File Entropy Analysis in Storage Systems for Partial Ransomware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional ransomware detection techniques struggle to identify ransomware that employs partial encryption of files, which can quickly infect enterprise documents and spread undetected due to the partially encrypted files remaining readable and statistically resembling unencrypted versions.

Innovation Solution

A cloud storage system analyzes file entropy and monitors file sharing commands to detect anomalies, generating a file sharing signature based on baseline activity, and blocks access when entropy thresholds are exceeded, indicating potential ransomware attacks, reverting affected files to previous versions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If conventional ransomware detection techniques are used, then detection simplicity is maintained, but detection capability against partial encryption ransomware deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection technique complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent changes the detection parameter from simple file integrity checks to entropy analysis. By calculating and comparing entropy values of file portions before and after potential encryption events, the system can detect partial encryption ransomware that conventional techniques miss. This parameter transformation enables detection of subtle changes while maintaining operational simplicity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent segments file analysis into specific portions rather than requiring full file analysis. By analyzing only affected portions of files and comparing their entropy characteristics, the system achieves high detection accuracy with reduced computational complexity compared to analyzing entire files or using comprehensive security suites.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If entropy analysis is performed on entire files, then detection accuracy is improved, but processing time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent divides files into portions and analyzes only the segments that may have been affected by ransomware. This selective segment analysis maintains high detection accuracy by focusing on critical areas while dramatically reducing the total processing time compared to analyzing entire files, especially for large enterprise documents.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by performing entropy analysis on only the necessary portions of files rather than complete files. This approach achieves sufficient detection accuracy for security purposes without the excessive time cost of full-file analysis, striking an optimal balance between precision and efficiency.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If file sharing access is unrestricted, then ease of operation is maintained, but security against ransomware deteriorates

Engineering Contradiction:
Improvefile sharing accessibilityVSAvoidransomware spread
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback mechanisms that continuously monitor file sharing activities and entropy changes. When ransomware activity is detected through entropy analysis, the system automatically provides feedback by blocking further access or alerting users, thereby maintaining ease of operation for legitimate sharing while preventing ransomware spread through dynamic security responses.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12423424B2Analyzing file entropy to identify adverse conditions
Publication Date: 2025.09.23 DELL PROD LP
  • US12423424B2 patent drawing
  • US12423424B2 patent drawing
  • US12423424B2 patent drawing

AI summary

A network connected storage device detects unusual file-sharing-command activity based on a baseline file-sharing-command signature and analyzes files stored on the storage with respect to a parameter, such as entropy, to determine whether ransomware may have infiltrated the storage device, or a storage associated therewith. Applying by the storage device a function to an entropy value corresponding to a second portion of a file may result in a determination that an analyzed entropy corresponding to the second portion may have been partially encrypted by ransomware. The analyzed entropy corresponding to the second file portion may be compared to an entropy of a first file portion. The first file portion may be a different portion of the same file as the second portion or may be the same portion of the same file that resulted from analysis before the triggering event.