Method and system for detecting anomalies caused by malware in a storage device using an AI co-processor

The integration of an AI co-processor in SSDs for monitoring SSD controller operations addresses latency and resource issues in existing SSD security systems, enabling real-time, efficient detection of malicious software threats and maintaining data integrity.

CN113939818BActive Publication Date: 2025-07-15FLEXXON PTE LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202080038671.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-05-22
Filing Date
2020-08-21
Publication Date
2025-07-15
Estimated Expiration
2040-08-21

AI Technical Summary

Technical Problem

The prior art is difficult to effectively detect and prevent ransomware attacks in solid-state drives (SSDs), making it difficult to ensure data security, and existing methods may cause resource overload, information leakage and frequent firmware updates, affecting system stability.

Method used

The NVM shortcut protocol or AHCI command of the SSD controller chipset is used to monitor the NVM shortcut protocol or AHCI command, and the ransomware attack is detected by measuring the electromotive force signature, and the self-training mode and convolutional layer algorithm are used to monitor data integrity in real time, independent of the SSD controller resources, reduce latency and detect threats in advance.

Benefits of technology

It realizes early detection of ransomware attacks, improves data security and system stability, reduces resource overload and firmware update frequency, and ensures real-time and accuracy of data integrity monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113939818B_ABST
    Figure CN113939818B_ABST
Patent Text Reader

Abstract

A computer-implemented system and method for performing electromotive force analysis of a storage device, comprising a storage device; an artificial intelligence co-processor (AI co-processor) chipset; a thin inductive coil disposed near a portion of the surface of the storage device for capturing data from the electromotive radiation generated by the storage device; an analog-to-digital converter; and at least one probe for communicating the captured data to the analog-to-digital converter. The data is captured by the thin inductive coil and communicated to the analog-to-digital converter via at least one probe, and the analog-to-digital converter digitizes the voltage level of the captured data and communicates the digitized and amplified result to the AI co-processor. The AI co-processor chipset performs analysis of the data to detect any anomalies in the operation of the storage device and outputs the result for further processing. Embodiments include the use of NVM Express protocol or AHCI controller engine, thus enabling real-time detection of any hardware threats or attacks such as side-channel attacks, voltage glitches, and any other hardware changes. Embodiments can detect malicious or non-malicious activities such as ransomware, viruses, and malware by measuring the electromotive potential energy caused by the abnormal activities.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - reference to related patent applications

[0002] This application claims the benefit of Singapore Provisional Application No. 10201907989W, filed on August 29, 2019, which is incorporated herein by reference in its entirety. Technical Field

[0003] Embodiments of the subject matter of the present invention relate to systems, devices, and methods for detecting anomalies in a storage device such as a solid - state drive (SSD), and more particularly, for independently detecting malware attacks using hardware and software. Background Art

[0004] A common problem associated with SSDs is keeping the stored data secure and protected from any type of malware attack (e.g., ransomware attack), while simultaneously monitoring the security of the SSD in real - time. The threats and attacks of ransomware and other malware are increasing over time and becoming more complex in nature, making them more difficult to detect and neutralize, and requiring more hardware and software resources and frequent updates from system users or administrators.

[0005] Examples of prior art for artificial intelligence - based detection methods for threats or abnormal activities such as ransomware, viruses, and malware include firmware - based, software - based, or hardware - based technical solutions. In some of these prior art examples, the firmware or software technical solutions are located within the solid - state drive controller chipset in accordance with the original firmware, and thus these elements rely on the resources of the solid - state drive controller chipset. These types of prior art configurations may cause operational time delays due to delays in threat analysis activities. In these prior art examples, in the case of insufficient random access memory (RAM) capacity, the memory resources may easily be overloaded, or CPU usage, power, and current overloads may also occur. Under certain types of attacks such as side - channel or differential power analysis (DPA) attacks, these problems may cause information leakage.

[0006] Moreover, the prior art typically has firmware portability issues because the firmware in a device needs to be updated when the solid-state drive microcontroller architecture changes. These updates may require human intervention, which may also lead to an increase in the frequency of system defects. In addition, firmware or software integrations that fail at these points may render the entire solid-state drive inoperable. In some examples of using hardware solutions, the prior art involves tamper detection, detecting counterfeit hardware and unauthorized firmware, and detecting software and firmware types that may degrade the functionality of the device. In some prior art hardware solutions, the methods used focus on the functions available in the integrated circuit flash memory and do not check the integrity of the data stored in the solid-state drive NAND flash memory. In addition, this type of prior art monitors data without using or integrating artificial intelligence.

[0007] In addition, prior art methods for detecting ransomware attacks in solid-state drives utilize the NVM Express (NVMe) protocol or AHCI. Many also utilize firmware- or software-based solutions that require human intervention for code updates as the architecture changes. Due to more instructions being executed, the prior art also has latency in information processing regarding SSD controller chipset resources such as RAM, DMA, and flash memory. SUMMARY OF THE INVENTION

[0008] Exemplary embodiments provide computer-implemented methods, devices, and systems that detect ransomware attacks, threats, or activities targeting a solid-state drive (SSD) storage device using state-of-the-art technology by applying an artificial intelligence co-processor (AI co-processor) to monitor the input and / or output of the NVM Express (NVMe / NVM Express) protocol or AHCI commands of an SSD controller chipset and by linearly measuring the electromotive force induced during the execution of the NVMe protocol or AHCI commands by the solid-state drive. Due to the importance of data integrity, the embodiments of the claimed subject matter allow users and administrators to have an additional layer of security protection against ransomware threats or attacks that conventional security tools may have difficulty detecting.

