Intermittent cryptographic attack
By monitoring the I/O operation of the storage system and identifying and calculating encrypted data segments of a given data size, the detection problem of intermittent encryption attacks is solved, and real-time prevention and data recovery are improved.
Patent Information
- Application Number
- CN202410720304.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-01-22
- Filing Date
- 2024-06-05
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-06-05
AI Technical Summary
The prior art is difficult to detect and prevent intermittent encryption attacks in real time, which makes it difficult to recover part of the data object after encryption, resulting in data loss.
By monitoring input/output operations of the storage system, I/O operations involving encrypted data segments of a given data size are identified, confidence measurements are calculated and compared with thresholds, and attack indicators are generated to determine whether there is an intermittent encryption attack.
Real-time detection and prevention of intermittent encryption attacks is realized, reducing the risk of data loss and improving data recovery capabilities.
Smart Images

Figure CN120354407A_ABST
Abstract
Description
Background Art
[0001] Ransomware attacks involve encrypting data on a single computer or multiple computers connected via a network. In a ransomware attack, encryption keys can be used to encrypt the data, rendering the data inaccessible to the user unless a ransom is paid to obtain the encryption keys. Ransomware attacks can cause severe damage to enterprises (including businesses, government agencies, educational organizations, individuals, etc.). BRIEF DESCRIPTION OF THE DRAWINGS
[0002] Some embodiments of the present disclosure are described in conjunction with the following drawings.
[0003] Figure 1 is a block diagram of a computer system including an intermittent encryption attack detector according to some examples.
[0004] Figure 2 is a schematic diagram of intermittent encryption of a file according to some examples.
[0005] Figure 3 is a flowchart of a process for detecting an intermittent encryption attack according to some examples.
[0006] Figure 4 is a block diagram of a storage medium storing machine-readable instructions according to some examples.
[0007] Figure 5 is a block diagram of a system according to some examples.
[0008] Figure 6 is a flowchart of a process according to some examples.
[0009] Throughout the drawings, the same reference numerals represent similar but not necessarily identical elements. The drawings are not necessarily to scale, and in order to more clearly illustrate the examples shown, the dimensions of some components may be exaggerated. Additionally, the drawings provide examples and / or embodiments consistent with the description; however, the description is not limited to the examples and / or embodiments provided in the drawings. DETAILED DESCRIPTION
[0010] Ransomware attacks are difficult to detect. By the time the user (such as an individual user, an organization such as a business, government, or educational institution, or any other type of entity) begins to realize the attack, most or all of the data may have been encrypted and thus inaccessible. The inability to detect ransomware attacks in real time reduces the user's ability to recover from the attack.
[0011] In some cases, ransomware can encrypt an entire data object, where a "data object" can refer to any one or some combination of the following: a file in a file system, an image, a video, executable program code, or any other container of data. In other cases, ransomware can perform intermittent encryption on a data object, in which the ransomware encrypts selected portions of the data object but not other portions of the data object. While a ransomware protection system may be able to detect ransomware that encrypts an entire data object, such a ransomware protection system may not be able to combat ransomware that applies intermittent encryption. As a result, a ransomware attack may escape detection, and any partially encrypted (intermittently encrypted) data object is lost because the user may not be able to recover the original data from the partially encrypted data object.
[0012] According to some embodiments of the present disclosure, an intermittent encryption attack detector is capable of determining whether an intermittent encryption attack is occurring based on monitoring the data sizes of input / output (I / O) operations to a storage system. The intermittent encryption attack detector identifies a subset of I / O operations from among a plurality of I / O operations to the storage system that involve encrypted data of a given data size. The intermittent encryption attack detector calculates a measurement based on the number of I / O operations in the subset of I / O operations to the storage system that involve encrypted data of a given data size, and determines whether an intermittent encryption attack is occurring for the storage system based on the measurement.
[0013] An "encryption attack" refers to a collection of one or more unauthorized data encryption operations. During normal operation of a computer system, data encryption can be performed to protect data from unauthorized access. Such data encryption operations associated with planned or programmed operations are considered authorized data encryption operations. However, unauthorized data encryption operations may be performed by an attacker, including a human user, program, or machine.
