Backup Metadata Analysis for Early Cyber-Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber-attack detection methods, particularly for ransomware, are costly and time-consuming, often failing to detect attacks until significant damage has occurred due to the difficulty in scanning large data sets and the ability of attacks to corrupt files without altering their size or hash values.

Innovation Solution

Leverage backup meta-data to reduce the amount of data scanned by a cyber-security module, using periodic backups to detect cyber-attacks by comparing meta-data changes, allowing early identification and mitigation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional cyber-attack detection methods scan large data sets, then detection thoroughness is improved, but processing time and costs increase significantly

Engineering Contradiction:
Improvedetection thoroughnessVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts and analyzes only the metadata portion of backup files rather than scanning the entire file content. The metadata contains file system structure information, file names, paths, and other organizational data that can reveal ransomware activity patterns without requiring examination of actual file contents, thus dramatically reducing processing time while maintaining detection effectiveness

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the backup data into metadata and content portions, analyzing only the metadata segment for ransomware detection. This segmentation allows the system to focus computational resources on the smaller, more informative metadata portion that contains structural changes indicative of ransomware attacks, thereby reducing overall processing requirements

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If traditional methods scan entire backup files, then corruption detection accuracy is improved, but computational resources and costs increase

Engineering Contradiction:
Improvecorruption detection accuracyVSAvoidcomputational resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system extracts metadata from backup files and analyzes only this extracted portion for signs of corruption and ransomware activity. The metadata contains sufficient information to detect structural changes and anomalies without requiring full file content scanning, thus reducing computational resource consumption while maintaining detection accuracy

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by analyzing only the necessary metadata portion rather than the entire backup file. This partial analysis approach provides sufficient detection capability for ransomware and corruption identification without the excessive computational resources required for complete file content scanning

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If backup metadata is compared between initial and subsequent backups, then early attack detection is improved, but data processing requirements increase

Engineering Contradiction:
Improveearly attack detectionVSAvoiddata processing volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system extracts and compares only the metadata portions of backup files across different time points. This extraction approach identifies changes in file system structure, new files, deleted files, and other metadata attributes that indicate ransomware activity, achieving early detection while processing significantly less data than full file content comparison would require

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12386953B2Using backup meta-data and analytics for detecting cyber-attacks
Publication Date: 2025.08.12 DELL PROD LP
  • US12386953B2 patent drawing
  • US12386953B2 patent drawing
  • US12386953B2 patent drawing

AI summary

Embodiments of the invention relate to generating backups of assets. More specifically, in one or more embodiments of the invention, the meta-data generated during the backups is leveraged for detecting cyber-attacks by leveraging backup meta-data, to reduce the amount of data that needs to be scanned by a cyber-security module to detect a cyber-attack, such as a ransomware attack. This allows any attacks to be detected earlier and reduce processing by leveraging the periodic backups that are performed as part of data protection, to detect when an attack has or is occurring. By making these determinations, a quick identification of possible ransomware attacks may be made and other methods of mitigating the attack may be deployed when the method of mitigating the attack might still be useful to mitigate potential damage to a user's data.