Intermittent encryption attack

CN120354407BActive Publication Date: 2026-09-08HEWLETT PACKARD ENTERPRISE DEV LP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410720304.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2024-01-22
Filing Date
2024-06-05
Publication Date
2026-09-08
Estimated Expiration
2044-06-05

Smart Images

  • Figure CN120354407B_ABST
    Figure CN120354407B_ABST
Patent Text Reader

Abstract

This application relates to an intermittent encryption attack. In some examples, a system identifies, from a plurality of input / output (I / O) operations to a storage system, a subset of the I / O operations that involve encrypted data segments of a given data size. The system computes a measure based on a number of the I / O operations in the subset of the I / O operations that involve encrypted data segments of the given data size. Based on the measure, the system determines whether an intermittent encryption attack to the storage system is occurring.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] Ransomware attacks involve encrypting data on a single computer or multiple computers connected via a network. In ransomware attacks, an encryption key is used to encrypt the data, making it inaccessible to the user unless a ransom is paid to retrieve the encryption key. Ransomware attacks can cause severe damage to businesses, including commercial enterprises, government agencies, educational organizations, and individuals. Attached Figure Description

[0002] Some embodiments of this disclosure are described in conjunction with the accompanying drawings.

[0003] Figure 1 It is a block diagram of a computer system that includes an intermittent encryption attack detector, based on some examples.

[0004] Figure 2 This is a diagram illustrating the intermittent encryption of some example files.

[0005] Figure 3 This is a flowchart illustrating the process of detecting intermittent cryptographic attacks, based on some examples.

[0006] Figure 4 It is a block diagram of a storage medium with machine-readable instructions based on some examples of storage.

[0007] Figure 5 It is a block diagram of a system based on some examples.

[0008] Figure 6 It is a flowchart based on some examples of processing.

[0009] Throughout the accompanying drawings, the same reference numerals denote similar, but not necessarily identical, elements. The drawings are not necessarily to scale, and the dimensions of some parts may be exaggerated for clarity of the examples shown. Furthermore, the drawings provide examples and / or embodiments consistent with the description; however, the description is not limited to the examples and / or embodiments provided in the drawings. Detailed Implementation

[0010] Ransomware attacks are difficult to detect. By the time users (such as individual users, organizations such as businesses, governments, or educational institutions, or any other type of entity) become aware of the attack, most or all of their data may already be encrypted and inaccessible. The inability to detect ransomware attacks in real time reduces a user's ability to recover from the attack.

[0011] In some cases, ransomware can encrypt an entire data object, where "data object" can refer to any one or a combination of the following: files, images, videos, executable program code, or any other container of data within a file system. In other cases, ransomware can perform intermittent encryption on a data object, in which the ransomware encrypts selected portions of the data object but not the rest. While ransomware protection systems may be able to detect ransomware that encrypts an entire data object, such systems may be unable to handle ransomware that applies intermittent encryption. Therefore, ransomware attacks may evade detection, and any partially encrypted (intermittently encrypted) data object will be lost because the user may be unable to recover the original data from the partially encrypted data object.

[0012] According to some embodiments of this disclosure, an intermittent cryptographic attack detector can determine whether an intermittent cryptographic attack is occurring based on monitoring the data size of input / output (I / O) operations on a storage system. The intermittent cryptographic attack detector identifies a subset of encrypted data involving a given data size from multiple I / O operations of the storage system. The detector calculates a measurement based on the number of I / O operations within this subset of encrypted data involving a given data size, and determines whether an intermittent cryptographic attack is occurring on the storage system based on this measurement.

[0013] A “cryptographic attack” refers to a collection of one or more unauthorized data encryption operations. During normal operation of a computer system, data encryption can be performed to protect data from unauthorized access. Such data encryption operations associated with planned or programmed actions are considered authorized data encryption operations. However, unauthorized data encryption operations can be performed by attackers, including human users, programs, or machines.

[0014] The example cryptographic attack was executed by ransomware, which includes malware that has already been activated on the system to encrypt data. Entities launching ransomware attacks typically attempt to extract payment (ransom) from victims in exchange for encryption keys that the victims can use to decrypt encrypted data. In other examples, cryptographic attacks may be executed by attackers under different circumstances.