[0014] An example encryption attack is performed by ransomware, which includes malware that has been launched in the system to perform encryption of data. The entity that initiates a ransomware attack typically attempts to obtain payment (ransom) from the victim of the ransomware attack in exchange for an encryption key that the victim can use to decrypt the encrypted data. In other examples, an encryption attack can be performed by an attacker in other circumstances.
[0015] An intermittent encryption attack refers to an encryption attack that encrypts less than all of the data objects. An example of an intermittent encryption attack involves skip encryption, in which every Y-byte segment of a data object is encrypted while skipping N bytes between the Y-byte segments. The attacker can arbitrarily choose the values of Y and N. Y and N have different values. In some examples, Y is less than N. An intermittent encryption attack may seek to encrypt smaller data segments while leaving larger data segments unencrypted in an attempt to evade a ransomware protection system that can detect the encryption of data.
[0016] Another type of intermittent encryption attack involves fast encryption, in which the first Y bytes of a data object are encrypted and the remainder of the data object is not encrypted. Another type of intermittent encryption attack involves percentage encryption, in which every Y-byte segment of a data object is encrypted while skipping P bytes between the Y-byte segments, where P is set based on a target P% of the total size of the data object. The attacker can arbitrarily choose the values of Y and P.
[0017] More generally, an intermittent encryption attack seeks to encrypt one or more sub-parts of a data object. A "sub-part" of a data object refers to a part of the data object, where the part has a target size that is less than the total size of the data object. In the case where a given data object has a total size that is less than the target size, the intermittent encryption attack will encrypt the entire given data object.
[0018] Although the above refers to data segments of a certain number of bytes (e.g., Y, N, P), in other examples, an intermittent encryption attack can encrypt data segments of any given data size. According to some examples of the present disclosure, an intermittent encryption attack detector identifies I / O operations involving encrypted data segments of a given data size (e.g., Y-byte size) and calculates a measurement based on the number of I / O operations involving encrypted data segments of the given data size. The intermittent encryption attack detector compares the measurement to one or more thresholds to determine whether an intermittent encryption attack is occurring.
[0019] Figure 1 is a block diagram of a computer system 100 that includes an intermittent encryption attack detector 102. The intermittent encryption attack detector 102 can be implemented with one or more hardware processing circuits, which can include any one or some combination of a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or another hardware processing circuit. Alternatively, the intermittent encryption attack detector 102 can be implemented with a combination of one or more hardware processing circuits and machine-readable instructions (software and / or firmware) executable on the one or more hardware processing circuits.
[0020] Examples of computer system 100 can include any one or some combinations of the following: a collection of computers (e.g., server computers, desktop computers, laptop computers, tablet computers, or other types of computers), a collection of smartphones, a collection of Internet of Things (IoT) devices, a collection of household appliances, a collection of vehicles, a collection of gaming devices, or a collection of other types of electronic devices. As used herein, a "collection" of items can refer to a single item or multiple items.
[0021] Storage system 104 is coupled to computer system 100. Storage system 104 can be located inside computer system 100 or, alternatively, can be located outside computer system 100. Storage system 104 can be implemented using a collection of storage devices. Examples of storage devices can include any one or some combinations of the following: disk-based storage devices, solid state drives, or other types of storage devices.
[0022] Computer system 100 includes a data requester 106 capable of issuing a data request (112) to access (read or write) data 108 stored in storage system 104. Data requester 106 can include a person, a program (e.g., an application program, an operating system (OS), firmware, or any other type of program including machine-readable instructions), or an electronic component. There may be multiple data requesters in computer system 100 capable of accessing the data in storage system 104. In some examples, data requester 106 can include a virtual machine (VM) that provides a virtual computing environment that emulates a physical computing environment. In other examples, data requester 106 can include a container or any other type of virtual computing environment. In other examples, data requester 106 does not operate in a virtual computing environment.
[0023] The data requester can also be outside computer system 100. Such an external data requester can submit a data request to computer system 100 for accessing data 108 in storage system 104.
[0024] Computer system 100 includes a driver 110. In some examples, driver 110 can be part of the operating system of computer system 100. In other examples, driver 110 can be part of a hypervisor (also known as a virtual machine monitor (VMM)) or any other type of virtual manager. The hypervisor is used to create and manage VMs and computer system 100. Another example of a virtual manager is a container engine that can start and manage containers in computer system 100.
