Inline Offline Ransomware Detection Cue Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current malware detection systems in production sites and vaults operate independently, with offline ransomware checks unable to inspect all protected data, leading to inefficiencies and incomplete detection.

Innovation Solution

Integration of inline and offline ransomware detection processes, where the inline process identifies suspicious data and sends cues to the offline process for prioritized inspection, enabling focused evaluation and corrective measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If offline ransomware checks are performed in the vault on all protected data, then detection completeness is improved, but processing time and computational resources increase significantly

Engineering Contradiction:
Improvedetection completenessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The inline ransomware detection process performs preliminary detection and analysis on data before it is stored in the vault. It identifies suspicious patterns and generates cues about potentially infected files, so that when offline checks are performed later, they can focus only on the most suspicious data rather than examining all protected data comprehensively.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of performing exhaustive offline ransomware checks on all protected data in the vault, the system performs partial checks only on data subsets identified as high-risk by the inline detection process. The offline process responds to cues from inline detection by prioritizing inspection of specific data identified as potentially affected, rather than conducting a complete scan of all vault data.

Inventive Principle:
Principle #16Partial or excessive action

2Device complexity

If inline and offline ransomware detection processes operate independently, then system complexity is reduced, but detection effectiveness decreases

Engineering Contradiction:
Improvesystem complexityVSAvoiddetection effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The inline ransomware detection process generates cues based on its analysis of incoming data, and these cues are fed back to the offline ransomware detection process. The offline process uses this feedback information to prioritize its inspection activities, creating a closed-loop system where detection results from one process inform and improve the effectiveness of the other process.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent merges the inline and offline ransomware detection processes into a coordinated system. Rather than operating as separate independent systems, the two processes are integrated through cue generation and response mechanisms, allowing them to work together synergistically to improve overall detection effectiveness while maintaining operational efficiency.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20240338449A1Integration of inline malware discovery and offline vault ransomware prediction
Publication Date: 2024.10.10 DELL PROD LP
  • US20240338449A1 patent drawing
  • US20240338449A1 patent drawing
  • US20240338449A1 patent drawing

AI summary

One example method includes, by a first malware detection process, checking an aspect of a production system for evidence of a malware process, identifying the aspects as possibly affected by the malware process, generating cues that identify the aspect, and transmitting the cues to a second malware detection process. The second malware detection process checks the cues to identify the aspect, and determines that the malware process has affected the aspect. The first malware detection process may be an inline process, and the second malware detection process may be an offline process.