I/O Proxy Ransomware Detection in Cloud Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ransomware attacks pose significant challenges in detection and mitigation due to their ability to conceal their presence and encrypt significant portions of storage volumes, making it difficult for existing security measures to accurately determine the presence of such malicious activity based on imperfect statistical analyses.

Innovation Solution

The use of I/O proxy devices interposed between hardware processing elements and data storage devices in cloud provider networks to analyze input/output patterns for anomalous activity indicative of ransomware attacks, coupled with a security posture management service that correlates these findings with other security data to enable near-real-time detection and remediation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If statistical analysis methods are used to detect ransomware, then detection capability is provided, but detection accuracy deteriorates due to imperfect statistical analyses and ability of ransomware to conceal presence

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection accuracy
Core Design Contradiction:
Difficulty of detecting and measuringVSMeasurement precision

Solution Approach 1:

The patent introduces an I/O proxy device as an intermediary component positioned between the compute instance and storage device. This proxy device monitors and analyzes I/O operations without requiring modification of the guest operating system or application software. The proxy captures I/O messages, analyzes patterns indicative of ransomware (such as rapid encryption operations), and triggers remediation actions. This intermediary approach enables accurate detection while maintaining system integrity and avoiding direct interference with the potentially compromised system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If I/O proxy devices are deployed to monitor I/O patterns, then detection accuracy improves, but device complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system architecture segments the detection functionality into a separate I/O proxy device that is independent from both the compute instance and storage device. This segmentation allows the proxy to specialize in monitoring and analysis without adding complexity to the core computing or storage systems. The proxy device handles the complex task of pattern recognition and anomaly detection, while the original systems maintain their simplified operational models.

Inventive Principle:
Principle #1Segmentation

3Productivity

If rapid detection and remediation actions are implemented, then productivity is improved through quick response, but device complexity increases due to automated remediation mechanisms

Engineering Contradiction:
Improveresponse speedVSAvoidremediation system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by maintaining I/O message buffers and analyzing patterns in real-time before ransomware can cause significant damage. The I/O proxy device continuously monitors I/O operations, identifies suspicious patterns (such as rapid sequential writes indicative of encryption), and triggers remediation actions like snapshot creation or I/O throttling. This preliminary detection and response mechanism enables quick containment of threats before they can encrypt large portions of data.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12058169B1Automated ransomware recovery using log-structured storage
Publication Date: 2024.08.06 AMAZON TECH INC
  • US12058169B1 patent drawing
  • US12058169B1 patent drawing
  • US12058169B1 patent drawing

AI summary

Techniques are described for monitoring and analyzing input/output (I/O) messages for patterns indicative of ransomware attacks affecting computer systems of a cloud provider, and for performing various remediation actions to mitigate data loss once a potential ransomware attack is detected. The monitoring of I/O activity for such patterns is performed at least in part by I/O proxy devices coupled to computer systems of a cloud provider network, where an I/O proxy device is interposed in the I/O path between guest operating systems running on a computer system and storage devices to which I/O messages are destined. An I/O proxy device can analyze I/O messages for patterns indicative of potential ransomware attacks by monitoring for anomalous I/O patterns which may, e.g., be indicative of a malicious process attempting to encrypt or otherwise render in accessible a significant portion of one or more storage volumes as part of a ransomware attack.