[0025] A "driver" can refer to a program that manages access to storage system 104. In response to a data request from a data requester, driver 110 can issue a corresponding input / output (I / O) operation 114 that performs access (read and / or write) to data 108 in storage system 104 according to the data request.
[0026] According to some embodiments of the present disclosure, in order to determine whether an intermittent encryption attack is occurring, intermittent encryption attack detector 102 is capable of monitoring I / O operations 114. Based on I / O operations 114, confidence measurement calculator 116 in intermittent encryption attack detector 102 calculates a confidence measurement that provides an indication of whether a data encryption attack may be occurring. Confidence measurement calculator 116 can be implemented as part of the hardware processing circuitry of intermittent encryption attack detector 102, or as machine-readable instructions executable by intermittent encryption attack detector 102.
[0027] Memory 118 stores one or more attack detection thresholds 120. Intermittent encryption attack detector 102 compares the confidence measurement calculated by confidence measurement calculator 116 with one or more attack detection thresholds 120. Based on the comparison of the calculated confidence measurement with one or more attack detection thresholds 120, intermittent encryption attack detector 102 generates an attack indicator 122. Attack indicator 122 can have any one of a plurality of different values. A first value can indicate that no intermittent encryption attack may be occurring. A second value of attack indicator 122 can indicate that an encryption attack may be occurring. In some cases, attack indicator 122 can be set to more than two values. In these examples, the different values of attack indicator 122 can indicate different possible confidence levels related to intermittent encryption attack detection. A higher confidence level can indicate that an intermittent encryption attack is more likely to be occurring compared to a lower confidence level.
[0028] Although the above refers to an example in which the first value of attack indicator 122 indicates that no intermittent encryption attack is occurring, in other examples, the absence of attack indicator 122 indicates that no intermittent encryption attack is occurring. In other words, if the confidence measurement calculated by confidence measurement calculator 116 indicates that an intermittent encryption attack may not exist, then intermittent encryption attack detector 102 does not output attack indicator 122.
[0029] Computer system 100 can also include a remediator 124 that can take one or more remedial measures in response to attack indicator 122 indicating that an encryption attack may be occurring. Remediator 124 can be implemented with one or more hardware processing circuits or machine-readable instructions executed on one or more hardware processing circuits.
[0030] The remedial measures taken by the remediator 124 can include any one or some combination of the following: providing an alert for the encryption attack, disabling components of the computer system 100 (e.g., stopping a program, turning off an electronic component, disabling network access, etc.), disabling the entire computer system 100 (e.g., putting the computer system 100 in a lower power consumption state such as a sleep state or a shutdown state), or any other remedial measure.
[0031] In other examples, the remediator 124 can be external to the computer system 100. In such examples, the computer system 100 can send (such as via a network) the attack indicator 122 (such as in a message or information element) to the remediator 124.
[0032] An example is provided below in which four attack detection thresholds 120 are employed. These four attack detection thresholds are denoted as Th1, Th2, Th3, and Th4, where Th1 < Th2 < Th3 < Th4. If the confidence measure calculated by the confidence measure calculator 116 is less than Th1, it indicates that no intermittent encryption attack is likely occurring, and thus no remedial measures are required. If confidence < Th1, the intermittent encryption attack detector 102 does not output the attack indicator 122 (or sets the attack indicator 122 to a "no attack" value to indicate that no attack is occurring).
[0033] If Th1 ≤ confidence < Th2, the intermittent encryption attack detector 102 sets the attack indicator 122 to a "warning" value. In response to the "warning" value of the attack indicator 122, the remediator 124 issues a warning to a target entity (such as a human user, a program, or a machine).
[0034] If Th2 ≤ confidence < Th3, the intermittent encryption attack detector 102 sets the attack indicator 122 to an "error" value. In response to the "error" value of the attack indicator 122, the remediator 124 issues an error message to a target entity (such as a human user, a program, or a machine). The error message indicates to the target entity that an error has occurred in the computer system 100.
[0035] If Th3 ≤ confidence < Th4, the intermittent encryption attack detector 102 sets the attack indicator 122 to a "severe" value. In response to the "severe" value of the attack indicator 122, the remediator 124 disables the target function of the computer system 100, where the disabled target function can include a program, an electronic component, a network interface, the entire computer system 100, or any other function. For example, disabling the target function can prevent further write I / O operations.
[0036] The "no attack", "warning", "error", and "critical" values can be any set values, including different numerical values, different alphanumeric strings, or other values.