[0009] Many of the embodiments include flexible printed circuit boards, rigid flex printed circuit boards, and / or rigid printed circuit boards. Moreover, many of these boards have a low profile thickness. These embodiments allow for scalability and can thus be integrated into any existing solid-state drive format.

[0010] The embodiments also include using ASICs, FPGAs, and / or embedded FPGAs together with passive and / or active components common in a single printed circuit board for system integration. The embodiments also integrate ASICs, FPGAs, and / or embedded FPGAs with a solid state drive chipset, or in some embodiments, the components may be placed between the printed circuit board and the protective cover of the solid state drive. In other embodiments, the components may be arranged to cover the printed circuit board, using a form factor that is the same as or similar to the target solid state drive printed board layout. In some embodiments of these embodiments, the inductor of the small inductor may be placed on top of or next to the integrated circuit of the solid state drive, such that the embodiments are directly connected to the circuit via a connector or via vias soldered in the printed circuit board of the AI co-processor.

[0011] In many embodiments of these embodiments, the AI co-processor is programmed to have a self-training or self-learning mode. During the self-training or self-learning mode, the solid state drive device may execute a series of predefined NVM express protocols and / or AHCI commands during a specified time period. During this execution, the AI co-processor receives a data stream from the solid state drive device via a secure communication bus, such as the I2C protocol, SPI protocol, USB, LVDS, and / or any specified protocol defined by the user or predefined at the factory. In these embodiments, the AI co-processor uses an external or internal analog-to-digital converter with high resolution bits to measure the electromotive force generated by the solid state drive controller chipset in a linear mode, for generating one or more signature patterns presented in a series of binary or hexadecimal codes. These codes may then be stored, for example, in one or more secure flash elements of the AI co-processor. In these embodiments, the generated patterns may have rich values and lean values, which may be used as threshold limits for any abnormal threats, attacks, and / or activities caused, for example, by malware or ransomware.

[0012] The embodiments may also provide a convolutional layer algorithm module embedded within the AI co-processor, such that the embodiments are capable of training themselves without utilizing an external deep learning model, while still being able to monitor the integrity of the stored data in real time.

[0013] Many embodiments of the embodiments operate by bonding or providing a dedicated hardware AI co-processor, which improves the performance and reliability of the security of the device, and reduces the time delay by eliminating the RAM overflow of the target solid state drive by using independent resources of hardware including, for example, flash memory and other types of memory such as RAM. Some embodiments use ultra-low voltage to prevent failure mode operation.

[0014] Many embodiments are coupled to or communicate with a target solid state drive (SSD) controller via a secure connection bus. Some embodiments use intelligent algorithms for early detection of threat attacks such as malware or ransomware attacks before the attacks can spread. Embodiments herein can be used with some different integrated circuit packages, for example, embodiments can be integrated with any SSD controller architecture without firmware updates or synchronization with the target SSD controller.

[0015] Many embodiments of the embodiments herein allow for a significant reduction in time to market while providing a reliable method to monitor the integrity of data and the associated operations of associated devices related to the firmware and controller methods integrated with one or more SSDs. In an exemplary attack, a ransomware attack uses the top layer of the host system to execute one or more sequences of NVMe or AHCI commands external to the firmware of the target SSD integrated circuit flash memory. In response, one embodiment will sample or measure the electromotive force generated by ransomware activities and operations through the SSD using the NVMe protocol or the AHCI protocol. During the attack activity, the ransomware attack includes a malicious sequence of NVMe / or AHCI commands that causes the target SSD integrated circuit to generate a series of electromotive force signatures that are unique relative to other threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Embodiments of the claimed subject matter will be described by way of example with reference to the drawings, in which:

[0017] Figure 1 A schematic block diagram of an AI co-processor module and an external integrated circuit block according to an embodiment of the claimed subject matter is shown, which shows a ransomware detector operating in conjunction with an SSD using the NVMe protocol or the AHCI protocol;

[0018] Figure 2 A three-dimensional view of an SSD according to an embodiment of the claimed subject matter is shown, the SSD having the form factor of a modular M.2 card integrated in a printed circuit board;

[0019] Figure 3 A top-down cutaway view of a modular M.2 card according to an embodiment of the claimed subject matter is shown, where the SSD controller is integrated with an AI co-processor ransomware detector configured as a hardware solution;

[0020] Figure 4 The correlation of the NVMe / AHCI commands relative to the measured Vemf linearly over time according to an embodiment of the claimed subject matter is shown;

[0021] Figure 5AShows exemplary voltage levels of electromotive force linear with time in the presence of anomalies such as ransomware and in normal operating modes, according to embodiments of the claimed subject matter;

[0022] Figure 5B Shows the cross-correlation of sampled bytes of NVMe / AHCI buffered commands with detected ransomware or exemplary anomalies; and

[0023] Figure 6 Shows an AI co-processor interconnection system according to embodiments of the claimed subject matter. Detailed Description

[0024] According to embodiments of the claimed subject matter, various devices, systems, and method systems are used to detect malware, including attacks by malware that includes ransomware.

