NAS Ransomware Detection via File System Audit Events

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for detecting ransomware and unauthorized access in file systems are ineffective, as signature-based detection can be evaded, behavioral analysis is resource-intensive, and status-based detection systems do not provide real-time notification or identify affected users or unauthorized actors.

Innovation Solution

A Network Attached Storage (NAS) system that captures, de-duplicates, and analyzes file system audit events to identify anomalous activity, such as ransomware infections, insider threats, and credential misappropriation by monitoring unique file operations and comparing them to normal patterns, generating alerts for abnormal activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If signature-based ransomware detection is used, then detection simplicity is maintained, but detection effectiveness deteriorates because ransomware can avoid detection by using different signatures

Engineering Contradiction:
Improvedetection simplicityVSAvoiddetection effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transitions from signature-based detection to behavior-based detection by changing the detection parameters from static file signatures to dynamic behavioral patterns. The system monitors file operations, access patterns, and system changes over time to detect ransomware, thereby maintaining detection simplicity while improving effectiveness against evolving threats

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces dynamic monitoring of file system audit events and system behavior changes to detect ransomware. Instead of relying on static signatures, the system continuously observes operational patterns, file access behaviors, and system state changes, enabling detection of previously unseen ransomware variants through their behavioral characteristics

Inventive Principle:
Principle #15Dynamics

2Reliability

If behavioral analysis-based approaches are used, then detection accuracy is improved, but computational resource consumption increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts and focuses on specific high-value behavioral indicators from the complex file system audit events, such as unusual file access patterns, rapid sequential deletions, and abnormal permission changes. By concentrating computational resources on these key indicators rather than analyzing all possible behavioral parameters, the system maintains high detection accuracy while reducing overall computational resource consumption

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements partial monitoring by focusing on critical file system operations and high-risk behavioral patterns rather than comprehensively analyzing all file operations. The system applies enhanced analysis only to suspicious patterns detected through initial filtering, thereby achieving effective detection with reduced computational overhead

Inventive Principle:
Principle #16Partial or excessive action

3Use of energy by moving object

If status-based detection systems are used, then system resource consumption is reduced, but real-time detection capability is lost because they look for system changes at specified time intervals

Engineering Contradiction:
Improvesystem resource consumptionVSAvoiddetection speed
Core Design Contradiction:
Use of energy by moving objectVSSpeed

Solution Approach 1:

The patent implements continuous real-time monitoring of file system audit events through event-driven architecture. The system processes and analyzes file operations as they occur, maintaining continuous surveillance of system behavior without time intervals, thereby achieving both low resource consumption through efficient event processing and high detection speed through immediate analysis of suspicious patterns

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent incorporates real-time feedback mechanisms where the detection system immediately responds to suspicious behavioral patterns by generating alerts and taking protective actions. The system continuously monitors audit events, analyzes behavioral changes, and provides instantaneous feedback about detected threats, enabling rapid response while maintaining efficient resource utilization through targeted analysis

Inventive Principle:
Principle #23Feedback

4Device complexity

If status-based detection systems are used, then implementation complexity is reduced, but the ability to identify affected users or unauthorized actors is lost

Engineering Contradiction:
Improvesystem complexityVSAvoididentification capability
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent enhances the detection system with multi-functionality by integrating not only ransomware detection but also user identification, behavioral analysis, and forensic tracking capabilities. The same audit event processing infrastructure that detects ransomware also captures and analyzes user identity information, access patterns, and authorization anomalies, thereby maintaining system simplicity while gaining comprehensive identification capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11709932B2Realtime detection of ransomware
Publication Date: 2023.07.25 RUBRIK INC
  • US11709932B2 patent drawing
  • US11709932B2 patent drawing
  • US11709932B2 patent drawing

AI summary

Some examples relate generally to managing and storing data, and more specifically to the real-time detection of ransomware, system (or insider) threats, or the misappropriation of credentials by using file system audit events.