Honeypot File Detection for Crypto-Ransomware on SSDs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Crypto-ransomware encrypts files on solid state devices (SSDs) making them unreadable, and existing prevention methods are inadequate in detecting and preventing unauthorized access effectively.
Innovation Solution
A system utilizing honeypot files, generated with random data, is implemented on SSDs to detect and prevent crypto-ransomware by monitoring access requests and taking action based on predefined detection modes, such as halting access or requesting authentication upon unauthorized attempts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If honeypot files are used to detect crypto-ransomware, then detection capability is improved, but device complexity increases
Solution Approach 1:
The system pre-generates honeypot files with identifiable markers and places them in the file system before any ransomware attack occurs. These files are prepared in advance with known characteristics that will trigger detection when accessed by unauthorized processes
Solution Approach 2:
The honeypot files serve as intermediary elements between the legitimate file system and the ransomware detection mechanism. They act as decoys that mediate between normal file operations and security detection, allowing the system to monitor access patterns without directly interfering with legitimate user activities
2Reliability
If access monitoring is implemented to detect unauthorized attempts, then security is improved, but processing overhead increases
Solution Approach 1:
The monitoring system applies different levels of scrutiny to different files based on their honeypot status. Legitimate files receive standard access handling, while honeypot files trigger enhanced monitoring and authentication checks, concentrating processing resources only where security threats are most likely
3Reliability
If honeypot files are randomly distributed on SSD, then detection effectiveness is improved, but storage space is reduced
Solution Approach 1:
The system distributes honeypot files throughout the SSD storage space, using a portion of the total capacity for security purposes. This partial deployment provides effective detection coverage without completely filling the storage device, balancing security needs with available storage capacity
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A memory system includes a controller having a processor and one or more memory media, and a method of operating the memory system. A host generates honeypot files and the processor is configured to write the honeypot files onto the memory media at random locations. The controller monitors the locations of the randomly distributed honeypot files for access. The host may set a mode of operation concerning access of the honeypot files randomly distributed on the memory media. In a strict mode of operation, the controller may halt access to the memory media or require authentication if a single honeypot file is accessed. In a moderate mode of operation, the controller may analyze the memory media to determine if under attack if a single honeypot file is accessed. In a light mode of operation, the controller may not take any action until a predetermined number of honeypot files are accessed.