[0015] Intermittent encryption attacks are encryption attacks that encrypt less than the entire data object. An example of an intermittent encryption attack involves skip-step encryption, where every Y-byte segment of the data object is encrypted while N-byte segments are skipped between Y-byte segments. An attacker can arbitrarily choose the values ​​of Y and N. Y and N can have different values. In some examples, Y is less than N. Intermittent encryption attacks may seek to encrypt smaller data segments while leaving larger segments unencrypted, in an attempt to evade ransomware protection systems that can detect the encryption.

[0016] Another type of intermittent encryption attack involves fast encryption, which encrypts the first Y bytes of a data object without encrypting the rest. Another type of intermittent encryption attack involves percentage encryption, which encrypts every Y-byte segment of a data object while skipping P-byte segments between Y-byte segments, where P is set based on a target P% of the total size of the data object. An attacker can arbitrarily choose the values ​​of Y and P.

[0017] More typically, intermittent encryption attacks seek to encrypt one or more sub-parts of a data object. A "sub-part" of a data object refers to a portion of the data object that has a target size smaller than the total size of the data object. Given a data object with a total size smaller than the target size, an intermittent encryption attack will encrypt the entire given data object.

[0018] While the above refers to data segments of a certain number of bytes (e.g., Y, N, P), in other examples, intermittent encryption attacks can encrypt data segments of any given size. According to some examples of this disclosure, an intermittent encryption attack detector identifies I / O operations involving encrypted data segments of a given size (e.g., Y bytes) and calculates a measurement based on the number of I / O operations involving encrypted data segments of that size. The intermittent encryption attack detector compares this measurement to one or more thresholds to determine whether an intermittent encryption attack is occurring.

[0019] Figure 1 This is a block diagram of a computer system 100 including an intermittent encryption attack detector 102. The intermittent encryption attack detector 102 can be implemented using one or more hardware processing circuits, which may include any one or a combination of a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or another hardware processing circuit. Alternatively, the intermittent encryption attack detector 102 can be implemented using a combination of one or more hardware processing circuits and machine-readable instructions (software and / or firmware) executable on the one or more hardware processing circuits.

[0020] Examples of computer system 100 may include any one or a combination of the following: a collection of computers (e.g., server computers, desktop computers, laptops, tablets, or other types of computers), a collection of smartphones, a collection of Internet of Things (IoT) devices, a collection of home appliances, a collection of vehicles, a collection of gaming devices, or a collection of other types of electronic devices. As used herein, a “collection” of items may refer to a single item or multiple items.

[0021] Storage system 104 is coupled to computer system 100. Storage system 104 may be located inside computer system 100, or alternatively, may be located outside computer system 100. Storage system 104 may be implemented using a collection of storage devices. Examples of storage devices may include any one or a combination of the following: disk-based storage devices, solid-state drives, or other types of storage devices.

[0022] Computer system 100 includes a data requester 106 capable of issuing data requests (112) to access (read or write) data 108 stored in storage system 104. Data requester 106 may include a person, a program (e.g., an application, operating system (OS), firmware, or any other type of program including machine-readable instructions), or an electronic component. Computer system 100 may have multiple data requesters capable of accessing data in storage system 104. In some examples, data requester 106 may include a virtual machine (VM) that provides a virtual computing environment simulating a physical computing environment. In other examples, data requester 106 may include a container or any other type of virtual computing environment. In other examples, data requester 106 does not operate within a virtual computing environment.

[0023] The data requester can also be located outside the computer system 100. Such an external data requester can submit data requests to the computer system 100 to access data 108 in the storage system 104.

[0024] Computer system 100 includes drive 110. In some examples, drive 110 may be part of the operating system of computer system 100. In other examples, drive 110 may be part of a hypervisor (also known as a virtual machine monitor (VMM)) or any other type of hypervisor. A hypervisor is used to create and manage virtual machines and computer system 100. Another example of a hypervisor is a container engine that can start and manage containers within computer system 100.

[0025] "Driver" can refer to a program that manages access to storage system 104. In response to a data request from a data requester, driver 110 can issue a corresponding input / output (I / O) operation 114, which performs access (read and / or write) to data 108 in storage system 104 according to the data request.

[0026] According to some embodiments of this disclosure, in order to determine whether an intermittent encryption attack is occurring, the intermittent encryption attack detector 102 is capable of monitoring I / O operations 114. Based on the I / O operations 114, a confidence measurement calculator 116 in the intermittent encryption attack detector 102 calculates a confidence measurement, which provides an indication of whether a data encryption attack may be occurring. The confidence measurement calculator 116 may be implemented as part of the hardware processing circuitry of the intermittent encryption attack detector 102, or as machine-readable instructions executable by the intermittent encryption attack detector 102.

