AI Cloud Service Detecting Ransomware via Compressibility Metrics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud storage systems are vulnerable to ransomware attacks, where infected files can automatically sync across devices, leading to widespread encryption and data loss, as existing technologies lack effective real-time monitoring and mitigation mechanisms to detect and counter such malicious activities.
Innovation Solution
Implementing an AI-driven cloud service that monitors data reduction metrics to identify unusual behavior, such as low compressibility, and takes remediation actions like halting activity, removing access permissions, or reverting to previous file versions to mitigate ransomware attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If files are automatically synchronized across cloud storage devices, then data sharing and collaboration are improved, but the risk of malware propagation and data corruption increases
Solution Approach 1:
The patent introduces a cloud service as an intermediary between endpoints and cloud storage. This service monitors file operations, detects ransomware behavior (such as bulk encryption patterns), and intervenes to prevent malicious files from being synchronized to other devices. The intermediary filters harmful content while allowing legitimate file sharing to proceed.
Solution Approach 2:
The system implements continuous monitoring of cloud storage operations with feedback loops that detect anomalies in file access patterns. When ransomware activity is detected (such as unusual encryption behavior), the system responds by blocking further synchronization operations and alerting users, creating a closed-loop security mechanism that adapts to threats in real-time.
2Productivity
If cloud storage enables real-time file synchronization, then productivity is improved, but the ability to detect and respond to ransomware attacks deteriorates
Solution Approach 1:
The patent implements preliminary detection mechanisms that analyze files before they are synchronized to cloud storage or other devices. The cloud service scans incoming files for ransomware signatures and suspicious behavior patterns, preventing malicious content from entering the synchronization pipeline. This proactive approach maintains fast sync speeds for legitimate files while blocking threats in advance.
Solution Approach 2:
The system segments the file synchronization process into multiple stages: initial upload, security scanning, approval, and final distribution. By dividing the synchronization workflow, the system can maintain high speed for approved files while applying thorough security checks without bottlenecking the entire system. Legitimate files flow through quickly, while suspicious files undergo additional scrutiny.
3Ease of operation
If multiple devices are connected to cloud storage for file sharing, then accessibility is improved, but the vulnerability to ransomware infection increases
Solution Approach 1:
The cloud service acts as a security intermediary between multiple connected devices and the cloud storage system. It monitors all file operations from and to connected devices, detecting ransomware behavior patterns such as bulk encryption attempts. When threats are detected, the service blocks the malicious device from accessing other devices, preventing infection propagation while maintaining normal access for legitimate users.
Data Source
AI summary
A service monitors activity of a cloud storage during operation of the storage. The service may be a cloud AI service. The AI service may be trained with data labeled as ‘normal’ relative to compressibility of a storage unit of the storage during a known normal period. The service generates storage activity metrics based on the monitored activity and compares the metrics to a normal characteristic activity associated with the cloud storage. The monitored activity may comprise data reduction operations to a storage unit of the cloud storage. If metrics corresponding to monitored activity do not satisfy normal characteristic activity criteria, such as compressibility, the service may determine that the storage has been subjected to a ransomware attack and may initiate an action that protects data of the storage. Corrective actions may be initiated to block access to a suspicious endpoint or revert a storage unit to a previous version.


