enter the IP and credentials for the second NAS

Important settings in Hyper Backup:

  • Backup rotation: Smart Recycle (to save space)
  • Integrity check: Enable (checks the backups)
  • Notifications: Email on success/failure

Option B: Cloud Sync (for synchronization)

Difference between Hyper Backup and Cloud Sync:

  • Hyper Backup: versioned backup (you can roll back)
  • Cloud Sync: real-time synchronization (like Dropbox)

For ransomware protection: Hyper Backup is better!

Cloud Sync is useful for:

  • Quick access to files from anywhere
  • Sharing with others
  • BUT: ransomware can sync encrypted files

If you use Cloud Sync:

  1. Package Center > Cloud Sync
  2. Set up the connection
  3. IMPORTANT: Enable versioning in the cloud:
    • Google Drive: retains versions for 30 days
    • Dropbox: retains versions for 30 days (or 180 with a paid plan)

5. Network Security

Step 1: No direct access from the Internet!

Check port forwarding:

  1. Log in to the router’s admin panel
  2. Check Port Forwarding / Virtual Server / NAT rules
  3. Delete ALL rules for:
    • Ports 5000, 5001 (DSM)
    • Port 22 (SSH)
    • Ports 445, 139 (SMB)
    • Port 21 (FTP)

If external access is required, use:

Option A: QuickConnect (most secure)

  1. Control Panel > External Access > QuickConnect
  2. Enable QuickConnect
  3. Create a QuickConnect ID (for example: mynasname)
  4. Access via: quickconnect.to/mynasname
  5. Traffic passes through Synology servers (secure)

Option B: VPN Server (more complex, but very secure)

  1. Package Center > VPN Server
  2. Install
  3. Configure OpenVPN or L2TP/IPSec
  4. Connect to the VPN as if you were on the local network
  5. Then access the NAS locally

DO NOT use:

  • DDNS + Port Forwarding (dangerous!)
  • UPnP (automatically opens ports)

Step 2: Isolating the NAS on the network (advanced)

If your router supports VLANs:

  1. Create a separate VLAN for the NAS
  2. Restrict access between VLANs
  3. This way, if a computer becomes infected, it cannot directly access the NAS

If you don’t have VLANs:

  • Place the NAS on a separate subnet (if possible)
  • Use a guest network for untrusted devices

6. Access Control

Step 1: Principle of Least Privilege

Creating a read-only user:

  1. Control Panel > User & Group > Create
  2. Name: “readonly_user”
  3. Password: strong password
  4. Shared folder permissions:
    • For critical folders: Read-only
    • For work folders: Read/Write (only if necessary)

Use the read-only user for:

  • Viewing photos/videos
  • Listening to music
  • Reading documents

Use the read/write user ONLY when:

  • Copying new files
  • Editing documents
  • Then log in with the read-only account

Step 2: Restricting SMB access

Control Panel > File Services > SMB > Advanced:

  1. Max SMB protocol: SMB3
  2. Min SMB protocol: SMB2
  3. Enable: “Opportunistic locking” (helps against ransomware)

Windows additional protection:
On the Windows computer:

  1. Map the network drive using “Connect using different credentials”
  2. Map as a read-only user by default
  3. Unmap after working with the files

Step 3: Disable the Recycle Bin (controversial)

The Recycle Bin can help with accidental deletions, BUT:

  • Ransomware can also encrypt files in the Recycle Bin
  • It takes up space

Solution:

  • For critical folders: Disable the Recycle Bin
  • Rely on system snapshots for recovery
  • For working folders: Enable (for convenience)

7. Monitoring and Alerts

Step 1: Set up email notifications

Control Panel > Notification > Email:

  1. Enable email notifications
  2. SMTP settings:
    • Service provider: select one or Custom
    • For Gmail:
      • SMTP server: smtp.gmail.com
      • Port: 587
      • SMTP authentication: Yes
      • Username: your Gmail address
      • Password: App Password (not your regular password!)
        • Google Account > Security > 2-Step Verification > App passwords
  3. Send test email

Enable notifications for:

  • System: Critical errors, updates
  • Storage: Disk failures, space warnings
  • Security: Login attempts, firewall blocks
  • Backup: Hyper Backup success/failure
  • Snapshots: Snapshot creation failures

Step 2: Log Center

  1. Package Center > Log Center
  2. Install
  3. Configure log archiving (stores them for a long time)

Check regularly:

  • Connection logs for unusual activity
  • File access logs for suspicious operations
  • Security logs for failed login attempts

Step 3: Security Advisor

  1. Control Panel > Security Advisor
  2. Run a security scan regularly (weekly)
  3. Fix all High and Medium severity issues

Important checks:

  • Default admin account (has it been changed?)
  • Weak passwords
  • Exposed services
  • Outdated packages

8. Recovery Plan

If you suspect a ransomware attack:

STEP 1: IMMEDIATE ACTIONS

  1. DISCONNECT FROM THE NETWORK!
    • Unplug the Ethernet cable from the NAS IMMEDIATELY
    • Do not turn off the power (this may damage the drives)
  2. Isolate the infected computers
  3. DO NOT pay the ransom!