[0027] Memory 118 stores one or more attack detection thresholds 120. The intermittent encryption attack detector 102 compares a confidence measurement calculated by the confidence measurement calculator 116 with one or more attack detection thresholds 120. Based on the comparison of the calculated confidence measurement with one or more attack detection thresholds 120, the intermittent encryption attack detector 102 generates an attack indicator 122. The attack indicator 122 can have any of a number of different values. A first value may indicate that no intermittent encryption attack is likely occurring. A second value of the attack indicator 122 may indicate that an encryption attack may be occurring. In some cases, the attack indicator 122 may be set to more than two values. In these examples, different values ​​of the attack indicator 122 may indicate different possible confidence levels related to the detection of intermittent encryption attacks. A higher confidence level indicates that an intermittent encryption attack is more likely to be occurring compared to a lower confidence level.

[0028] While the above refers to an example where the first value of attack indicator 122 indicates that no intermittent encryption attack is occurring, in other examples, the absence of attack indicator 122 indicates that no intermittent encryption attack is occurring. In other words, if the confidence measurement calculated by confidence measurement calculator 116 indicates that an intermittent encryption attack may not exist, then intermittent encryption attack detector 102 will not output attack indicator 122.

[0029] Computer system 100 may also include a remedy 124, which can take one or more remedial measures in response to an attack indicator 122 indicating that a cryptographic attack may be occurring. The remedy 124 may be implemented using one or more hardware processing circuits or machine-readable instructions that execute on one or more hardware processing circuits.

[0030] The remedial measures taken by the remediator 124 may include any one or a combination of any of the following: providing an alarm of a cryptographic attack, disabling components of the computer system 100 (e.g., stopping a program, shutting down an electronic component, disabling network access, etc.), disabling the entire computer system 100 (e.g., placing the computer system 100 in a lower power consumption state, such as a sleep state or a shutdown state), or any other remedial measures.

[0031] In other examples, the remediator 124 may be external to the computer system 100. In such examples, the computer system 100 may transmit (e.g., transmit via a network) an attack indicator 122 (e.g., in information or an information element) to the remediator 124.

[0032] An example is provided below, in which four attack detection thresholds 120 are employed. These four attack detection thresholds are represented as Th1, Th2, Th3 and Th4, where Th1 < Th2 < Th3 < Th4. If the confidence measurement (confidence) calculated by the confidence measurement calculator 116 is less than Th1, it indicates that no intermittent cryptographic attack is likely occurring, and therefore no remedial measure is required. If confidence < Th1, the intermittent cryptographic attack detector 102 does not output the attack indicator 122 (or sets the attack indicator 122 to a "no attack" value to indicate that no attack is occurring).

[0033] If Th1 ≤ confidence < Th2, the intermittent cryptographic attack detector 102 sets the attack indicator 122 to a "warning" value. In response to the "warning" value of the attack indicator 122, the remediator 124 issues a warning to a target entity (such as a human user, a program, or a machine).

[0034] If Th2 ≤ confidence < Th3, the intermittent cryptographic attack detector 102 sets the attack indicator 122 to an "error" value. In response to the "error" value of the attack indicator 122, the remediator 124 issues an error message to a target entity (such as a human user, a program, or a machine). The error message indicates to the target entity that an error has occurred in the computer system 100.

[0035] If Th3 ≤ confidence < Th4, the intermittent cryptographic attack detector 102 sets the attack indicator 122 to a "critical" value. In response to the "critical" value of the attack indicator 122, the remediator 124 disables a target function of the computer system 100, wherein the disabled target function may include a program, an electronic component, a network interface, the entire computer system 100, or any other function. For example, disabling the target function can prevent further write I / O operations.

[0036] The "No Attack" value, "Warning" value, "Error" value, and "Critical" value can be set arbitrarily, including different numerical values, different alphanumeric strings, or other values.

[0037] The following is for reference Figure 2 and Figure 3 . Figure 2 This is a schematic diagram illustrating intermittent encryption attacks. Figure 3 This is a flowchart illustrating a process for detecting intermittent cryptographic attacks, based on some examples of this disclosure. For instance, this process can be performed by an intermittent cryptographic attack detector 102. Although Figure 3 The example shows a specific order of tasks, but in other examples, tasks can be performed in a different order, some tasks can be omitted, and other tasks can be added.

