Data Tampering Defense Through Entropy-Based Ransomware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing ransomware detection methods struggle to effectively identify zero-day attacks with low false positive and false negative rates, particularly in legacy systems, and are often unable to detect unauthorized data encryption efficiently.

Innovation Solution

A system that continuously monitors data entropy changes by measuring order metrics across multiple portions of target data using EnFrets, comparing these measurements to predefined ranges, and triggering alarms or disconnecting systems to prevent unauthorized encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If signature-based detection methods are used to identify known ransomware, then detection accuracy for known threats is improved, but the system becomes ineffective against zero-day attacks and requires frequent updates

Engineering Contradiction:
Improvedetection accuracyVSAvoideffectiveness against zero-day attacks
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent transitions from signature-based detection to entropy-based detection, fundamentally changing the detection parameter from known malware signatures to statistical properties of encrypted data. This allows the system to detect unknown ransomware variants by monitoring changes in data entropy rather than relying on predefined signatures.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces the mechanical approach of signature matching with a statistical physics approach using entropy measurements. Instead of comparing data against known malware patterns, the system uses thermodynamic concepts (entropy, energy, temperature) to detect the presence of encryption activity, making it adaptable to any ransomware that modifies data entropy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If behavioral analysis is used to detect ransomware operations, then zero-day attack detection capability is improved, but false positive rate increases significantly

Engineering Contradiction:
Improvezero-day attack detection capabilityVSAvoidfalse positive rate
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces entropy as an intermediary measurement that indirectly detects encryption behavior without directly monitoring suspicious file operations. By measuring the statistical properties of data (entropy, energy, temperature) rather than directly observing file access patterns, the system reduces false positives while maintaining zero-day detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system continuously monitors entropy, energy, and temperature metrics and uses feedback loops to adjust detection thresholds. This allows the system to learn normal entropy variations in different contexts and only trigger alerts when entropy changes exceed established baselines, significantly reducing false positives.

Inventive Principle:
Principle #23Feedback

3Reliability

If filesystem permissions are restricted to prevent file encryption, then data protection is improved, but compatibility with legacy software deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoidcompatibility with legacy software
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces the mechanical filesystem permission model with a statistical monitoring approach. Instead of preventing encryption through access controls, the system allows files to be encrypted but detects the encryption process through entropy measurements, enabling protection without restricting legacy software functionality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250209165A1Data Tampering Defense System
Publication Date: 2025.06.26 CALADESI TECHNOLOGY INC
  • US20250209165A1 patent drawing
  • US20250209165A1 patent drawing
  • US20250209165A1 patent drawing

AI summary

Apparatus and methods for detecting and thwarting ransomware attacks are disclosed. Target data (11) is read from a repository of data (12). An order measurement sensor (14) calculates a number of measurements of order (16) of the target data (11). Each measurement of order (16) is calculated from an EnFret (40) which describes the portion of the target data (11) to use. A comparator (18) compares the measurement of order (14) with a plurality of pre-determined levels of order (22P) retrieved from a library (20). If the comparator (18) determines that at least one of these measurements of order (16) falls outside of the plurality of range of order (23P), then an indicator (24) indicates that an anomalous measurement of order (16) has been made. An anomalous measurement of order indicates that the target data (11) is tampered with and encrypted.