[0025] Embodiments can be utilized to protect data stored within a storage device, which utilizes artificial intelligence by sampling an electromotive force caused by abnormal current flow indicating possible malware or other threats. Anomalies include changes in the input / output activities of the storage device, such as those found during ransomware access to logical block addresses.

[0026] In many current embodiments, an AI co-processor is bonded or placed near a solid-state drive controller chipset that utilizes the NVM Express protocol or AHCI. In several embodiments, the AI co-processor can be placed together with, collinearly with, or on the top side of the solid-state drive controller chip. In certain embodiments, the AI co-processor is embedded in a user-customized ASIC, an embedded FPGA, or an SoC+FPGA, as a single core or multi-core.

[0027] These embodiments will operate independently of the solid-state drive controller chipset resources to detect ransomware attacks in real time. In one example of use, each of many threats or attacks has its own electromotive force (EMF) pattern signature, and these signatures are used for further analysis and compared with the electromotive force (EMF) of one or more solid-state drive controller chipsets in normal operation.

[0028] Many embodiments of the described embodiments provide a user - friendly technical solution to integrate the described embodiments with an existing solid - state drive controller integrated circuit board, using a standard communication bus that allows scalability with any type of solid - state drive utilizing the NVM Express protocol and / or AHCI. The detection of malware is characterized by an AI co - processor that has a dedicated bus communication link with the solid - state drive controller integrated circuit via a defined security protocol. All NVMe sequences (including administrative sequence commands and user sequence commands) can be shared with the AI co - processor in real - time. The AI co - processor will measure the electromotive force (EMF) generated by the integrated circuits of the solid - state drive chipset during any normal operating condition and during a malware (including ransomware) attack, as well as any received NVMe, any AHCI sequence, any NVMe, or any AHCI stream.

[0029] One advantage of many embodiments of the described embodiments is real - time analysis with minimized time delay, which can be helpful for use in cloud storage server applications or high - end platform server applications. Many embodiments of these embodiments allow early malware / ransomware detection, which helps eliminate the number of false detections, resulting in a higher accuracy rate for detecting threats and attacks from malware, including ransomware.

[0030] In many embodiments of the described embodiments, the measured electromotive force energy is converted into a digital signal using an analog - to - digital controller, and the resulting signal is then calculated or transformed according to time - series analysis through different signal convolution algorithms and / or compared with a large number of stored threat patterns, malware patterns, and / or ransomware patterns. The number of patterns for comparison can be up to several million. Other embodiments utilize one or more self - training modules (either within or outside the AI co - processor) that execute during the normal operation of the solid - state drive controller to perform comparisons of any number and type of appropriate patterns.

[0031] In many of these embodiments used to detect ransomware, when the ransomware score, the time criterion of the threshold correlation coefficient reaches a predetermined or real-time determined level of ransomware threat, the AI co-processor will trigger an alarm via a general-purpose input / output bus to warn the solid-state drive controller to take further preventive measures and execute one or more corresponding configurations. Many of these embodiments operate independently of the solid-state drive power supply, and they include dedicated internal RAM, flash memory, and one or more communication peripheral devices. Other embodiments may have different component configurations. The embodiments may adopt the format of any conventional ASIC technology solution package, including but not limited to BGA, CSP, or a bitstream document operating as a slave from any FPGA and / or any embedded FPGA. The preferred embodiment participates in activities together with an external integrated circuit for measuring or capturing electromotive force energy and active and passive components.

[0032] This embodiment is not limited to a unique configuration to detect threats and attacks from malware, viruses, ransomware, or any other type of attack on a solid-state drive supporting the NVMe protocol or AHCI protocol. The embodiment can utilize any number of implementation methods and interfaces to the monitored hardware, such as any target protocol, such as the NVMe-oF protocol related to storage, where the storage is, for example, the storage used in a system such as a SaaS system.

[0033] In many of the embodiments, the protocols for NVMe and AHCI are utilized, but various protocols can also be utilized individually or in combination with other protocols. For example, the NVMeOF (NVMe over Fabric) can be utilized in combination with the AI core. These protocols can also be used to monitor activities and train the embodiments to identify abnormal activities using any type of protocol. Some of these embodiments will further utilize software integration.

[0034] In many of these embodiments, some different threats and any abnormal activities related to the hardware can be monitored, such as certain usage patterns or patterns indicating that the storage is being partially or fully replicated. For example, a higher usage volume compared to normal usage can indicate improper activities related to the storage device.