[0037] Refer to the following Figure 2 and Figure 3 . Figure 2 is a schematic diagram showing an intermittent encryption attack. Figure 3 is a flowchart of a process for detecting an intermittent encryption attack according to some examples of the present disclosure. For example, this process can be executed by the intermittent encryption attack detector 102. Although Figure 3 shows a specific order of tasks, in other examples, the tasks can be executed in a different order, some tasks can be omitted, and other tasks can be added.
[0038] Figure 2 shows an original file 200 (not yet encrypted) including Y-byte segments A, B, C, and D (i.e., each of A, B, C, and D has a length of Y bytes, where Y≥1). An N-byte segment is provided between consecutive pairs of the Y-byte segments in the original file 200. A single N-byte segment is provided between any consecutive pair of Y-byte segments in the original file 200. A "consecutive pair" of Y-byte segments refers to two Y-byte segments in a file (or other data object) that are separated by only a single N-byte segment.
[0039] Intermittent encryption of the original file 200 (e.g., by ransomware) results in an intermittently encrypted file 202. The intermittent encryption applies encryption E(A) to the Y-byte segment A, skips the next N-byte segment 212, applies encryption E(B) to the Y-byte segment B, skips the next N-byte segment 214, applies encryption E(C) to the Y-byte segment C, skips the next N-byte segment 216, applies encryption E(D) to the Y-byte segment D, and so on.
[0040] The intermittently encrypted file 202 includes an encrypted Y-byte segment AE, followed by an unencrypted N-byte segment 212A, followed by an encrypted Y-byte segment BE, followed by an unencrypted N-byte segment 214A, followed by an encrypted Y-byte segment CE, followed by an unencrypted N-byte segment 216A, and so on. It should be noted that the unencrypted N-byte segments in the intermittently encrypted file 202 are the same as the corresponding N-byte segments in the original file 200. For example, the unencrypted N-byte segment 212A is the same as the N-byte segment 212, the unencrypted N-byte segment 214A is the same as the N-byte segment 214, and the unencrypted N-byte segment 216A is the same as the N-byte segment 216.
[0041] As Figure 3As shown, the intermittent encryption attack detector 102 monitors (at 302) I / O operations that write data to a storage system (e.g., the storage system 104 in Figure 1 ). In Figure 1 , in response to data requests from one or more data requesters 106, the drive 110 generates I / O operations. The intermittent encryption attack detector 102 determines (at 304) various data sizes of the I / O operations, where the "data size" (or more simply, "size") of an I / O operation refers to the size of the data written to the storage system in the I / O operation. The intermittent encryption attack detector 102 determines (at 306) whether the I / O operations tend to a given data size (e.g., a Y-byte segment). If the number of I / O operations of the given data size exceeds the number of I / O operations of the next most common data size and exceeds a specified difference, the I / O operations "tend to" the given data size. If an intermittent encryption attack is occurring, a larger number of I / O operations of the same data size (e.g., Y-byte size) is expected.
[0042] If the intermittent encryption attack detector 102 determines (at 306) that the I / O operations do not tend to any data size, the intermittent encryption attack detector 102 provides (at 308) an indication of "no attack", which may include setting the attack indicator 122 to a "no attack" value, or not outputting the attack indicator 122 at all.
[0043] If the intermittent encryption attack detector 102 determines (at 306) that the I / O operations tend to a given data size (which is assumed to be a Y-byte size in this example), the intermittent encryption attack detector 102 calculates (at 310) the entropy based on each Y-byte segment. In some examples, the calculated entropy may include Shannon entropy. If the Shannon entropy calculated based on any data segment (which may refer to a part or all of a data object) exceeds a specified entropy threshold, it indicates that the data segment has been encrypted. If the Shannon entropy calculated based on the data segment does not exceed the specified threshold, it indicates that the data segment has not been encrypted.
[0044] Based on the entropy calculated for Y-byte I / O operations (I / O operations that write Y-byte segments), the intermittent encryption attack detector 102 sets (at 312) a value X that represents the first number of Y-byte I / O operations of encrypted data (i.e., the Y-byte segments generated by the first number of Y-byte I / O operations have an entropy that exceeds the specified entropy threshold). The intermittent encryption attack detector 102 also sets (at 314) a value X T, this value represents the total number of Y-byte I / O operations. The total number of Y-byte I / O operations includes the sum of the first quantity of encrypted data and the second quantity of unencrypted data of the Y-byte I / O operations (i.e., the Y-byte segments generated by the second quantity of Y-byte I / O operations have an entropy not exceeding the specified entropy threshold).
