Malware Detection via I/O Signatures in Encrypted Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing malware detection techniques in data storage systems are ineffective in identifying malware-induced changes in host-encrypted data, as such changes do not significantly alter reducibility ratios, and fail to detect malware re-encryption of encrypted data.
Innovation Solution
A method that monitors I/O activity for changes in compression and deduplication ratios, creates an IOC record based on detected changes, and matches these changes across multiple storage objects to identify suspected malware activity, even in host-encrypted data, by using I/O profiles and IOC matching criteria.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If malware detection relies on monitoring reducibility ratios, then detection simplicity is maintained, but detection effectiveness deteriorates for host-encrypted data
Solution Approach 1:
The patent transitions from monitoring a single parameter (reducibility ratio) to monitoring multiple I/O characteristics including I/O size, I/O rate, and I/O pattern. This parameter expansion enables effective detection of malware-induced changes in host-encrypted data while maintaining the automated monitoring approach.
Solution Approach 2:
The IOC record structure is designed to be universal, capturing multiple types of I/O characteristics and their unexpected changes. This multi-functional IOC framework can detect various malware activities across different storage objects regardless of encryption status, making the detection system broadly applicable.
2Measurement precision
If single storage object monitoring is used, then detection focus is maintained, but detection coverage deteriorates
Solution Approach 1:
The patent combines monitoring results from multiple storage objects by matching IOC records across objects. When the same IOC signature appears in multiple storage objects, it indicates a coordinated malware attack, thereby expanding detection coverage while maintaining precise identification of malware behavior patterns.
Solution Approach 2:
The detection process is segmented into distinct phases: individual storage object monitoring, IOC record creation, and cross-object IOC matching. This segmentation allows precise monitoring of each object while systematically aggregating results to achieve comprehensive coverage of malware activities across the storage system.
Data Source
AI summary
In at least one embodiment, processing can include: detecting a first unexpected change to a first characteristic for a first storage object (SO); detecting no unexpected change to the first characteristic for a second SO; and responsive to said detecting the first unexpected change, performing first processing including: detecting a second unexpected change to a second characteristic for the first SO; creating an indication of compromise (IOC) including a signature characterizing behavior of suspected malware activity impacting the first SO, the signature including the first and second unexpected changes; detecting a third unexpected change to the second characteristic with respect to the second SO; determining, in accordance with criteria, that unexpected changes in I/O activity of the second SO match the IOC, wherein the unexpected changes include the third unexpected change; and responsive to determining the unexpected changes match the IOC, determining suspected malware activity impacting the second SO.