[0035] Now turning to the drawings, Figure 1A block diagram of an exemplary hardware system 100 is shown, which is based on an AI co-processor chipset for detecting ransomware related to a solid-state drive controller, utilizing the electromotive force generated by the solid-state drive chipset during runtime corresponding to the NVMe protocol or the AHCI protocol. The hardware system 100 includes an AI co-processor chipset 120, which is joined in the same printed circuit with a solid-state drive (SSD) motherboard 142 through a predefined communication bus. During the powered-on state of the hardware system 100, power is provided by the PMIC 141 integrated circuit, where the power output value can be configured by the AI co-processor chipset 120 if needed.

[0036] After the power state is indicated as valid, the hardware system 100 uses a small inductor coil 110 to start sampling the electromotive force generated by the solid-state drive motherboard 142 or the solid-state drive controller 142. Other embodiments may use larger or smaller inductor coils or other data collection components known to those skilled in the art. In these embodiments, the AI co-processor processes identification activities or threats by extracting attributes in the measured data. Embodiments using the AI co-processor will reduce any latency delay in analyzing the captured data, but other embodiments using non-AI co-processors may also be used to analyze the captured data.

[0037] The inductor or inductor coil can be of a thin form factor, such as used in the M.2 SSD format, or it can be of any other appropriate size. For example, in some facilities such as data centers with limited space within each server housing, or when set to be used in a laptop / notebook computer device, a smaller or thinner form factor can be utilized. Some embodiments of these embodiments can be placed near an M.2 PCB, which utilizes any available space within the housing. For example, in a laptop computer housing with a 1.35 mm thickness (the gap between the motherboard and the M.2 PCB), a thin inductor placed near the storage device can be used.

[0038] In this embodiment, the potential across the inductor coil 110 is sampled by the analog-to-digital converter 140, and the sampled values are transferred to the AI co-processor chipset 120 via one or more differential signals. The data buffer of the analog-to-digital converter 140 is temporarily held in a buffer dedicated to the differential signal (DIFF-SIGNAL) 121 and is transferred to a dedicated digital filter 122 for further processing to avoid comparison of unwanted signals. In many embodiments, the filtering of unwanted signals is implemented using one or more software algorithms, each algorithm being based on one or more user-predefined settings and one or more criteria, and thus the embodiments are not limited to a single state machine. In some embodiments, a single AI co-processor chipset may be used, but in other embodiments, a single or multiple AI co-processor chipsets may be used in parallel or in a serial configuration with one or more cores in certain operations to process the captured data.

[0039] The hardware timer (TIMER) module 123 records one or more time periods of the digital filter 122. The NVMe / AHCI module 124 records all commands that have been executed via the I / O bus module 125 and the solid-state drive motherboard 142 or a solid-state drive controller IC 142 for the NVMe protocol or the AHCI protocol, and the I / O bus module 125 is programmed using the SPI protocol or I2C or any high-speed communication control.

[0040] After a predefined period of data sampling from all three modules (the digital filter 122, the hardware timer module 123, and the NVMe / AHCI module 124), all data from those modules is transferred via an internal bus within the AI co-processor chipset 120 to a digital signal processing algorithm 126 for further conversion, which includes applying one or more different calculations depending on how the user configures the sequence. The result of the one or more calculations (e.g., the buffer frame generated by the digital signal processing algorithm 126) is communicated to the spectral image generator 127 module, and the generated image will be compared and matched by a DSP / SoC with a neural network algorithm and a self-training image pattern within the internal flash memory 129.

[0041] If there are no matching, partial matching, or other technical solution results indicating possible ransomware threats, the integrated circuit of the external secure flash memory 143 is queried. If the ransomware status mode is detected, for example, by using the DSP / SoC 128 with a neural network algorithm, the system will interrupt the I / O bus 130 to the security warning output pins of the solid-state drive motherboard 142 or / and the solid-state drive controller IC 142. When the security event causes an interruption, the solid-state drive motherboard 142 or the solid-state drive controller IC 142 can further take one or more further actions according to one or more predefined configurations installed by the user and / or the manufacturer. The interruption of the system can be implemented in any number of ways known to those skilled in the art. For example, if the AI co-processor is set within the IC, a physical bus is used, or if the AI co-processor is integrated with the SSD controller, it is through firmware code, where the interruption can be achieved by writing to a predefined register within the chipset. In other embodiments, the exclusive SSD IC controller used by the OEM factory can be configured through at least one I / O connection bus to share activities and exchange attributes collected from the SSD controller, including, for example, the following attributes: EMF values over time. Other embodiments can use the Diewafe technical solution (ASIC HW IP), where the AI core can be converted from RTL to GDS format. Still other embodiments can be implemented in one or more parallel cores through software implementation.

[0042] In certain embodiments, further steps or actions can include restricting access to the stored data, communicating one or more warnings (e.g., sending one or more warning bundles through an external wireless connection or a wired connection or both), locking the storage device or components within the storage device or components external to the storage device, and / or enabling a read-only mode that does not have the ability to overwrite any stored data.

[0043] In many embodiments of the described embodiments, self-training can be used to allow the AI co-processor chipset to learn what is normal and what is abnormal. In one example, the AI co-processor chipset uses a reference data set in the one or more comparisons against other data sets using one or more tolerance levels. In an exemplary self-training embodiment, the normal operation threshold setting uses numerical values of one or more predefined attributes. In certain embodiments, the artificial intelligence algorithm running in the AI co-processor chipset compares the current operation data set with the normal or baseline operation data set, while using the currently incoming data set to update or modify the data set in use without the need for external input values.

