Ransomware Detection via Data Block Change Rate Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting ransomware attacks are costly, time-consuming, and often only employed during infrequent backups, leading to potential exposure of backup data and delayed detection, which can result in significant damage before the attack is mitigated.

Innovation Solution

Implementing a system that enables changed block tracking, takes snapshots of data blocks at multiple times, and determines the rate of change and pattern of changes to detect anomalies exceeding thresholds, triggering scans for ransomware when unusual activity is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If traditional ransomware detection methods are used, then detection accuracy may be adequate, but detection time is delayed and damage occurs before mitigation

Engineering Contradiction:
Improvedetection timeVSAvoiddetection reliability
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system performs preliminary monitoring of data block changes and identifies suspicious patterns before ransomware completes its encryption process. By detecting anomalies in data modification patterns early in the attack lifecycle, the system enables mitigation before significant damage occurs, resolving the contradiction between early detection and reliable identification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the detection process into multiple stages: continuous monitoring of data block changes, analysis of change patterns, identification of suspicious behaviors, and final ransomware confirmation. This segmentation allows the system to reduce detection time through continuous monitoring while maintaining reliability through progressive verification at each stage.

Inventive Principle:
Principle #1Segmentation

2Loss of time

If continuous monitoring and scanning is performed, then early detection capability is improved, but system cost and complexity increase

Engineering Contradiction:
Improvedetection timeVSAvoidsystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system applies partial monitoring by focusing only on data blocks that exhibit suspicious change patterns rather than continuously scanning all data. By monitoring all data blocks for changes but only performing full analysis on those showing anomalous patterns, the system achieves early detection without the prohibitive cost and complexity of continuous comprehensive scanning.

Inventive Principle:
Principle #16Partial or excessive action

3Use of energy by moving object

If infrequent backups are used for detection, then system resource consumption is reduced, but detection is delayed and backup data becomes exposed

Engineering Contradiction:
Improveenergy consumptionVSAvoiddetection time
Core Design Contradiction:
Use of energy by moving objectVSLoss of time

Solution Approach 1:

The system maintains continuous monitoring of data block changes without requiring periodic backup operations. This continuous observation enables real-time detection of ransomware activity while consuming minimal resources, as the system only processes change metadata rather than copying entire datasets. The continuous action resolves the contradiction by enabling timely detection without the energy cost of frequent backups.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11949710B2System and method for efficient early indication of ransomware attack for damage prevention and control
Publication Date: 2024.04.02 DELL PROD LP
  • US11949710B2 patent drawing
  • US11949710B2 patent drawing
  • US11949710B2 patent drawing

AI summary

In general, one or more embodiments of the invention relates to systems and methods for detecting ransomware attacks earlier and closer to the time of attack. The ransomware attack can be detect by determining a change rate of data blocks between snapshots. The ransomware attack can also be detected by determining the pattern of changes in the blocks deviates from a normal pattern. By making these determinations, a quick identification of possible ransomware attacks can be made and other methods of mitigating the attack can be deployed when they are may still be useful to mitigate potential damage to a user's data.