Deduplication Efficiency Metrics for Unauthorized Encryption Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current storage systems lack active functionality to differentiate between legitimate and non-legitimate encryption, allowing cybercriminals to encrypt files undetected, leading to issues like ransomware attacks.
Innovation Solution
A method involving deduplication efficiency metrics to detect unauthorized encryption by comparing actual deduplication efficiency values with expected values and generating alerts or performing remedial actions when predefined criteria are met, such as monitoring concurrent users and sessions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If no active functionality is implemented to detect encryption, then the storage system maintains simplicity and avoids false alerts, but unauthorized encryption cannot be detected and security is compromised
Solution Approach 1:
The patent introduces deduplication efficiency metrics as an intermediary indicator to indirectly detect unauthorized encryption. Instead of directly monitoring encryption operations, the system measures deduplication efficiency, which naturally degrades when unauthorized encryption occurs. This intermediary approach enables security detection without requiring direct encryption monitoring functionality.
Solution Approach 2:
The system implements continuous monitoring of deduplication efficiency metrics and compares them against baseline thresholds. When efficiency drops below expected levels, the system generates alerts and can trigger automated remedial actions. This feedback loop enables dynamic security response based on observed storage system performance.
2Reliability
If deduplication efficiency monitoring is implemented to detect unauthorized encryption, then security detection capability is improved, but system complexity and computational overhead increase
Solution Approach 1:
The system leverages existing deduplication operations to generate security detection data. The same deduplication processes that serve storage optimization purposes also provide the metrics needed for security monitoring. This self-service approach eliminates the need for separate monitoring infrastructure and reduces overall system complexity.
Solution Approach 2:
The deduplication mechanism serves dual purposes: storage optimization and security detection. By making the deduplication system multi-functional, the patent avoids adding separate monitoring complexity while enabling unauthorized encryption detection through the same operational data streams.
3Loss of time
If real-time deduplication efficiency evaluation is performed, then unauthorized encryption can be detected promptly, but processing time and system performance may be impacted
Solution Approach 1:
The system pre-calculates and maintains deduplication efficiency metrics as part of normal storage operations. By having this data readily available from ongoing deduplication processes, the system can immediately evaluate security conditions without performing additional real-time computations, thus avoiding performance impact while enabling prompt detection.
Data Source
AI summary
Techniques are provided for detection of unauthorized encryption using one or more deduplication efficiency metrics. One method comprises obtaining a deduplication efficiency value for a deduplication operation in a storage system; evaluating the deduplication efficiency value for the deduplication operation relative to an expected deduplication efficiency value; and performing one or more automated remedial actions, such as generating an alert notification, in response to the evaluating satisfying one or more deduplication criteria. A count of a number of concurrent users may be compared to an expected number of concurrent users, and/or (ii) a count of a number of concurrent sessions for a given user may be compared to an expected number of concurrent sessions for the given user. A ransomware alert or an unauthorized encryption alert may be generated when the evaluating and/or the comparison satisfy predefined attack criteria.


