Compressibility Metric Ransomware Detection in Storage Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional storage systems face inefficiencies in data management and security, particularly in handling security threats and ensuring data integrity across distributed storage nodes, where existing solutions often rely on complex and redundant processes that can lead to increased latency and reduced reliability.
Innovation Solution
The implementation of a storage system architecture that utilizes non-volatile random access memory (NVRAM) as a buffer for write operations, offloading device management from storage drives, and employing erasure coding and mirroring schemes to ensure data redundancy and availability, while also incorporating a cloud-based monitoring system for enhanced security and data protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional storage systems use complex and redundant processes for data management and security, then data reliability is improved, but latency increases and productivity decreases
Solution Approach 1:
The patent extracts the security monitoring function from the main storage processing path by introducing a separate anomaly detection system that monitors compressibility metrics independently. This allows security checks to occur without blocking normal write operations, thus maintaining data reliability while reducing latency.
Solution Approach 2:
The patent introduces compressibility metrics as an intermediary indicator to detect ransomware threats. Instead of directly analyzing file contents or blocking operations, the system uses compressibility changes as a mediator to identify anomalies, enabling security monitoring without significant performance overhead.
2Reliability
If traditional storage systems use complex and redundant processes for data management, then data integrity is improved, but device complexity increases
Solution Approach 1:
The patent changes the monitoring parameter from complex file analysis to simple compressibility metrics. By tracking how well data compresses over time, the system detects ransomware encryption without needing complex decryption or content analysis, thus maintaining data integrity while reducing process complexity.
Solution Approach 2:
The storage system performs self-monitoring by analyzing its own compressibility characteristics. The system automatically detects anomalies in data patterns without external intervention, maintaining data integrity through self-service monitoring rather than complex external verification processes.
3Object-affected harmful factors
If ransomware encrypts data on a storage system, then data security is compromised, but detection difficulty increases
Solution Approach 1:
The patent converts the harmful effect of ransomware encryption into a detectable signal. Encrypted data has distinct compressibility characteristics compared to normal data, so the very act of encryption creates an anomaly that the monitoring system can easily detect by measuring compressibility changes.
Solution Approach 2:
The patent changes the 'color' or observable property of data from content-based to compressibility-based detection. Instead of trying to detect encryption by analyzing data content (which is hidden), the system detects changes in compressibility properties, making the threat visible through a different characteristic.
Data Source
AI summary
An illustrative method includes a data protection system determining a first compressibility metric associated with write traffic processed by a storage system, the first compressibility metric indicating an amount of storage space saved if the write traffic is compressed; determining a second compressibility metric associated with read traffic processed by a storage system, the second compressibility metric indicating an amount of storage space saved if the read traffic is compressed; determining, based on a comparison of the first compressibility metric with the second compressibility metric, that the write traffic is less compressible than the read traffic; determining, based on the write traffic being less compressible than the read traffic, that the storage system is possibly being targeted by a security threat; and performing, based on the determining that the storage system is possibly being targeted by the security threat, a remedial action with respect to the storage system.


