File Entropy Analysis in Storage Systems for Partial Ransomware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional ransomware detection techniques struggle to identify ransomware that employs partial encryption of files, which can quickly infect enterprise documents and spread undetected due to the partially encrypted files remaining readable and statistically resembling unencrypted versions.
Innovation Solution
A cloud storage system analyzes file entropy and monitors file sharing commands to detect anomalies, generating a file sharing signature based on baseline activity, and blocks access when entropy thresholds are exceeded, indicating potential ransomware attacks, reverting affected files to previous versions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If conventional ransomware detection techniques are used, then detection simplicity is maintained, but detection capability against partial encryption ransomware deteriorates
Solution Approach 1:
The patent changes the detection parameter from simple file integrity checks to entropy analysis. By calculating and comparing entropy values of file portions before and after potential encryption events, the system can detect partial encryption ransomware that conventional techniques miss. This parameter transformation enables detection of subtle changes while maintaining operational simplicity.
Solution Approach 2:
The patent segments file analysis into specific portions rather than requiring full file analysis. By analyzing only affected portions of files and comparing their entropy characteristics, the system achieves high detection accuracy with reduced computational complexity compared to analyzing entire files or using comprehensive security suites.
2Measurement precision
If entropy analysis is performed on entire files, then detection accuracy is improved, but processing time increases
Solution Approach 1:
The patent divides files into portions and analyzes only the segments that may have been affected by ransomware. This selective segment analysis maintains high detection accuracy by focusing on critical areas while dramatically reducing the total processing time compared to analyzing entire files, especially for large enterprise documents.
Solution Approach 2:
The patent applies partial action by performing entropy analysis on only the necessary portions of files rather than complete files. This approach achieves sufficient detection accuracy for security purposes without the excessive time cost of full-file analysis, striking an optimal balance between precision and efficiency.
3Ease of operation
If file sharing access is unrestricted, then ease of operation is maintained, but security against ransomware deteriorates
Solution Approach 1:
The patent implements feedback mechanisms that continuously monitor file sharing activities and entropy changes. When ransomware activity is detected through entropy analysis, the system automatically provides feedback by blocking further access or alerting users, thereby maintaining ease of operation for legitimate sharing while preventing ransomware spread through dynamic security responses.
Data Source
AI summary
A network connected storage device detects unusual file-sharing-command activity based on a baseline file-sharing-command signature and analyzes files stored on the storage with respect to a parameter, such as entropy, to determine whether ransomware may have infiltrated the storage device, or a storage associated therewith. Applying by the storage device a function to an entropy value corresponding to a second portion of a file may result in a determination that an analyzed entropy corresponding to the second portion may have been partially encrypted by ransomware. The analyzed entropy corresponding to the second file portion may be compared to an entropy of a first file portion. The first file portion may be a different portion of the same file as the second portion or may be the same portion of the same file that resulted from analysis before the triggering event.