STEP 2: ASSESS THE DAMAGE

  1. Log in via HDMI/USB keyboard if possible
  2. Or briefly connect to the network to check the status
  3. Check which files are affected:
    • Are there any new file extensions (.locked, .encrypted)?
    • Are there any ransom note files?

STEP 3: RECOVERY FROM A SNAPSHOT

If you have snapshots (that’s why they’re critical!):

  1. Snapshot Replication
  2. Select the affected folder
  3. View snapshots from before the attack
  4. Restore:
    • Option A: Restore the entire folder
    • Option B: Browse the snapshot and copy specific files

Restore process:

  1. Snapshot Replication > Snapshots
  2. Select the shared folder
  3. Select a snapshot from before the attack (check the date/time)
  4. Click Action > Restore
  5. Select:
    • - Restore to original location (replaces the files)
    • - or Clone to new location (preserves the encrypted files)
  6. Confirm

STEP 4: RESTORE FROM HYPER BACKUP

If snapshots are not sufficient:

  1. Hyper Backup > Restore
  2. Select a backup task
  3. Select the version prior to the attack
  4. Restore the selected folders/files

STEP 5: CLEANUP AND PREVENTION

  1. Scan ALL computers with antivirus
  2. Change ALL passwords
  3. Review security settings
  4. Upgrade DSM and all packages
  5. Check firewall rules
  6. Check which users/applications have access

Security Checklist

Daily:

  • Automatic snapshots are working
  • Monitor for unusual activity

Weekly:

  • Check email notifications
  • Verify that Hyper Backup was successful
  • Scan with Security Advisor

Monthly:

  • Test a restore from a snapshot
  • Test a restore from Hyper Backup
  • Check disk space
  • Review logs in Log Center
  • Check for DSM updates

As needed:

  • Change passwords (every 3–6 months)
  • Review user permissions
  • Update the backup strategy

Additional recommendations

For Windows computers:

Ransomware Protection (Windows 11/10):

  • Settings > Update & Security > Windows Security
  • Virus & threat protection > Ransomware protection
  • Enable Controlled folder access
  • Add NAS folders to Protected folders

Antivirus:

  • Install a high-quality antivirus (Windows Defender is a good option)
  • Enable real-time protection
  • Regular scans

Rule:

  • DO NOT open suspicious attachments
  • DO NOT click on links in emails from strangers
  • Update Windows regularly

For Mac computers:

  1. Gatekeeper: Keep it enabled
  2. XProtect: Built-in antimalware
  3. Time Machine: Back up your Mac to a separate drive

Offline backup

The most secure protection:

  1. Buy 2–3 external USB drives
  2. Perform a monthly backup to one of the drives
  3. UNMOUNT the drive and store it in a safe place
  4. Rotate the drives

That way, even in the worst-case scenario, you’ll have an offline copy!

Summary

The Golden Rules Against Ransomware:

  1. ✅ Locked snapshots—the most important protection!
  2. ✅ 3-2-1 Backup Strategy—including offsite
  3. ✅ Strong Passwords + 2FA—on all accounts
  4. ✅ Firewall + blocked ports—no direct WAN access
  5. ✅ Updates — always the latest DSM and packages
  6. ✅ Read-only access — whenever possible
  7. ✅ Monitoring — email alerts and regular checks
  8. ✅ Testing — regularly test restores

Remember:

RAID 1 protects against hardware failure, BUT NOT against ransomware!

The only true protection is:

  • Snapshots (cannot be encrypted)
  • Offsite backups (physically separate)
  • Strong security (attack prevention)

If you follow this guide:

  • ✅ Ransomware won’t be able to destroy your data
  • ✅ You can recover in minutes or hours
  • ✅ You can sleep soundly

Good luck, stay cautious, and stay safe!


Comments

No Comments To Display

Add Comment

You have 3 tries before the form temporarily locks.