NAS Ransomware Detection via File System Audit Events
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for detecting ransomware and unauthorized access in file systems are ineffective, as signature-based detection can be evaded, behavioral analysis is resource-intensive, and status-based detection systems do not provide real-time notification or identify affected users or unauthorized actors.
Innovation Solution
A Network Attached Storage (NAS) system that captures, de-duplicates, and analyzes file system audit events to identify anomalous activity, such as ransomware infections, insider threats, and credential misappropriation by monitoring unique file operations and comparing them to normal patterns, generating alerts for abnormal activity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If signature-based ransomware detection is used, then detection simplicity is maintained, but detection effectiveness deteriorates because ransomware can avoid detection by using different signatures
Solution Approach 1:
The patent transitions from signature-based detection to behavior-based detection by changing the detection parameters from static file signatures to dynamic behavioral patterns. The system monitors file operations, access patterns, and system changes over time to detect ransomware, thereby maintaining detection simplicity while improving effectiveness against evolving threats
Solution Approach 2:
The patent introduces dynamic monitoring of file system audit events and system behavior changes to detect ransomware. Instead of relying on static signatures, the system continuously observes operational patterns, file access behaviors, and system state changes, enabling detection of previously unseen ransomware variants through their behavioral characteristics
2Reliability
If behavioral analysis-based approaches are used, then detection accuracy is improved, but computational resource consumption increases
Solution Approach 1:
The patent extracts and focuses on specific high-value behavioral indicators from the complex file system audit events, such as unusual file access patterns, rapid sequential deletions, and abnormal permission changes. By concentrating computational resources on these key indicators rather than analyzing all possible behavioral parameters, the system maintains high detection accuracy while reducing overall computational resource consumption
Solution Approach 2:
The patent implements partial monitoring by focusing on critical file system operations and high-risk behavioral patterns rather than comprehensively analyzing all file operations. The system applies enhanced analysis only to suspicious patterns detected through initial filtering, thereby achieving effective detection with reduced computational overhead
3Use of energy by moving object
If status-based detection systems are used, then system resource consumption is reduced, but real-time detection capability is lost because they look for system changes at specified time intervals
Solution Approach 1:
The patent implements continuous real-time monitoring of file system audit events through event-driven architecture. The system processes and analyzes file operations as they occur, maintaining continuous surveillance of system behavior without time intervals, thereby achieving both low resource consumption through efficient event processing and high detection speed through immediate analysis of suspicious patterns
Solution Approach 2:
The patent incorporates real-time feedback mechanisms where the detection system immediately responds to suspicious behavioral patterns by generating alerts and taking protective actions. The system continuously monitors audit events, analyzes behavioral changes, and provides instantaneous feedback about detected threats, enabling rapid response while maintaining efficient resource utilization through targeted analysis
4Device complexity
If status-based detection systems are used, then implementation complexity is reduced, but the ability to identify affected users or unauthorized actors is lost
Solution Approach 1:
The patent enhances the detection system with multi-functionality by integrating not only ransomware detection but also user identification, behavioral analysis, and forensic tracking capabilities. The same audit event processing infrastructure that detects ransomware also captures and analyzes user identity information, access patterns, and authorization anomalies, thereby maintaining system simplicity while gaining comprehensive identification capabilities
Data Source
AI summary
Some examples relate generally to managing and storing data, and more specifically to the real-time detection of ransomware, system (or insider) threats, or the misappropriation of credentials by using file system audit events.