[0044] Figure 2A three-dimensional view of a solid-state drive with the form factor of an M.2 modular card is shown. This embodiment is integrated in the same printed circuit board 200. The NAND flash memory modules 201, 202, 203, and 204 are serially arranged and have direct connections to the solid-state drive controller 205. In addition, this embodiment is arranged within the boundary guard trace 211, which allows the AI co-processor 216 to be protected from unintentional signals and isolates the incoming sensitive signals from other high-speed signals that may interfere with this embodiment. The inductance coil 220 placed on top of the solid-state drive controller 205 captures the generated electromotive force, which is connected to the analog-to-digital converter 212 through two differential signal lines 221 and 222. The inductance coil 220 can be placed at any readable position near the solid-state drive controller 205.

[0045] In this embodiment, during the ransomware detection process, the external secure flash 213 is used as a database for ransomware pattern data. Any other storage medium known to those skilled in the art can also be used. All components within the region boundary 210, together with the passive components 214, are powered by a dedicated power management unit 215. These embodiments show an example of a hardware technical solution for the ransomware detector configuration, which can be utilized to protect any type of M.2 modular card. Other configurations known to those skilled in the art that achieve the same result using different components can also be used, such as the layout format of any standard storage device like M.2.

[0046] Figure 3 A top-down cutaway view of a modular M.2 card 300 according to an embodiment of the claimed subject matter is shown, where a solid-state drive controller is integrated with an AI co-processor ransomware detector configured as a hardware technical solution. This embodiment is arranged in the region 301 and is protected by a guard trace boundary 305. The inductance coil 304 is a flexible printed circuit board used to capture the electromotive force, and the inductance coil 304 is connected within the region 301 through a pair of signal lines. In this embodiment, the first line is the positive signal 302, and the second line is the negative signal 303. Also in this embodiment, the components are arranged very close to the PCIe power pad trace 306 to facilitate reducing power noise.

[0047] Figure 4Shows the correlation of Vemf measured relatively linearly over time for NVMe / AHCI commands, as shown in Chart 310. The points in Chart 310 represent a set of bytes sampled within a 5 millisecond time period during which the NVMe / AHCI write command 311 is continuously executed, which causes the solid state controller chipset to draw a greater current. This configuration causes an increase in the electromotive force, which can exceed the threshold value of the ransomware detection value, which is shown by the dashed line 312 in Chart 310. This Chart 310 shows an example of a pre-computed method used to detect ransomware. The aforementioned time period can be a wide range (e.g., from one nanosecond to one second), which depends on user and / or manufacturing requirements, such as the time period preferably used for a specific SSD controller, storage device, or other hardware component.

[0048] Figure 5A Shows that Chart 320 displays exemplary voltage levels of the electromotive force linearly over time in the presence of an anomaly such as ransomware and in the normal operating mode. As can be seen, the anomalies caused, for example, by ransomware and the normal operation of the NVMe / AHCI are slightly different. During this process, the electromotive force causes the solid state drive chipset to execute more instructions, and this increase in instructions results in an increase in the current accompanying the integrated circuit signal flow. The slight difference in this captured anomaly (caused in this example by the presence of ransomware) is shown by the dashed line 321. Chart 320 shows a greater electromotive force being generated compared to the electromotive force generated during the normal operation of the commands executed by the NVMe / AHCI. This difference shows the value of using the electromotive force to identify anomalies.

[0049] Figure 5B Shows the cross-correlation of the sampled bytes of the NVMe / AHCI buffered commands detected with ransomware or an exemplary anomaly according to an embodiment of the claimed subject matter. More specifically, it shows in Chart 330 the cross-correlation of the sampled bytes of the NVMe / AHCI buffered commands detected with ransomware or other anomalies. The measured values of the anomalies (such as the activity of ransomware) are shown by the dashed line 331, and this measured value has a positive correlation with the measured values of the NVMe / AHCI commands present during normal operation shown by the line 333. This type of analysis can help avoid false positives, such as those caused by erase / delete commands of the NVMe / AHCI that occur during normal operation, which might otherwise cause false warnings of the presence of anomalies such as ransomware. By setting a threshold score between 9 and 10 in Chart 330, anomalies or ransomware peaks can be detected when they exceed the threshold score shown by the dashed line 332, allowing anomalies such as ransomware to be detected at an early stage before they are allowed to corrupt files or perform other types of damage.

[0050] Figure 6An AI co - processor unit interconnection system showing embodiments of the claimed subject matter is presented. In these embodiments, three external variables are used for further digital computations. These variables are three bits of the NVMe / AHCI variable 430, where the MSB represents the NVMe / AHCI write command, the second bit represents the read command, and the LSB represents the erase / delete command. When one of the said commands is captured, a value of 0 or 1 is presented in the corresponding bit position. Secondly, the measured electromotive force value 420 is presented in thirty - two bits, and finally the timer value 410 is also presented in thirty - two bits. These external values are temporarily held in buffer registers: a 3 - bit register 443 for NVMe / AHCI, a 32 - bit register 442 for the voltage value of the electromotive force, and a timer register 441. In other embodiments, the number of variables may be more or less than three.

