Anti-Ransomware Backup Service for User Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ransomware poses a significant threat as existing antivirus software is not tailored to effectively combat it, leading to delays in recognizing malicious activities and resulting in critical user files being held for ransom, with current data backup solutions providing inadequate protection against data loss and encryption.

Innovation Solution

The implementation of anti-ransomware systems and methods that utilize a database of trusted and untrusted processes to monitor and safeguard user data, generating snapshot backups, and restoring files from local or cloud backups if encrypted, while terminating untrusted processes to prevent data interference.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If antivirus software is used to protect against malware, then general malware protection is provided, but it operates with inherent delays that allow ransomware to encrypt files before detection

Engineering Contradiction:
Improvemalware protection capabilityVSAvoiddetection delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by creating backup copies of files before ransomware can encrypt them. The backup service proactively safeguards files in advance, so when ransomware attacks occur, the original files can be restored from backups without loss. This resolves the time delay issue by ensuring protection is already in place before the threat materializes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary backup service that sits between the user's files and ransomware threats. This backup service acts as a mediator that captures file states and maintains separate backup copies, allowing the system to detect and respond to ransomware attacks independently of traditional antivirus detection delays.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional data backup services are used to protect against data loss, then data restoration capability is provided, but they are not tailored to specifically protect against ransomware encryption threats

Engineering Contradiction:
Improvedata restoration capabilityVSAvoidransomware-specific protection
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system applies local quality by implementing ransomware-specific protection features within the broader backup service. The backup service is enhanced with specialized components that specifically detect and respond to ransomware behaviors, while maintaining general backup functionality for other data protection needs. This allows tailored ransomware protection without sacrificing overall backup versatility.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent achieves universality by designing a backup service that simultaneously provides general data backup functionality and specialized ransomware protection. The system can handle both routine data protection tasks and specific ransomware threat responses, making it adaptable to multiple protection scenarios without requiring separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Device complexity

If no specific anti-ransomware measures are implemented, then system simplicity is maintained, but critical user files are vulnerable to encryption and held for ransom

Engineering Contradiction:
Improvesystem simplicityVSAvoidfile encryption vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The system implements preliminary action by automatically creating backup copies of files before ransomware can encrypt them. This proactive measure ensures that even if ransomware successfully encrypts original files, the backup copies remain intact and can be used for restoration, thereby neutralizing the encryption vulnerability without adding complex user-facing features.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the copying principle by maintaining duplicate copies of user files in a protected backup environment. These copies serve as insurance against ransomware encryption, allowing the system to protect files from harm while keeping the primary system simple and unchanged. The copying mechanism provides vulnerability protection without requiring complex modifications to the user's workflow.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11436328B1Systems and methods of safeguarding user data
Publication Date: 2022.09.06 ACRONIS INT
  • US11436328B1 patent drawing
  • US11436328B1 patent drawing
  • US11436328B1 patent drawing

AI summary

Methods and systems for safeguarding against malware such as ransomware are described. In part, the disclosure relates to systems and methods for restoring user data and other data encrypted by malware or otherwise rendered inaccessible thereby. In one embodiment, the disclosure relates to a method of safeguarding user data. The method includes monitoring a plurality of processes executing on a computing device; detecting when a first process of the plurality of processes attempts to modify one or more parameters of a user data file; determining if first process is a trusted process or an untrusted process using one or more heuristics; and if the first process is determined to be an untrusted process, create a backup version of the user data file, wherein the backup version of the user data file is created with regard to an unchanged version the user data file.