[0045] Files (or more commonly, data objects) smaller than Y bytes may also have been encrypted. Since such small files (or more commonly, data objects) are smaller than Y bytes, they will be fully encrypted. This example assumes that the intermittent encryption attack targets segments of Y-byte-sized files (or more commonly, data objects) that are smaller than the size of the unencrypted segment (e.g., the N-byte segments of skip encryption or fast encryption discussed further above, or the P-byte segments of percentage encryption discussed further above).
[0046] The intermittent encryption attack detector 102 calculates (at 316) the entropy for each "small-sized" segment. A "small-sized" segment is a data segment written by an I / O operation that is smaller than Y bytes (such I / O operations are called "small-sized I / O operations"). Based on the entropy calculated for the small-sized I / O operations, the intermittent encryption attack detector 102 sets (at 318) the value Z, which represents the third quantity of encrypted data of the small-sized I / O operations (i.e., the small-sized segments generated by the third quantity of small-sized I / O operations have an entropy exceeding the specified entropy threshold). The intermittent encryption attack detector 102 also (at 320) sets the value Z T , this value represents the total number of small-sized I / O operations. The total number of small-sized I / O operations is the sum of the third quantity of encrypted data and the fourth quantity of unencrypted data of the small-sized I / O operations (i.e., the small-sized segments generated by the fourth quantity of small-sized I / O operations have an entropy not exceeding the specified entropy threshold).
[0047] The intermittent encryption attack detector 102 calculates (at 322) a confidence measure based on the calculated X, X T , Z, and Z T values, for example, according to Equation 1 below:
[0048]
[0049] where T represents the total number of I / O operations, and the I / O operations include Y-byte I / O operations, small-sized I / O operations, and other I / O operations (including unencrypted N-byte or P-byte segments). In other examples, other formulas for calculating the confidence measure may be used.
[0050] In some examples, if an intermittent encryption attack is occurring, the expected ratio is approximately 0.8 (or more generally, greater than 0.5), and the ratio is approximately 0.05 (or more generally, greater than 0.01). Based on the above and expected values, one or more attack thresholds (e.g., Th1, Th2, Th3, and Th4 discussed above) can be set accordingly, such as being set by a human, a program, or a machine, etc.
[0051] In some examples, a larger X value (representing the number of I / O operations involving encrypted Y-byte segments) and a larger Z value (representing the number of I / O operations involving encrypted small-sized segments) result in a higher confidence value, which indicates a greater certainty in detecting that an intermittent encryption attack is occurring. Larger X and Z values indicate that the encrypted data segments are larger compared to the unencrypted data segments.
[0052] The intermittent encryption attack detector 102 compares the confidence measurement with one or more attack thresholds (at 324). If based on this comparison the intermittent encryption attack detector 102 determines (at 326) that an intermittent encryption attack may be occurring, then the intermittent encryption attack detector 102 generates (at 328) an attack indicator that is set to a value indicating such an attack. However, if based on this comparison the intermittent encryption attack detector 102 determines (at 326) that an intermittent encryption attack may not be occurring, then the intermittent encryption attack detector 102 provides (at 308) an indication of "no attack".
[0053] According to some examples of the present disclosure, intermittent encryption attacks can be detected based on analyzing data segments rather than the entire data object. In some examples, intermittent encryption attacks can be detected in real time, i.e., as detected during the execution of I / O operations.
[0054] Figure 4 is a block diagram of a non-transitory machine-readable or computer-readable storage medium 400 storing machine-readable instructions that, when executed, cause the system to perform various tasks. The "system" can refer to one or more computers.
[0055] The machine-readable instructions include encrypted data segment identification instructions 402 for identifying, from multiple I / O operations on a storage system, a subset of I / O operations involving encrypted data segments of a given data size. An example of the "given data size" is the Y-byte size discussed above, which is the target data size of the data segments of the data object that an attacker attempts to encrypt using an intermittent encryption attack. The storage system can be part of one or more computers or can be remote from one or more computers.