[0051] Sub - module 454 of the AI co - processor system 440 is the first module to start computing buffer values using two DFT (Discrete Fourier Transform) engines. The correlation analysis engine 446 computes the cross - correlation of two signals from the first DFT 445 and the second DFT 444. The correlation analysis engine 446 then transmits the computed values of the first DFT 445 and the second DFT 444 and the computed cross - correlation dimension values together to the ransomware score verification engine 447 located in sub - module 455. If the score is greater than the threshold, the values of the first DFT 445 and the second DFT 444 are both transmitted to the FFT (Fast Fourier Transform) engine 448, and the resulting values of the FFT engine 448 are then transmitted as a spectral image to the neural network engine 449 in sub - module 453. This spectral image is compared with a database of spectral image signatures of anomalies or ransomware, which are pre - loaded, pre - computed, and / or trained by the neural network engine 449. To access the database, the neural network engine 449 runs a series of read and write commands through the memory controller 450. A specific protocol bus 451 with a two - way mode reads the target flash circuit. If the computation of the neural network engine 449 detects an anomaly such as ransomware that results in a match, the neural network engine 449 sends a warning signal to the target solid - state drive controller through the bus 452.

[0052] Tables 1 and 2 show exemplary algorithms according to embodiments of the claimed subject matter, but any other suitable algorithms known to those skilled in the art may also be used.

[0053] Table 1:

[0054] Algorithm:

[0055] Convolution algorithm

[0056]

[0057] Table 2:

[0058] Decision tree algorithm:

[0059]

[0060] In certain embodiments, the platforms, systems, media, and methods described herein include a digital processing device or use devices of the same type. In many embodiments, the digital processing device includes one or more hardware central processing units (CPUs) or general purpose graphics processing units (GPUs) that execute the functions of the one or more devices. In certain embodiments, the digital processing device further includes an operating system that is configured to execute executable instructions. In many embodiments, the digital processing device is optionally connected to a computer network. In other embodiments, the digital processing device is optionally connected to a network such as the Internet, which gives it the ability to connect to servers located on the World Wide Web. In still other embodiments, the digital processing device is optionally connected to a cloud computing infrastructure. In other embodiments, the digital processing device is optionally connected to an internal network. In other embodiments, the digital processing device is optionally connected to a data storage device.

[0061] According to the description herein, suitable digital processing devices include, by way of non-limiting example, server computers, desktop computers, laptop computers, notebooks, sub-notebooks, netbook computers, network tablet computers, set-top box computers, media streaming devices, handheld computers, Internet appliances, mobile smartphones, tablet computers, personal digital assistants, video game consoles, and vehicles.

[0062] Those skilled in the art will recognize that many smartphones are suitable for use in the systems described herein. Those skilled in the art will also recognize that selected televisions, video players, and digital music players with optional computer network connectivity are suitable for use in the embodiments described herein. Suitable tablet computers include those known to those skilled in the art having booklet, slate, and convertible configurations.

[0063] In certain embodiments, the digital processing device includes an operating system that is configured to execute executable instructions. The operating system is, for example, software that includes programs and data, manages the hardware of the device, and provides services for the execution of application programs. Those skilled in the art will recognize that suitable server operating systems include, by way of non-limiting example, FreeBSD, OpenBSD, Linux, Mac OS X Windows and Those skilled in the art will recognize that suitable personal computer operating systems include, by way of non-limiting example, Mac OS and UNIX-like operating systems (such as GNU / ). In some embodiments, the operating system is provided by cloud computing. Those skilled in the art will also recognize that suitable mobile smartphone operating systems include, by way of non-limiting example, OS, Research In BlackBerry Windows OS, Windows OS, and Those skilled in the art will also recognize that suitable media streaming device operating systems include, by way of non-limiting example, Apple Google Google Amazon and Those skilled in the art will also recognize that suitable video game console operating systems include, by way of non-limiting example, Xbox Microsoft Xbox One, Wii and

[0064] In some embodiments, the device includes a storage and / or memory device. A storage and / or memory device is one or more physical devices used to store data or programs temporarily or permanently. In some embodiments, the device is volatile memory and thus requires power to maintain stored information. In some embodiments, the device is non-volatile memory and thus retains stored information when the digital processing device is not powered. In other embodiments, the non-volatile memory includes flash memory. In some embodiments, the non-volatile memory includes dynamic random access memory (DRAM). In some embodiments, the non-volatile memory includes ferroelectric random access memory (FRAM). In some embodiments, the non-volatile memory includes phase change random access memory (PRAM). In other embodiments, the device is a storage device, which includes, by way of non-limiting example, CD-ROM, DVD, flash memory devices, disk drives, tape drives, optical drives, and cloud computing-based storage devices. In still other embodiments, the storage and / or memory device is a combination of, for example, those devices disclosed herein.

