Data Tampering Defense Through Entropy-Based Ransomware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing ransomware detection methods struggle to effectively identify zero-day attacks with low false positive and false negative rates, particularly in legacy systems, and are often unable to detect unauthorized data encryption efficiently.
Innovation Solution
A system that continuously monitors data entropy changes by measuring order metrics across multiple portions of target data using EnFrets, comparing these measurements to predefined ranges, and triggering alarms or disconnecting systems to prevent unauthorized encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If signature-based detection methods are used to identify known ransomware, then detection accuracy for known threats is improved, but the system becomes ineffective against zero-day attacks and requires frequent updates
Solution Approach 1:
The patent transitions from signature-based detection to entropy-based detection, fundamentally changing the detection parameter from known malware signatures to statistical properties of encrypted data. This allows the system to detect unknown ransomware variants by monitoring changes in data entropy rather than relying on predefined signatures.
Solution Approach 2:
The patent replaces the mechanical approach of signature matching with a statistical physics approach using entropy measurements. Instead of comparing data against known malware patterns, the system uses thermodynamic concepts (entropy, energy, temperature) to detect the presence of encryption activity, making it adaptable to any ransomware that modifies data entropy.
2Adaptability or versatility
If behavioral analysis is used to detect ransomware operations, then zero-day attack detection capability is improved, but false positive rate increases significantly
Solution Approach 1:
The patent introduces entropy as an intermediary measurement that indirectly detects encryption behavior without directly monitoring suspicious file operations. By measuring the statistical properties of data (entropy, energy, temperature) rather than directly observing file access patterns, the system reduces false positives while maintaining zero-day detection capability.
Solution Approach 2:
The system continuously monitors entropy, energy, and temperature metrics and uses feedback loops to adjust detection thresholds. This allows the system to learn normal entropy variations in different contexts and only trigger alerts when entropy changes exceed established baselines, significantly reducing false positives.
3Reliability
If filesystem permissions are restricted to prevent file encryption, then data protection is improved, but compatibility with legacy software deteriorates
Solution Approach 1:
The patent replaces the mechanical filesystem permission model with a statistical monitoring approach. Instead of preventing encryption through access controls, the system allows files to be encrypted but detects the encryption process through entropy measurements, enabling protection without restricting legacy software functionality.
Data Source
AI summary
Apparatus and methods for detecting and thwarting ransomware attacks are disclosed. Target data (11) is read from a repository of data (12). An order measurement sensor (14) calculates a number of measurements of order (16) of the target data (11). Each measurement of order (16) is calculated from an EnFret (40) which describes the portion of the target data (11) to use. A comparator (18) compares the measurement of order (14) with a plurality of pre-determined levels of order (22P) retrieved from a library (20). If the comparator (18) determines that at least one of these measurements of order (16) falls outside of the plurality of range of order (23P), then an indicator (24) indicates that an anomalous measurement of order (16) has been made. An anomalous measurement of order indicates that the target data (11) is tampered with and encrypted.


