Honeypot File Detection for Crypto-Ransomware on SSDs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Crypto-ransomware encrypts files on solid state devices (SSDs) making them unreadable, and existing prevention methods are inadequate in detecting and preventing unauthorized access effectively.

Innovation Solution

A system utilizing honeypot files, generated with random data, is implemented on SSDs to detect and prevent crypto-ransomware by monitoring access requests and taking action based on predefined detection modes, such as halting access or requesting authentication upon unauthorized attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If honeypot files are used to detect crypto-ransomware, then detection capability is improved, but device complexity increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system pre-generates honeypot files with identifiable markers and places them in the file system before any ransomware attack occurs. These files are prepared in advance with known characteristics that will trigger detection when accessed by unauthorized processes

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The honeypot files serve as intermediary elements between the legitimate file system and the ransomware detection mechanism. They act as decoys that mediate between normal file operations and security detection, allowing the system to monitor access patterns without directly interfering with legitimate user activities

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access monitoring is implemented to detect unauthorized attempts, then security is improved, but processing overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The monitoring system applies different levels of scrutiny to different files based on their honeypot status. Legitimate files receive standard access handling, while honeypot files trigger enhanced monitoring and authentication checks, concentrating processing resources only where security threats are most likely

Inventive Principle:
Principle #3Local quality

3Reliability

If honeypot files are randomly distributed on SSD, then detection effectiveness is improved, but storage space is reduced

Engineering Contradiction:
Improvedetection effectivenessVSAvoidstorage space
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system distributes honeypot files throughout the SSD storage space, using a portion of the total capacity for security purposes. This partial deployment provides effective detection coverage without completely filling the storage device, balancing security needs with available storage capacity

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3622431B1Crypto-ransomware compromise detection
Publication Date: 2022.08.10 MICRON TECHNOLOGY INC
  • EP3622431B1 patent drawingFigure 1
  • EP3622431B1 patent drawingFigure 2
  • EP3622431B1 patent drawingFigure 3

AI summary

A memory system includes a controller having a processor and one or more memory media, and a method of operating the memory system. A host generates honeypot files and the processor is configured to write the honeypot files onto the memory media at random locations. The controller monitors the locations of the randomly distributed honeypot files for access. The host may set a mode of operation concerning access of the honeypot files randomly distributed on the memory media. In a strict mode of operation, the controller may halt access to the memory media or require authentication if a single honeypot file is accessed. In a moderate mode of operation, the controller may analyze the memory media to determine if under attack if a single honeypot file is accessed. In a light mode of operation, the controller may not take any action until a predetermined number of honeypot files are accessed.