Deduplication Efficiency Metrics for Unauthorized Encryption Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current storage systems lack active functionality to differentiate between legitimate and non-legitimate encryption, allowing cybercriminals to encrypt files undetected, leading to issues like ransomware attacks.

Innovation Solution

A method involving deduplication efficiency metrics to detect unauthorized encryption by comparing actual deduplication efficiency values with expected values and generating alerts or performing remedial actions when predefined criteria are met, such as monitoring concurrent users and sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If no active functionality is implemented to detect encryption, then the storage system maintains simplicity and avoids false alerts, but unauthorized encryption cannot be detected and security is compromised

Engineering Contradiction:
ImprovesecurityVSAvoiddetection functionality
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces deduplication efficiency metrics as an intermediary indicator to indirectly detect unauthorized encryption. Instead of directly monitoring encryption operations, the system measures deduplication efficiency, which naturally degrades when unauthorized encryption occurs. This intermediary approach enables security detection without requiring direct encryption monitoring functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous monitoring of deduplication efficiency metrics and compares them against baseline thresholds. When efficiency drops below expected levels, the system generates alerts and can trigger automated remedial actions. This feedback loop enables dynamic security response based on observed storage system performance.

Inventive Principle:
Principle #23Feedback

2Reliability

If deduplication efficiency monitoring is implemented to detect unauthorized encryption, then security detection capability is improved, but system complexity and computational overhead increase

Engineering Contradiction:
Improveunauthorized encryption detectionVSAvoidmonitoring system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system leverages existing deduplication operations to generate security detection data. The same deduplication processes that serve storage optimization purposes also provide the metrics needed for security monitoring. This self-service approach eliminates the need for separate monitoring infrastructure and reduces overall system complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The deduplication mechanism serves dual purposes: storage optimization and security detection. By making the deduplication system multi-functional, the patent avoids adding separate monitoring complexity while enabling unauthorized encryption detection through the same operational data streams.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of time

If real-time deduplication efficiency evaluation is performed, then unauthorized encryption can be detected promptly, but processing time and system performance may be impacted

Engineering Contradiction:
Improvedetection response timeVSAvoidstorage system performance
Core Design Contradiction:
Loss of timeVSProductivity

Solution Approach 1:

The system pre-calculates and maintains deduplication efficiency metrics as part of normal storage operations. By having this data readily available from ongoing deduplication processes, the system can immediately evaluate security conditions without performing additional real-time computations, thus avoiding performance impact while enabling prompt detection.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11822656B2Detection of unauthorized encryption using deduplication efficiency metric
Publication Date: 2023.11.21 EMC IP HLDG CO LLC
  • US11822656B2 patent drawing
  • US11822656B2 patent drawing
  • US11822656B2 patent drawing

AI summary

Techniques are provided for detection of unauthorized encryption using one or more deduplication efficiency metrics. One method comprises obtaining a deduplication efficiency value for a deduplication operation in a storage system; evaluating the deduplication efficiency value for the deduplication operation relative to an expected deduplication efficiency value; and performing one or more automated remedial actions, such as generating an alert notification, in response to the evaluating satisfying one or more deduplication criteria. A count of a number of concurrent users may be compared to an expected number of concurrent users, and/or (ii) a count of a number of concurrent sessions for a given user may be compared to an expected number of concurrent sessions for the given user. A ransomware alert or an unauthorized encryption alert may be generated when the evaluating and/or the comparison satisfy predefined attack criteria.