[0038] Figure 2 The original file 200 (not yet encrypted) is shown, comprising Y-byte segments A, B, C, and D (i.e., each of A, B, C, and D is Y bytes in length, where Y ≥ 1). N-byte segments are provided between consecutive pairs of Y-byte segments in the original file 200. A single N-byte segment is provided between any consecutive pairs of Y-byte segments in the original file 200. A “consecutive pair” of Y-byte segments refers to two Y-byte segments in a file (or other data object) separated only by a single N-byte segment.

[0039] Intermittent encryption of the original file 200 (e.g., by ransomware) produces an intermittently encrypted file 202. The intermittent encryption applies encryption E(A) to Y-byte segment A, skipping the next N-byte segment 212; applies encryption E(B) to Y-byte segment B, skipping the next N-byte segment 214; applies encryption E(C) to Y-byte segment C, skipping the next N-byte segment 216; applies encryption E(D) to Y-byte segment D, and so on.

[0040] The intermittently encrypted file 202 includes an encrypted Y-byte segment AE, followed by an unencrypted N-byte segment 212A, then an encrypted Y-byte segment BE, followed by an unencrypted N-byte segment 214A, then an encrypted Y-byte segment CE, followed by an unencrypted N-byte segment 216A, and so on. It is important to note that the unencrypted N-byte segments in the intermittently encrypted file 202 are identical to the corresponding N-byte segments in the original file 200. For example, unencrypted N-byte segment 212A is identical to N-byte segment 212, unencrypted N-byte segment 214A is identical to N-byte segment 214, and unencrypted N-byte segment 216A is identical to N-byte segment 216.

[0041] like Figure 3As shown, the intermittent encryption attack detector 102 monitors (at 302) attacks directed at the storage system (e.g., Figure 1 The storage system 104) performs I / O operations to write data. Figure 1 In response to data requests from one or more data requesters 106, driver 110 generates I / O operations. Intermittent cryptographic attack detector 102 determines (at 304) various data sizes for the I / O operations, where the "data size" (or more simply referred to as "size") of an I / O operation refers to the size of the data written to the storage system in the I / O operation. Intermittent cryptographic attack detector 102 determines (at 306) whether I / O operations tend to favor a given data size (e.g., a Y-byte segment). I / O operations "tend" to favor the given data size if the number of I / O operations for that given data size exceeds the number of I / O operations for the next most common data size and exceeds a specified difference. If an intermittent cryptographic attack is occurring, a larger number of I / O operations for the same data size (e.g., Y-byte size) are expected.

[0042] If the intermittent encryption attack detector 102 determines (at 306) that the I / O operation does not favor any data size, the intermittent encryption attack detector 102 provides (at 308) a "no attack" indication, which may include setting the attack indicator 122 to a "no attack" value, or not outputting the attack indicator 122 at all.

[0043] If the intermittent encryption attack detector 102 determines (at 306) that I / O operations tend to favor a given data size (assumed to be Y bytes in this example), the intermittent encryption attack detector 102 calculates (at 310) entropy based on each Y-byte segment. In some examples, the calculated entropy may include Shannon entropy. If the Shannon entropy calculated based on any data segment (which may refer to a portion or the entirety of a data object) exceeds a specified entropy threshold, it indicates that the data segment has been encrypted. If the Shannon entropy calculated based on a data segment does not exceed the specified threshold, it indicates that the data segment has not been encrypted.

[0044] Based on the entropy calculated for Y-byte I / O operations (I / O operations that write Y-byte segments), the intermittent encryption attack detector 102 sets (at 312) a value X, which represents the first number of Y-byte I / O operations on encrypted data (i.e., the Y-byte segment generated by the first number of Y-byte I / O operations has an entropy exceeding a specified entropy threshold). The intermittent encryption attack detector 102 also sets (at 314) a value X. TThis value represents the total number of Y-byte I / O operations. The total number of Y-byte I / O operations includes the sum of a first number of Y-byte I / O operations containing encrypted data and a second number of Y-byte I / O operations containing unencrypted data (i.e., the Y-byte segment generated by the second number of Y-byte I / O operations has an entropy that does not exceed a specified entropy threshold).

