Continuous Data Management for Ransomware Recovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data management systems face challenges in providing rapid data recovery and ransomware detection, with snapshot-based backup solutions offering poor recovery point objectives (RPOs) and existing ransomware detection methods being ineffective, particularly in real-time scenarios.
Innovation Solution
A disaster recovery system that employs continuous data management (CDM) to monitor compute infrastructure, intercept and replicate virtual disk I/O streams, and form recoverable snapshot-log chains for near-real-time data replication and recovery, enabling RPOs of seconds and rapid ransomware detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If snapshot-based backup is used, then data recovery capability is provided, but recovery point objective (RPO) is poor (tens of minutes to several hours)
Solution Approach 1:
The patent implements continuous data protection by continuously monitoring and replicating data changes to the backup site, eliminating the interruptions and delays inherent in periodic snapshots. This ensures that data is always being backed up without stopping, achieving near-real-time recovery capability.
Solution Approach 2:
The system performs preliminary actions by continuously preparing backup copies of data changes before actual ransomware attacks occur. The backup infrastructure is pre-configured and continuously updated, so when an attack happens, recovery can immediately begin from the most recent backup point.
2Loss of time
If frequent snapshots are taken to improve RPO, then recovery time is reduced, but system performance is impacted and user experience deteriorates
Solution Approach 1:
Instead of periodic snapshots that interrupt the system, the patent uses continuous background monitoring and replication of data changes. This continuous action happens transparently without requiring system freezes or interruptions, maintaining both fast recovery capability and system performance.
Solution Approach 2:
The backup process is segmented into continuous change detection, data replication, and backup storage operations that run independently in the background. This segmentation allows backup operations to proceed continuously without blocking or impacting the main system operations.
3Difficulty of detecting and measuring
If signature-based ransomware detection is used, then detection capability is provided, but detection accuracy is ineffective as ransomware uses different signatures
Solution Approach 1:
The system continuously monitors data changes and compares them against established patterns of legitimate operations. When changes deviate from normal behavior patterns, the system triggers alerts and isolation procedures, providing feedback-based detection that adapts to various ransomware variants without relying on fixed signatures.
Solution Approach 2:
The patent introduces an intermediary layer of continuous monitoring and analysis between the ransomware and the detection system. This intermediary continuously observes data changes, file access patterns, and system behavior, analyzing them for signs of malicious activity without direct confrontation with the ransomware itself.
4Difficulty of detecting and measuring
If behavioral analysis-based ransomware detection is used, then detection capability is improved, but computational resources are taxed
Solution Approach 1:
Instead of analyzing all system behavior globally, the patent applies focused monitoring at specific critical points where data changes occur. The system monitors only the data access patterns, file modification times, and storage operations that are most indicative of ransomware activity, concentrating computational resources where they are most effective.
Solution Approach 2:
The system performs partial behavioral analysis by monitoring only the most relevant data change patterns rather than attempting complete system analysis. This selective monitoring approach provides sufficient detection capability while significantly reducing the computational burden compared to comprehensive behavioral analysis.
5Difficulty of detecting and measuring
If status-based detection systems are used to look for system changes, then detection is provided, but real-time operation is not achieved and rapid notification cannot be provided
Solution Approach 1:
The system continuously monitors data changes and backup status in real-time, maintaining constant observation without interruption. This continuous monitoring enables immediate detection and response to ransomware activities, eliminating the delays inherent in periodic status checks.
Solution Approach 2:
The backup system is pre-configured with continuous monitoring capabilities that are ready to detect and report ransomware activities immediately upon occurrence. The infrastructure is prepared in advance with monitoring agents and analysis frameworks that can rapidly identify and notify about malicious events without delay.
Data Source
AI summary
Examples relate generally to systems and methods for orchestrating a recovery in the event of a ransomware attack on a compute infrastructure. More specifically, some examples include techniques for application migration in cloud data management, ransomware recovery, and mitigation of lost data.