[0056] The machine-readable instructions include confidence measurement calculation instructions 404 for calculating a measurement based on the number of I / O operations in a subset of encrypted data segments of a given data size involved in the I / O operations. In some examples, the measurement is calculated according to Equation 1. In other examples, another equation is used to calculate the measurement, and the output produced by the other equation represents a higher confidence level of intermittent encryption detection for a higher number of I / O operations involving encrypted data segments of a given data size.
[0057] The machine-readable instructions include intermittent encryption attack determination instructions 406 for determining whether an intermittent encryption attack on the storage system is occurring based on the measurement. For example, the intermittent encryption attack determination instructions 406 can compare the measurement with one or more attack thresholds.
[0058] In some examples, the machine-readable instructions identify a set of I / O operations involving data segments of a given data size from among multiple I / O operations, where the subset of I / O operations is part of the set of I / O operations. The measurement is further calculated based on the number of I / O operations in the set of I / O operations involving data segments of a given data size.
[0059] In some examples, the set of I / O operations involving data segments of a given data size includes I / O operations involving unencrypted data segments of a given data size and I / O operations in a subset of encrypted data segments of a given data size.
[0060] In some examples, the measurement is based on the ratio between the number of I / O operations in the subset of I / O operations and the number of I / O operations in the set of I / O operations.
[0061] In some examples, the machine-readable instructions identify another subset of I / O operations involving encrypted data segments of a data size less than the given data size from among multiple I / O operations. The measurement is further calculated based on the number of I / O operations in the other subset of encrypted data segments of a data size less than the given data size.
[0062] In some examples, the machine-readable instructions identify a set of I / O operations involving data segments of a data size less than the given data size from among multiple I / O operations, where the other subset of I / O operations is part of the set of I / O operations involving data segments of a data size less than the given data size. The measurement is further calculated based on the number of I / O operations in the set of I / O operations involving data segments of a data size less than the given data size.
[0063] In some examples, the I / O operations of the other subset of I / O operations include writing to a data object that has been fully encrypted.
[0064] In some examples, machine-readable instructions generate an error condition in a system based on measurements that meet a first criterion. An "error condition" can include an alert indicating that an intermittent cryptographic attack may be occurring.
[0065] In some examples, machine-readable instructions prohibit writing to a storage system based on measurements that meet a second criterion. Writing is disabled by disabling or turning off components, including programs, electronic components, entire computers, or other functions. The first and second criteria can include the attack thresholds discussed above.
[0066] Figure 5 is a block diagram of a system 500 according to some examples. System 500 can be implemented with one or more computers. The system includes a hardware processor 502 (or multiple hardware processors). The hardware processor can include a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or another hardware processing circuit.
[0067] System 500 includes a storage medium 504 that stores machine-readable instructions that are executable on the hardware processor 502 to perform various tasks. Machine-readable instructions executable on a hardware processor can refer to instructions executable on a single hardware processor or instructions executable on multiple hardware processors.
[0068] The machine-readable instructions in the storage medium 504 include I / O operation set identification instructions 506 for identifying a first set of data segments of a given data size involved in I / O operations from among multiple I / O operations on a storage system. The storage system can be part of system 500 or can be remote from system 500.
[0069] The machine-readable instructions in the storage medium 504 include I / O operation subset determination instructions 508 for determining a first subset of encrypted data segments of a given data size involved in I / O operations from the first set of I / O operations.
[0070] The machine-readable instructions in the storage medium 504 include confidence measurement calculation instructions 510 for calculating a measurement based on a first number of I / O operations in a first subset of encrypted data segments of a given data size involved in I / O operations and based on the total number of I / O operations in the first set of I / O operations. For example, the first number can be X and the total number can be X T .
[0071] The machine-readable instructions in the storage medium 504 include intermittent cryptographic attack determination instructions 512 for determining based on the measurement whether an intermittent cryptographic attack is occurring on the storage system.
[0072] Figure 6is a flowchart of a process 600 according to some examples. For example, the process 600 may be performed by an intermittent encryption attack detector 102 in Figure 1 .
[0073] The process 600 includes monitoring (at 602) a plurality of I / O operations involving writing data segments to a storage system. For example, based on data requests from one or more data requesters, a plurality of I / O operations may be generated by a drive 110 in Figure 1 .