[0045] Files (or more commonly, data objects) smaller than Y bytes may also be encrypted. Because such small files (or more commonly, data objects) are smaller than Y bytes, they will be fully encrypted. This example assumes that the intermittent encryption attack targets segments of files (or more commonly, data objects) that are Y bytes in size, smaller than the size of the unencrypted segment (e.g., N-byte segments of skip-encryption or fast encryption discussed further above, or P-byte segments of percentage encryption discussed further above).

[0046] The intermittent encryption attack detector 102 calculates (at 316) the entropy for each "small-sized" segment. A "small-sized" segment is a data segment smaller than Y bytes written by an I / O operation (such I / O operations are called "small-sized I / O operations"). Based on the entropy calculated for the small-sized I / O operations, the intermittent encryption attack detector 102 sets (at 318) the value Z, which represents the third number of encrypted data segments resulting from the small-sized I / O operations (i.e., the small-sized segments generated by the third number of small-sized I / O operations have an entropy exceeding a specified entropy threshold). The intermittent encryption attack detector 102 also sets the value Z (at 320). T This value represents the total number of small-size I / O operations. The total number of small-size I / O operations is the sum of the third number of small-size I / O operations containing encrypted data and the fourth number of small-size I / O operations containing unencrypted data (i.e., the small segments generated by the fourth number of small-size I / O operations have an entropy that does not exceed a specified entropy threshold).

[0047] The intermittent encryption attack detector 102 is based on the X and X calculated above. T Z and Z T The confidence level is calculated (at 322), for example, according to Equation 1 below:

[0048]

[0049] Where T represents the total number of I / O operations, including Y-byte I / O operations, small-size I / O operations, and other I / O operations (including unencrypted N-byte or P-byte segments). In other examples, other formulas can be used to calculate confidence measurements.

[0050] In some examples, if an intermittent cryptographic attack is occurring, the expected ratio is... Approximately 0.8 (or more generally, greater than 0.5), and the ratio Approximately 0.05 (or more generally, greater than 0.01). Based on the above... and The expected value can be set accordingly, and one or more attack thresholds (e.g., Th1, Th2, Th3 and Th4 discussed above) can be set by humans, programs or machines.

[0051] In some examples, larger X values ​​(representing the number of encrypted Y-byte segments involved in I / O operations) and larger Z values ​​(representing the number of encrypted small segments involved in I / O operations) result in higher confidence values, indicating a greater certainty that an intermittent encryption attack has been detected. Larger X and Z values ​​indicate that the encrypted data segments are larger compared to the unencrypted data segments.

[0052] The intermittent encryption attack detector 102 compares a confidence measurement with one or more attack thresholds (at 324). If, based on this comparison, the intermittent encryption attack detector 102 determines (at 326) that an intermittent encryption attack may be occurring, it generates (at 328) an attack indicator set to a value indicating such an attack. However, if, based on this comparison, the intermittent encryption attack detector 102 determines (at 326) that an intermittent encryption attack may not be occurring, it provides (at 308) a "no attack" indication.

[0053] Based on some examples of this disclosure, intermittent cryptographic attacks can be detected based on analyzing data segments rather than the entire data object. In some examples, intermittent cryptographic attacks can be detected in real time, such as during I / O operations.

[0054] Figure 4 This is a block diagram of a non-transitory machine-readable or computer-readable storage medium 400 that stores machine-readable instructions, which, when executed, cause the system to perform various tasks. "System" can refer to one or more computers.

[0055] The machine-readable instructions include encrypted data segment identification instructions 402, used to identify a subset of encrypted data segments involving a given data size from multiple I / O operations on the storage system. An example of a "given data size" is the Y-byte size discussed above, which is the target data size of a data segment of a data object that an attacker attempts to encrypt using an intermittent encryption attack. The storage system may be part of one or more computers or located remotely to one or more computers.

[0056] The machine-readable instructions include confidence measurement calculation instructions 404 for calculating a measurement based on the number of I / O operations involving a subset of encrypted data segments of a given data size. In some examples, the measurement is calculated according to Equation 1. In other examples, another equation is used to calculate the measurement, the output of which indicates a higher confidence level for intermittent encryption detection for a higher number of I / O operations involving encrypted data segments of a given data size.

