Malware Detection via I/O Signatures in Encrypted Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing malware detection techniques in data storage systems are ineffective in identifying malware-induced changes in host-encrypted data, as such changes do not significantly alter reducibility ratios, and fail to detect malware re-encryption of encrypted data.

Innovation Solution

A method that monitors I/O activity for changes in compression and deduplication ratios, creates an IOC record based on detected changes, and matches these changes across multiple storage objects to identify suspected malware activity, even in host-encrypted data, by using I/O profiles and IOC matching criteria.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If malware detection relies on monitoring reducibility ratios, then detection simplicity is maintained, but detection effectiveness deteriorates for host-encrypted data

Engineering Contradiction:
Improvedetection simplicityVSAvoiddetection effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transitions from monitoring a single parameter (reducibility ratio) to monitoring multiple I/O characteristics including I/O size, I/O rate, and I/O pattern. This parameter expansion enables effective detection of malware-induced changes in host-encrypted data while maintaining the automated monitoring approach.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The IOC record structure is designed to be universal, capturing multiple types of I/O characteristics and their unexpected changes. This multi-functional IOC framework can detect various malware activities across different storage objects regardless of encryption status, making the detection system broadly applicable.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If single storage object monitoring is used, then detection focus is maintained, but detection coverage deteriorates

Engineering Contradiction:
Improvedetection focusVSAvoiddetection coverage
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent combines monitoring results from multiple storage objects by matching IOC records across objects. When the same IOC signature appears in multiple storage objects, it indicates a coordinated malware attack, thereby expanding detection coverage while maintaining precise identification of malware behavior patterns.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The detection process is segmented into distinct phases: individual storage object monitoring, IOC record creation, and cross-object IOC matching. This segmentation allows precise monitoring of each object while systematically aggregating results to achieve comprehensive coverage of malware activities across the storage system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12596802B2Malware detection techniques
Publication Date: 2026.04.07 DELL PROD LP
  • US12596802B2 patent drawing
  • US12596802B2 patent drawing
  • US12596802B2 patent drawing

AI summary

In at least one embodiment, processing can include: detecting a first unexpected change to a first characteristic for a first storage object (SO); detecting no unexpected change to the first characteristic for a second SO; and responsive to said detecting the first unexpected change, performing first processing including: detecting a second unexpected change to a second characteristic for the first SO; creating an indication of compromise (IOC) including a signature characterizing behavior of suspected malware activity impacting the first SO, the signature including the first and second unexpected changes; detecting a third unexpected change to the second characteristic with respect to the second SO; determining, in accordance with criteria, that unexpected changes in I/O activity of the second SO match the IOC, wherein the unexpected changes include the third unexpected change; and responsive to determining the unexpected changes match the IOC, determining suspected malware activity impacting the second SO.