Cloud Storage Encryption Anomaly Detection Against Ransomware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing defenses against ransomware attacks on cloud storage devices are ineffective as they cannot detect attacks that utilize cloud infrastructure, as attackers often use control plane capabilities to encrypt the storage without executing malicious code.

Innovation Solution

A processor-based apparatus within the cloud service provider's system determines anomalous encryption operations by analyzing elements of encryption requests or executions against learned behaviors, outputting alerts and performing remedial actions to prevent or mitigate ransomware attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional malware detection methods are used to detect ransomware attacks, then attacks that execute malicious code can be detected, but attacks that use cloud control plane capabilities without executing code cannot be detected

Engineering Contradiction:
Improvedetection effectivenessVSAvoiddetection coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of detecting ransomware by identifying malicious code execution, the patent inverts the approach by monitoring for legitimate-looking cloud control plane operations that exhibit anomalous patterns. The system detects ransomware by looking for unusual sequences of authorized operations (encrypt, delete, modify) rather than trying to identify unauthorized code, thereby detecting attacks that bypass traditional malware detection.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces an intermediary monitoring layer between the cloud control plane and storage operations. This intermediary observes and analyzes the patterns of control plane operations, using machine learning to distinguish between legitimate user actions and ransomware-driven operations. The intermediary detects anomalies in operation sequences, timing, and patterns without requiring direct access to the underlying storage or execution environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If cloud control plane capabilities are used to encrypt storage devices, then encryption can be performed without executing malicious code on the device, but traditional security defenses cannot detect such attacks

Engineering Contradiction:
Improveattack execution simplicityVSAvoidattack detection difficulty
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies the concept of color changes by transforming the invisible threat into a detectable signal. Just as color changes make invisible processes visible, the system transforms invisible anomalous control plane operations into detectable patterns through machine learning analysis. The system assigns 'colors' (anomaly scores, risk levels) to different operation patterns, making previously undetectable attacks visible and actionable.

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

The patent implements continuous feedback loops where the system monitors cloud control plane operations, compares them against learned normal patterns, and adjusts its detection thresholds and models in real-time. The feedback mechanism allows the system to adapt to new attack patterns while maintaining sensitivity to anomalies, creating a dynamic defense that improves over time as it learns from observed operations.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20260058975A1Protection of cloud storage devices from anomalous encryption operations
Publication Date: 2026.02.26 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20260058975A1 patent drawing
  • US20260058975A1 patent drawing
  • US20260058975A1 patent drawing

AI summary

According to examples, an apparatus includes a processor that determines that an encryption operation has been requested or executed through a cloud control plane capability with respect to a cloud storage device. The processor also determines that the requested or executed encryption operation with respect to the cloud storage device is anomalous and, based on a determination that the requested or executed encryption operation with respect to the cloud storage device is anomalous, outputs an alert and/or performs a remedial action. By identifying anomalous encryption operation requests or executions on cloud storage devices, the processor is able to determine that ransomware attacks are or have occurred on the cloud storage devices. In some examples, the processor takes remedial actions to mitigate harm posed by or prevent the ransomware attacks.