[0057] The machine-readable instructions include intermittent cryptographic attack determination instructions 406, which determine, based on measurements, whether an intermittent cryptographic attack on the storage system is occurring. For example, intermittent cryptographic attack determination instructions 406 may compare the measurement with one or more attack thresholds.

[0058] In some examples, machine-readable instructions identify a set of I / O operations involving a given data size from multiple I / O operations, where a subset of the I / O operations is part of the set of I / O operations. The number of I / O operations within the set of data segments involving a given data size is then further calculated as a measurement.

[0059] In some examples, the set of I / O operations involving data segments of a given data size includes I / O operations involving unencrypted data segments of a given data size, as well as I / O operations involving encrypted data segments of a given data size.

[0060] In some examples, the measurement is the ratio between the number of I / O operations in a subset of I / O operations and the number of I / O operations in the set of I / O operations.

[0061] In some examples, machine-readable instructions identify another subset of I / O operations from multiple I / O operations that involve encrypted data segments smaller than a given data size. Measurements are then further calculated based on the number of I / O operations within this other subset of encrypted data segments smaller than a given data size.

[0062] In some examples, machine-readable instructions identify a set of I / O operations involving data segments smaller than a given data size from multiple I / O operations, where another subset of the I / O operations is a portion of the set of I / O operations involving data segments smaller than the given data size. Measurements are further calculated based on the number of I / O operations within the set of I / O operations involving data segments smaller than the given data size.

[0063] In some examples, another subset of I / O operations involves writing data objects that have been fully encrypted.

[0064] In some examples, machine-readable instructions generate error conditions in the system based on measurements that meet a first criterion. An "error condition" may include an alert indicating that an intermittent cryptographic attack may be occurring.

[0065] In some examples, machine-readable instructions are prevented from being written to the storage system based on measurements that meet the second criterion. Writing is disabled by disabling or shutting down components, including programs, electronic components, the entire computer, or other functions. The first and second criteria may include the attack thresholds discussed above.

[0066] Figure 5 This is a block diagram of system 500 based on some examples. System 500 can be implemented using one or more computers. The system includes hardware processor 502 (or multiple hardware processors). The hardware processor may include a microprocessor, the core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or other hardware processing circuitry.

[0067] System 500 includes a storage medium 504 storing machine-readable instructions that can be executed on a hardware processor 502 to perform various tasks. Machine-readable instructions executable on the hardware processor may refer to instructions executable on a single hardware processor or instructions executable on multiple hardware processors.

[0068] The machine-readable instructions in storage medium 504 include I / O operation set identification instructions 506, used to identify a first set of data segments involving a given data size from multiple I / O operations on the storage system. The storage system may be part of system 500 or may be located remotely from system 500.

[0069] The machine-readable instructions in storage medium 504 include I / O operation subset determination instructions 508, for determining from a first set of I / O operations a first subset of encrypted data segments involving a given data size for the I / O operations.

[0070] The machine-readable instructions in storage medium 504 include confidence measurement calculation instructions 510, used to calculate a measurement based on a first number of I / O operations in a first subset involving encrypted data segments of a given data size, and based on the total number of I / O operations in the first set of I / O operations. For example, the first number could be X, and the total number could be X... T .

[0071] The machine-readable instructions in storage medium 504 include intermittent cryptographic attack determination instructions 512, which are used to determine, based on measurements, whether an intermittent cryptographic attack is occurring on the storage system.

[0072] Figure 6This is a flowchart based on some examples of processing 600. For example, it can be generated by... Figure 1 The intermittent encryption attack detector 102 performs processing 600.

[0073] Processing 600 includes monitoring (at 602) multiple I / O operations involving writing data segments to the storage system. For example, this could be based on data requests from one or more data requesters. Figure 1 The driver 110 generates multiple I / O operations.

[0074] Processing 600 involves identifying (at 604) a first subset of encrypted data segments of a given data size from multiple I / O operations. Whether a data segment of a given data size is encrypted is determined based on entropy calculated from the data segments.

[0075] Processing 600 involves identifying (at 606) a second subset of I / O operations involving encrypted data segments smaller than a given data size from among multiple I / O operations. In some cases, encrypted data segments smaller than the given data size may include the entire encrypted data object.

[0076] Processing 600 involves calculating (at 608) a measurement based on a first number (e.g., X) of I / O operations in a first subset of encrypted data segments of a given data size and a second number (e.g., Z) of I / O operations in a second subset of encrypted data segments of a smaller data size.