[0074] The process 600 includes identifying (at 604) a first subset of I / O operations among the plurality of I / O operations that involve encrypted data segments of a given data size. Whether a data segment of a given data size is encrypted is determined based on calculating the entropy based on the data segment.
[0075] The process 600 includes identifying (at 606) a second subset of I / O operations among the plurality of I / O operations that involve encrypted data segments of a data size less than the given data size. In some cases, the encrypted data segments of a data size less than the given data size may include an entire encrypted data object.
[0076] The process 600 includes calculating (at 608) a measurement based on a first quantity (e.g., X) of I / O operations in the first subset of I / O operations among the I / O operations that involve encrypted data segments of a given data size and a second quantity (e.g., Z) of I / O operations in the second subset of I / O operations among the I / O operations that involve encrypted data segments of a data size less than the given data size.
[0077] The process 600 includes determining (at 610) whether an intermittent encryption attack on the storage system is occurring based on the measurement. For example, the measurement may be compared with one or more attack thresholds.
[0078] A storage medium (e.g., 400 in Figure 4 or Figure 1The 504) may include any one or some combination of the following: semiconductor memory devices such as dynamic or static random access memory (DRAM or SRAM), erasable programmable read only memory (EPROM), electrically erasable programmable read only memory (EEPROM), and flash memory; magnetic disks such as fixed disks, floppy disks, and removable disks; other magnetic media including magnetic tapes; optical media such as compact discs (CDs) or digital video discs (DVDs); or other types of storage devices. It should be noted that the instructions discussed above may be provided on a computer-readable or machine-readable storage medium, or alternatively, may be provided on multiple computer-readable or machine-readable storage media distributed in a large system that may have multiple nodes. Such a computer-readable or machine-readable storage medium or media is considered to be part of an article (or manufacture). An article or manufacture may refer to any single component or multiple components that are manufactured. The storage medium or media may be located in the machine that runs the machine-readable instructions, or at a remote site from which the machine-readable instructions can be downloaded over a network for execution.
[0079] In this disclosure, unless the context clearly dictates otherwise, the use of the terms "a," "an," or "the" is also intended to include the plural forms. Additionally, the terms "comprise," "comprises," "include," "includes," "have," or "has" when used in this disclosure specify the presence of the stated element but do not preclude the presence or addition of other elements.
[0080] In the foregoing description, numerous details are set forth to provide an understanding of the subject matter disclosed herein. However, implementations may be practiced without some of these details. Other implementations may include modifications and variations of the foregoing details. The appended claims are intended to cover such modifications and variations.
Claims
1. A non - transitory machine - readable storage medium including instructions that, when executed, cause a system to: Identify, from a plurality of input / output (I / O) operations on a storage system, a subset of the I / O operations that involve encrypted data segments of a given data size; Calculate a measurement based on the number of I / O operations in the subset of the I / O operations on the storage system that involve the encrypted data segments of the given data size; And Determine, based on the measurement, whether an intermittent encryption attack on the storage system is occurring.
2. The non-transitory machine-readable storage medium according to claim 1, wherein, The instructions, when executed, cause the system to: Identify, from the plurality of I / O operations, a set of data segments of the I / O operations that involve the given data size, wherein the subset of the I / O operations is part of the set of the I / O operations, wherein the measurement is further calculated based on the number of I / O operations in the set of the data segments of the I / O operations that involve the given data size.
3. The non-transitory machine-readable storage medium according to claim 2, wherein, The set of the I / O operations that involve the data segments of the given data size includes: I / O operations that involve unencrypted data segments of the given data size, and I / O operations in the subset of the I / O operations that involve the encrypted data segments of the given data size.
4. The non-transitory machine-readable storage medium according to claim 2, wherein, The measurement is based on the ratio between the number of I / O operations in the subset of the I / O operations and the number of I / O operations in the set of the I / O operations.
5. The non-transitory machine-readable storage medium according to claim 1, wherein, The intermittent encryption attack encrypts one or more sub - parts of a data object.
6. The non-transitory machine-readable storage medium according to claim 5, wherein, The instructions, when executed, cause the system to: Identify, from the plurality of I / O operations, another subset of the I / O operations that involve encrypted data segments of a data size less than the given data size, wherein the measurement is further calculated based on the number of I / O operations in the another subset of the I / O operations that involve the encrypted data segments of the data size less than the given data size.