[0065] In some embodiments, the platforms, systems, media, and methods disclosed herein include one or more non-transitory computer-readable storage media encoded with a program including instructions that are executable by an operating system of an optionally networked digital processing device. In other embodiments, the computer-readable storage media is a physical component of the digital processing device. In still other embodiments, the computer-readable storage media is optionally removable from the digital processing device. In certain embodiments, the computer-readable storage media includes, by way of non-limiting example, CD-ROMs, DVDs, flash memory devices, solid state memories, disk drives, tape drives, optical drives, cloud computing systems and servers, and the like. In certain instances, the program and instructions are permanently, substantially permanently, semi-permanently, or non-transitorily encoded on the media.

[0066] In many embodiments, the platforms, systems, media, and methods disclosed herein include at least one computer program, and / or its uses. The computer program includes a sequence of instructions that are executable in a CPU of a digital processing device and are written to perform a specified task. The computer-readable instructions can be implemented as program modules, such as functions, objects, application programming interfaces (APIs), data structures, etc., that perform particular tasks or implement particular abstract data types. Based on the disclosure provided herein, those skilled in the art will appreciate that the computer programs according to the embodiments can be written in various languages in various versions.

[0067] The functionality of the computer-readable instructions can be combined or distributed as needed in various environments. In some embodiments, the computer program includes a series of instructions. In some embodiments, the computer program includes multiple series of instructions. In some embodiments, the computer program is provided from one location. In other embodiments, the computer program is provided from multiple locations, including programs embedded or located in hardware. In various embodiments, the computer program includes one or more software modules. In various embodiments, the computer program (partially or wholly) includes one or more web applications, one or more mobile applications, one or more stand-alone applications, one or more web browser plugins, extensions, add-ons, or add-ins, or combinations thereof.

[0068] Some embodiments include a related database management system (RDBMS). Suitable examples of RDBMSs include Firebird, MySQL, PostgreSQL, SQLite, Oracle Database, Microsoft SQL Server, IBM DB2, IBM Informix, SAP Sybase, Teradata, and others. Those skilled in the art will recognize that a wide variety of hardware and software configurations can be utilized to achieve the results of the embodiments without departing from the scope of the claimed subject matter.

[0069] In some embodiments, the computer programs used in the embodiments include stand-alone applications, which are programs that run as independent computer processes rather than as additional components in an existing process, such as not being an add-on. Those skilled in the art will recognize that stand-alone applications are typically compiled. A compiler is a computer program that transforms source code written in a programming language into binary object code (e.g., assembly language or machine code). Suitable compiler languages include, by way of non-limiting example, C, C++, Objective-C, COBOL, Delphi, Eiffel, JavaTM, Lisp, PythonTM, Visual Basic, and VB.NET, or combinations thereof. Compilation is typically performed (at least in part) to produce an executable program. In some embodiments, the computer program includes one or more executable compiled applications. These applications or programs can be used in various embodiments of the claimed subject matter.

[0070] In some embodiments, the platforms, systems, media, and methods disclosed herein include software, server, and / or database modules or their uses. Given the disclosure provided herein, software modules are generated by techniques known to those skilled in the art, using machines, software, and languages known in the art. The software modules disclosed herein are implemented in any number of ways. In various embodiments, software modules include files, location codes, programming objects, programming constructs, or combinations thereof. In various other embodiments, software modules include multiple files, multiple location codes, multiple programming objects, multiple programming constructs, or combinations thereof. In various embodiments, one or more software modules include, by way of non-limiting example, web applications, mobile applications, and stand-alone applications. In some embodiments, software modules are in one computer program or application. In other embodiments, software modules are in more than one computer program or application. In some embodiments, software modules are hosted on one machine. In other embodiments, software modules are hosted on more than one machine. In yet other embodiments, software modules are hosted on a cloud computing platform. In some embodiments, software modules are hosted on one or more machines in one location. In other embodiments, software modules are hosted on one or more machines in more than one location.

[0071] In some embodiments, the platforms, systems, media, and methods disclosed herein include one or more databases or their uses. Given the disclosure provided herein, those skilled in the art will recognize that many databases are suitable for storing and retrieving, for example, the content of one or more records and the index of the one or more records and related information. In various embodiments, suitable databases include, by way of non-limiting example, relational databases, non-relational databases, object-oriented databases, object databases, entity-relationship model databases, relational databases, and XML databases. Additional non-limiting examples include SQL, PostgreSQL, MySQL, Oracle, DB2, and Sybase. In some embodiments, databases are Internet-based. In other embodiments, databases are web-based. In yet other embodiments, databases are cloud-based. In other embodiments, databases are based on one or more local computer storage devices including SSD devices.

Claims

1. A computer-implemented system for performing electromotive force analysis of a storage device, comprising: A storage device configured to execute a predetermined protocol; An AI co-processor chipset; A thin inductive coil disposed near a portion of the surface of the storage device for capturing data from the electromotive radiation (radia) generated by the storage device; An analog-to-digital converter; and At least one probe for communicating the captured data to the analog-to-digital converter; Wherein the data is captured by the thin inductive coil and communicated to the analog-to-digital converter via the at least one probe; Wherein the analog-to-digital converter digitizes the voltage level of the captured data and communicates the digitized and amplified result to the AI co-processor chipset; Wherein the AI co-processor chipset performs analysis of the data to detect any anomalies in the operation of the storage device and outputs the result for further processing, and Wherein for the analysis of the data for anomaly detection, the AI co-processor chip is configured to calculate the cross-correlation between the command variables associated with the predetermined protocol and the electromotive force generated by the storage device.