[0077] Processing 600 includes determining (at 610) whether an intermittent cryptographic attack on the storage system is occurring based on a measurement. For example, this measurement can be compared to one or more attack thresholds.

[0078] Storage media (e.g., Figure 4 400 or Figure 1504) may include any one or a combination of the following: semiconductor memory devices, such as dynamic or static random access memory (DRAM or SRAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), and flash memory; magnetic disks, such as fixed disks, floppy disks, and removable disks; other magnetic media, including magnetic tape; optical media, such as optical discs (CDs) or digital video discs (DVDs); or other types of storage devices. It should be noted that the instructions discussed above may be provided on a computer-readable or machine-readable storage medium, or alternatively, may be provided on multiple computer-readable or machine-readable storage media distributed across a large system that may have multiple nodes. Such computer-readable or machine-readable storage media or medium is considered part of an article (or article of manufacture). An article or article of manufacture may refer to any single or multiple manufactured components. The storage medium or medium may be located in a machine that executes the machine-readable instructions, or at a remote site from which machine-readable instructions can be downloaded via a network for execution.

[0079] In this disclosure, unless the context clearly indicates otherwise, the use of the terms “a,” “an,” or “the” is also intended to include the plural form. Furthermore, the terms “comprising,” “including,” “containing,” “containing,” “having,” or “having” as used in this disclosure specify the presence of the stated element but do not exclude the presence or addition of other elements.

[0080] In the foregoing description, numerous details have been set forth to provide an understanding of the subject matter disclosed herein. However, implementations may be carried out without some of these details. Other embodiments may include modifications and variations to the foregoing details. The appended claims are intended to cover such modifications and variations.

Claims

1. A non-transitory machine-readable storage medium comprising instructions that, when executed, cause the system to: Identify the set of I / O operations involving a data segment of a first data size from multiple input / output (I / O) operations to the storage system; Determine whether the number of I / O operations in the set of I / O operations involving the first data size exceeds the number of I / O operations involving the second data size by a value greater than a specified difference. as well as In response to the determination that the number of I / O operations in the set involving the first data size exceeds the number of I / O operations involving the second data size by a value greater than the specified difference: In the set of I / O operations, a subset of I / O operations involving encrypted data segments of the first data size is identified, wherein the set of I / O operations involving data segments of the first data size includes a subset of I / O operations involving encrypted data segments of the first data size and I / O operations involving unencrypted data segments of the first data size. The measurement is calculated based on the ratio between the number of I / O operations in the subset of the I / O operations involving the encrypted data segment of the first data size and the total number of I / O operations in the set of I / O operations. as well as Based on the measurements, it is determined whether an intermittent cryptographic attack is occurring on the storage system.

2. The non-transitory machine-readable storage medium according to claim 1, wherein, The I / O operations involving the data segment of the first data size include the most frequent I / O operations among the plurality of I / O operations, and the I / O operations involving the data segment of the second data size include the second most frequent I / O operations among the plurality of I / O operations.

3. The non-transitory machine-readable storage medium according to claim 1, wherein, When the instruction is executed, it causes the system to: In response to determining that the number of I / O operations in the set involving the data segment of the first data size does not exceed the sum of the number of I / O operations involving the data segment of the second data size and the specified difference, it indicates that no intermittent cryptographic attack is occurring.

4. The non-transitory machine-readable storage medium according to claim 1, wherein, The intermittent encryption attack encrypts one or more sub-parts of the data object.

5. The non-transitory machine-readable storage medium according to claim 4, wherein, When the instruction is executed, it causes the system to: Identify another subset of I / O operations from the plurality of I / O operations that involve encrypted data segments with a data size smaller than the first data size. The measurement is further calculated based on the number of I / O operations in another subset of the I / O operations involving encrypted data segments with a data size smaller than the first data size.

6. The non-transitory machine-readable storage medium according to claim 5, wherein, When the instruction is executed, it causes the system to: Identify another set of I / O operations from the plurality of I / O operations that involve data segments with a size smaller than the first data size, wherein this other subset of I / O operations is part of the other set of I / O operations. The measurement is further calculated based on the number of I / O operations in another set involving data segments with a data size smaller than the first data size.

7. The non-transitory machine-readable storage medium according to claim 6, wherein, The measurement is based on the ratio between the number of I / O operations in another subset of the I / O operations and the number of I / O operations in another set of the I / O operations.

