Detecting Unauthorized Encryption via Compression Rate Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data storage systems face inefficiencies due to redundant data storage and inability to differentiate between authorized and unauthorized encryption processes, particularly in the context of ransomware attacks, leading to resource wastage and security vulnerabilities.
Innovation Solution
Implementing monitoring tools that track file compression and encryption processes within the system, calculating a file compression success rate to detect unauthorized encryptions by distinguishing between compressed and encrypted files, and alerting administrators to potential security threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If data compression processes are combined with backup and recovery processes, then storage space efficiency is improved and costs are reduced, but the system cannot differentiate between compressed and encrypted files, leading to security vulnerabilities
Solution Approach 1:
The patent applies the principle of color changes by using file attribute tags to mark and differentiate between compressed and encrypted files. These tags act as visual identifiers (like colors) that allow the system to distinguish file types without changing the actual file content, enabling both efficient storage management and security monitoring
Solution Approach 2:
The system implements feedback mechanisms by continuously monitoring file operations and updating file attribute tags based on compression and encryption status. This feedback loop allows the system to adaptively manage storage resources while maintaining security awareness through real-time file state tracking
2Reliability
If monitoring tools track file compression and encryption processes, then unauthorized encryptions can be detected, but system complexity increases
Solution Approach 1:
The patent applies universality by designing a file attribute tagging system that serves multiple functions simultaneously: it tracks compression status, encryption status, and enables security monitoring all through the same infrastructure. This multi-functional approach reduces overall system complexity compared to implementing separate monitoring systems for each function
Solution Approach 2:
The file attribute tags act as intermediaries between the compression/encryption processes and the monitoring system. Rather than requiring direct complex interaction between monitoring tools and file operations, the tags serve as simple mediators that convey file state information, reducing system complexity
3Speed
If symmetric encryption algorithms are used to encrypt data objects, then encryption speed is improved, but the risk of private key compromise increases
Solution Approach 1:
The patent applies segmentation by implementing a hybrid encryption approach where symmetric encryption is used for bulk data encryption (maintaining speed) while asymmetric encryption keys manage the symmetric keys (reducing key compromise risk). This segments the encryption functions into two parts, each optimized for its specific purpose
Solution Approach 2:
Asymmetric encryption keys serve as intermediaries that protect the symmetric encryption keys without directly encrypting the data. This intermediary layer allows the system to use fast symmetric encryption while mitigating the key compromise risk through the security properties of asymmetric key management
4Reliability
If multiple versions of data objects are stored for recovery purposes, then data recovery capability is improved, but storage space consumption and resource inefficiency increase
Solution Approach 1:
The patent applies parameter changes by using file attribute tags to mark data object versions as compressed or encrypted. This allows the system to efficiently store multiple versions by changing only the attribute parameters rather than storing redundant full copies, reducing storage space while maintaining recovery capability
Solution Approach 2:
The system uses selective copying where only essential version information is replicated through attribute tags rather than copying entire data objects. This allows multiple versions to be tracked with minimal storage overhead while maintaining the ability to restore previous states
Data Source
AI summary
At a first time, a system identifies a set of data files which are stored in a part of a data storage system. At a second time, the system identifies each newly encoded data file based on identifying each data file in the set of data files which is encoded and created and/or updated since the first time. The system identifies each compressed data file based on identifying each newly encoded data file which is reduced in size since the first time. The system determines a file compression success rate based on a total count of each compressed data file relative to a total count of each newly encoded data file. If the system determines that the file compression success rate does not satisfy the file compression success rate threshold, the system outputs an alert about an unauthorized encryption in the data storage system.