7. The non-transitory machine-readable storage medium according to claim 6, wherein, The instructions, when executed, cause the system to: Identify, from the plurality of I / O operations, a set of data segments of the I / O operations that involve a data size less than the given data size, wherein the another subset of the I / O operations is part of the set of the I / O operations, wherein the measurement is further calculated based on the number of I / O operations in the set of the data segments of the I / O operations that involve a data size less than the given data size.
8. The non-transitory machine-readable storage medium according to claim 7, wherein, The measurement is based on the ratio between the number of I / O operations in the another subset of the I / O operations and the number of I / O operations in the set of the I / O operations.
9. The non-transitory machine-readable storage medium according to claim 6, wherein, The I / O operations in the another subset of the I / O operations include writing to a data object that has been fully encrypted.
10. The non-transitory machine-readable storage medium according to claim 1, wherein, The instructions, when executed, cause the system to: Determine, based on calculating the entropy of the data segments of the I / O operations in the subset of the I / O operations, that the I / O operations in the subset of the I / O operations involve encrypted data.
11. The non-transitory machine-readable storage medium according to claim 1, wherein, The instructions, when executed, cause the system to: Generate an error condition in the system based on the measurement meeting a first criterion.
12. The non-transitory machine-readable storage medium according to claim 11, wherein, The instructions, when executed, cause the system to: Prohibit writing to the storage system based on the measurement meeting a second criterion.
13. The non-transitory machine-readable storage medium according to claim 1, wherein, Identifying the subset of I / O operations includes identifying writing encrypted data to the storage system.
14. A system, the system comprising: A hardware processor; And A non-transitory storage medium storing instructions executable on the hardware processor, the instructions for: Identifying, from a plurality of input / output (I / O) operations on a storage system, a first set of I / O operations involving data segments of a given data size; Determining, from the first set of I / O operations, a first subset of I / O operations involving encrypted data segments of the given data size; Calculating a measurement based on a first number of I / O operations in the first subset of I / O operations involving the encrypted data segments of the given data size and based on a total number of I / O operations in the first set of I / O operations; And Determining whether an intermittent encryption attack on the storage system is occurring based on the measurement.
15. The system according to claim 14, wherein, The first set of I / O operations includes: The first subset of I / O operations involving the encrypted data segments of the given data size, and A second subset of I / O operations involving unencrypted data segments of the given data size.
16. The system according to claim 14, wherein, The instructions are executable on the hardware processor to: Identify a second subset of I / O operations involving encrypted data segments having a data size less than the given data size from the plurality of I / O operations, wherein the measurement is further calculated based on a second number of I / O operations in the second subset of I / O operations involving the encrypted data segments having a data size less than the given data size.
17. The system according to claim 16, wherein the instructions are executable on the hardware processor to: Identify a second set of I / O operations involving data segments having a data size less than the given data size from the plurality of I / O operations, wherein the second subset of I / O operations is part of the second set of I / O operations, Among them, The measurement is calculated based on a total number of I / O operations in the second set of I / O operations involving the data segments having a data size less than the given data size.
18. The system according to claim 17, wherein, The measurement is calculated based on: A ratio between the first number of I / O operations in the first subset of I / O operations and the total number of I / O operations in the first set of I / O operations, and A ratio between the second number of I / O operations in the second subset of I / O operations and the total number of I / O operations in the second set of I / O operations.
19. A method, the method comprising: Monitoring, by a system including a hardware processor, a plurality of input / output (I / O) operations involving writing data segments to a storage system; Identifying, by the system, a first subset of I / O operations involving encrypted data segments of a given data size from the plurality of I / O operations; Identifying, by the system, a second subset of I / O operations involving encrypted data segments having a data size less than the given data size from the plurality of I / O operations; The system calculates a measurement based on a first quantity of I / O operations in the first subset of the encrypted data segments that involve the given data size and are based on I / O operations, and a second quantity of I / O operations in the second subset of the encrypted data segments that involve data sizes less than the given data size and are based on I / O operations; and the system determines whether an intermittent encryption attack on the storage system is occurring based on the measurement.
20. The system according to claim 19, wherein The determination is based on comparing the measurement with one or more attack thresholds.
Citation Information
Patent Citations
Data encryption detection
CN116821922A
Extensible Attack Monitoring by a Storage System
US20210216630A1
Unauthorized data encryption detection based on pattern matching at a storage system
US20230367876A1