8. The non-transitory machine-readable storage medium according to claim 5, wherein, Another subset of the I / O operations includes writing data objects that have been fully encrypted.

9. The non-transitory machine-readable storage medium according to claim 1, wherein, When the instruction is executed, it causes the system to: The subset of I / O operations is determined to involve encrypted data based on the entropy of the data segments of the I / O operations within that subset.

10. The non-transitory machine-readable storage medium according to claim 1, wherein, When the instruction is executed, it causes the system to: Based on the measurement meeting the first criterion, an error condition is generated in the system.

11. The non-transitory machine-readable storage medium according to claim 10, wherein, When the instruction is executed, it causes the system to: Based on the fact that the measurement meets the second criterion, writing to the storage system is prohibited.

12. The non-transitory machine-readable storage medium according to claim 1, wherein, The subset of I / O operations identified includes identifying the writing of encrypted data to the storage system.

13. A system comprising: Hardware processor; as well as A non-transitory storage medium storing instructions executable on the hardware processor, the instructions being used for: Identify a first set of I / O operations involving a data segment of a first data size from multiple input / output (I / O) operations to the storage system; Determine whether the number of I / O operations in a first set involving a data segment of the first data size exceeds the number of I / O operations involving a data segment of the second data size by a value greater than a specified difference. as well as In response to the determination that the number of I / O operations in a first set involving a data segment of the first data size exceeds the number of I / O operations involving a data segment of the second data size by a value greater than the specified difference: Identify a first subset of I / O operations involving encrypted data segments of the first data size from the first set of I / O operations, wherein the first set of I / O operations includes a first subset of I / O operations involving encrypted data segments of the first data size and a second subset of I / O operations involving unencrypted data segments of the first data size; The measurement is calculated based on the ratio between the first number of I / O operations in a first subset of the I / O operations involving the encrypted data segment of the first data size and the total number of I / O operations in the first set of I / O operations. as well as The measurement is used to determine whether an intermittent cryptographic attack on the storage system is occurring.

14. The system according to claim 13, wherein, The I / O operations involving the data segment of the first data size include the most frequent I / O operations among the plurality of I / O operations, and the I / O operations involving the data segment of the second data size include the second most frequent I / O operations among the plurality of I / O operations.

15. The system of claim 13, wherein the instructions are executable on the hardware processor to: Identify a second set of I / O operations from the plurality of I / O operations that involve data segments with a data size smaller than the first data size. in, The measurement is calculated based on the total number of I / O operations in a second set involving data segments with a data size smaller than the first data size.

16. The system according to claim 15, wherein, The instructions described herein can be executed on the hardware processor to: From the second set of I / O operations, identify a second subset of I / O operations involving encrypted data segments with a data size smaller than the first data size, wherein the measurement is further based on the following calculation: The ratio between the second number of I / O operations in the second subset of the I / O operations and the total number of I / O operations in the second set of the I / O operations.

17. A method, the method comprising: System monitoring, including the hardware processor, involves multiple input / output (I / O) operations that write data segments to the storage system; The system identifies a set of I / O operations involving a data segment of a first data size from the plurality of I / O operations; The system determines whether the number of I / O operations in the set of I / O operations involving the first data size exceeds the number of I / O operations involving the second data size by a specified difference. as well as The value of the number of I / O operations in the set involving the data segment of the first data size exceeding the number of I / O operations involving the data segment of the second data size is greater than the specified difference: The system identifies a first subset of I / O operations involving encrypted data segments of the first data size from the set of I / O operations, wherein the set of I / O operations includes a first subset of I / O operations involving encrypted data segments of the first data size and a second subset of I / O operations involving unencrypted data segments of the first data size. The system calculates the measurement based on a first number of I / O operations in a first subset of the I / O operations involving the encrypted data segment of the first data size and the total number of I / O operations in the set of I / O operations. as well as The system determines whether an intermittent cryptographic attack on the storage system is occurring based on the measurement.

18. The method of claim 17, further comprising: Based on the determination that the number of I / O operations in the set involving the data segment of the first data size does not exceed the sum of the number of I / O operations involving the data segment of the second data size and the specified difference, the system indicates that no intermittent cryptographic attack is occurring.

Citation Information

Patent Citations

  • Data encryption detection

    CN116821922A

  • Unauthorized data encryption detection based on pattern matching at a storage system

    US20230367876A1