2. The computer-implemented system for performing electromotive force analysis of a storage device according to claim 1, wherein the storage device is a solid-state drive.

3. The computer-implemented system for performing electromotive force analysis of a storage device according to claim 2, the system further comprising: A solid-state drive controller; And A circuit chipset that communicates with the solid-state drive controller; Wherein the solid-state drive controller monitors the hardware performance of the solid-state drive by measuring the electromotive force of the solid-state drive and communicates the measured electromotive force data to the AI co-processor chipset.

4. The computer-implemented system for performing electromotive force analysis of a storage device according to claim 3, wherein the AI co-processor chipset performs analysis to provide real-time protection against any anomalies in the operation of the solid-state drive.

5. The computer-implemented system for performing electromotive force analysis of a storage device according to claim 4, wherein the predetermined protocol is the NVMe protocol.

6. The computer-implemented system for performing electromotive force analysis of a storage device according to claim 4, wherein the AI co-processor utilizes the AHCI protocol to interface with the solid-state drive.

7. The computer-implemented system for performing electromotive force analysis of a storage device according to claim 4, wherein the anomaly is caused by malware and wherein the further processing interrupts the operation of the solid-state drive.

8. The computer-implemented system for performing electromotive force analysis of a storage device according to claim 4, wherein the AI co-processor chipset applies artificial intelligence algorithms to detect the activities of ransomware.

9. The computer-implemented system for performing electromotive force analysis of a storage device according to claim 8, wherein when the activities of the ransomware are detected, the operation of the solid-state drive is interrupted.

10. The computer-implemented system for performing electromotive force analysis of a storage device as claimed in claim 1, wherein the AI co-processor chipset is configured to further perform the following steps: restricting access to the stored data, transmitting one or more warning beams via an external wireless connection or a wired connection or both, locking the storage device or components within the storage device or components external to the storage device and / or enabling a read-only mode that does not have the ability to overwrite any stored data.

11. A computer-implemented method for performing electromotive force analysis of a storage device, comprising the following steps: Capturing data of the electromotive radiation generated by the storage device using a thin inductive coil disposed near a portion of the surface of the storage device, the storage device executing a predetermined protocol; Communicating the captured data to an analog-to-digital converter via at least one probe; Digitizing the voltage level of the captured data using the analog-to-digital converter; Communicating the voltage level to the AI co-processor chipset; Analyzing the voltage level using the AI co-processor chipset to detect any anomalies in the operation of the storage device; Outputting the result for further processing, and wherein analyzing the voltage level of the anomaly detection includes calculating the cross-correlation between the command variable associated with the predetermined protocol and the electromotive force generated by the storage device.

12. The computer-implemented method for performing electromotive force analysis of a storage device as claimed in claim 11, wherein the storage device is a solid-state drive.

13. The computer-implemented method for performing electromotive force analysis of a storage device as claimed in claim 12, the method further comprising the following steps: Measuring the electromotive force of the solid-state drive by using a solid-state drive controller and a circuit chipset communicating with the solid-state drive controller to monitor the hardware performance of the solid-state drive; Communicating the measured electromotive force data to the AI co-processor chipset; Analyzing the measured electromotive force data using the AI co-processor chipset; and Outputting the result of the analysis to provide real-time protection against any anomalies in the operation of the solid-state drive.

14. The computer-implemented method for performing electromotive force analysis of a storage device as claimed in claim 13, wherein the AI co-processor chipset performs the analysis to provide real-time protection against any anomalies in the operation of the solid-state drive.

15. The computer-implemented method for performing electromotive force analysis of a storage device as claimed in claim 12, wherein the predetermined protocol is NVMe.

16. The computer-implemented method for performing electromotive force analysis of a storage device as claimed in claim 12, wherein the predetermined protocol is the AHCI protocol.

17. The computer-implemented method for performing electromotive force analysis of a storage device as claimed in claim 12, wherein the anomaly is caused by malware, and the method further comprises the following steps: Interrupting the operation of the solid-state drive when an anomaly caused by malware is detected.

18. The computer-implemented method for performing electromotive force analysis of a storage device as claimed in claim 13, wherein the AI co-processor chipset utilizes artificial intelligence algorithms to detect the activities of ransomware.

19. The computer-implemented method for performing electromotive force analysis of a storage device as claimed in claim 18, the method further comprising the steps of: When the AI co-processor chipset detects the activities of ransomware, interrupt the operation of the solid-state drive.

20. The computer-implemented method for performing electromotive force analysis of a storage device according to claim 11, further comprising the following steps: Restrict access to the stored data, send one or more warning beams via an external wireless connection or a wired connection or both, lock the storage device or components within the storage device or components external to the storage device and / or allow a read-only mode that does not have the ability to overwrite any stored data.

Citation Information

Patent Citations

  • Detection of malicious software, firmware, IP cores and circuitry via unintended emissions

    US20160098561A1