Malware Backup Restoration via Snapshot Timing Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data restoration methods face challenges in identifying and utilizing a clean backup that is safe from malware after a malware attack, especially in large organizations where data changes frequently and backups are numerous, leading to potential data loss due to timing discrepancies between backups and attack occurrences.
Innovation Solution
A method involving the formation of a list of designated file types susceptible to malware, periodic snapshots, and backups, with antivirus software analyzing these to determine the timing of a malware attack and identifying a clean backup prior to the attack, allowing for data recovery from a safe restoration point.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If backups are performed frequently to minimize data loss, then the relevance of restored data is improved, but the complexity of identifying a clean backup worsens due to the large number of backups
Solution Approach 1:
The system performs preliminary actions by creating snapshots and associating them with backups before a malware attack occurs. These snapshots serve as pre-prepared reference points that can be quickly identified and used for restoration, eliminating the need to search through numerous backups after an attack is detected.
Solution Approach 2:
Snapshots act as an intermediary between the backup system and the malware detection system. By creating intermediate snapshot points and associating them with specific backups, the system enables efficient correlation between backup versions and security events without requiring direct analysis of all backup data.
2Reliability
If the number of backups is increased to cover frequent data changes, then data recovery completeness is improved, but the time required to identify a clean backup worsens
Solution Approach 1:
The system performs preliminary actions by creating snapshots and associating them with backups before a malware attack occurs. These snapshots serve as pre-prepared reference points that can be quickly identified and used for restoration, eliminating the need to search through numerous backups after an attack is detected.
Solution Approach 2:
The system uses feedback from malware detection events to guide the backup restoration process. When malware is detected, the system receives feedback about the attack timing and uses this information to selectively identify and restore from the appropriate snapshot-associated backup, rather than blindly searching through all backups.
3Reliability
If antivirus scanning is performed on all backups to ensure safety, then the reliability of restored data is improved, but the productivity of the restoration process worsens due to extensive scanning time
Solution Approach 1:
The system extracts and analyzes only the specific snapshot data associated with the backup being considered for restoration, rather than scanning entire backup images. This selective extraction of relevant information from snapshots enables rapid safety verification without the overhead of comprehensive backup scanning.
Solution Approach 2:
Security-relevant information is captured in snapshots as a preliminary action before restoration is needed. These snapshots contain pre-analyzed data about the system state at backup creation time, enabling rapid safety verification during restoration without requiring extensive post-attack scanning.
Data Source
AI summary
Disclosed herein are systems and method for restoring a clean backup after a malware attack. In one aspect, a method forms a list of files that are of a plurality of designated file types that can be infected by malicious software. The method performs one or more snapshots of the files according to a predetermined schedule over a predetermined period of time and performs one or more backups. The method determines that a malware attack is being carried out on the computing device and generates a list of dangerous objects that spread the malware attack. The method compares the list of dangerous objects with the one or more snapshots to determine when the malware attack occurred. The method identifies a clean backup that was created most recently before the malware attack as compared to other backups and recovers data for the computing device from the clean backup.


