Compressibility Metric Ransomware Detection in Storage Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional storage systems face inefficiencies in data management and security, particularly in handling security threats and ensuring data integrity across distributed storage nodes, where existing solutions often rely on complex and redundant processes that can lead to increased latency and reduced reliability.

Innovation Solution

The implementation of a storage system architecture that utilizes non-volatile random access memory (NVRAM) as a buffer for write operations, offloading device management from storage drives, and employing erasure coding and mirroring schemes to ensure data redundancy and availability, while also incorporating a cloud-based monitoring system for enhanced security and data protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional storage systems use complex and redundant processes for data management and security, then data reliability is improved, but latency increases and productivity decreases

Engineering Contradiction:
Improvedata reliabilityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the security monitoring function from the main storage processing path by introducing a separate anomaly detection system that monitors compressibility metrics independently. This allows security checks to occur without blocking normal write operations, thus maintaining data reliability while reducing latency.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces compressibility metrics as an intermediary indicator to detect ransomware threats. Instead of directly analyzing file contents or blocking operations, the system uses compressibility changes as a mediator to identify anomalies, enabling security monitoring without significant performance overhead.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional storage systems use complex and redundant processes for data management, then data integrity is improved, but device complexity increases

Engineering Contradiction:
Improvedata integrityVSAvoidprocess complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the monitoring parameter from complex file analysis to simple compressibility metrics. By tracking how well data compresses over time, the system detects ransomware encryption without needing complex decryption or content analysis, thus maintaining data integrity while reducing process complexity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The storage system performs self-monitoring by analyzing its own compressibility characteristics. The system automatically detects anomalies in data patterns without external intervention, maintaining data integrity through self-service monitoring rather than complex external verification processes.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If ransomware encrypts data on a storage system, then data security is compromised, but detection difficulty increases

Engineering Contradiction:
Improvedata securityVSAvoidthreat detection difficulty
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent converts the harmful effect of ransomware encryption into a detectable signal. Encrypted data has distinct compressibility characteristics compared to normal data, so the very act of encryption creates an anomaly that the monitoring system can easily detect by measuring compressibility changes.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The patent changes the 'color' or observable property of data from content-based to compressibility-based detection. Instead of trying to detect encryption by analyzing data content (which is hidden), the system detects changes in compressibility properties, making the threat visible through a different characteristic.

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS11657146B2Compressibility metric-based detection of a ransomware threat to a storage system
Publication Date: 2023.05.23 PURE STORAGE INC
  • US11657146B2 patent drawing
  • US11657146B2 patent drawing
  • US11657146B2 patent drawing

AI summary

An illustrative method includes a data protection system determining a first compressibility metric associated with write traffic processed by a storage system, the first compressibility metric indicating an amount of storage space saved if the write traffic is compressed; determining a second compressibility metric associated with read traffic processed by a storage system, the second compressibility metric indicating an amount of storage space saved if the read traffic is compressed; determining, based on a comparison of the first compressibility metric with the second compressibility metric, that the write traffic is less compressible than the read traffic; determining, based on the write traffic being less compressible than the read traffic, that the storage system is possibly being targeted by a security threat; and performing, based on the determining that the storage system is possibly being targeted by the security threat, a remedial action with respect to the storage system.