Ransomware Detection via File Catalog Behavioral Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting ransomware attacks in data centers are inefficient, leading to delayed detection and increased spread of the threat across systems, as they rely on manual checks and lack automated mechanisms to identify sudden changes in data file behavior.

Innovation Solution

A data processing arrangement coupled to a data memory arrangement generates a file catalog with periodically updated information, using behavioral profiling and machine-learning algorithms to detect deviations from expected patterns, providing early warnings and reducing the need for manual checks across multiple systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual checks are used to detect ransomware contamination, then detection can be performed on individual systems, but the detection time is delayed and the threat spreads across more systems

Engineering Contradiction:
Improveransomware detection capabilityVSAvoiddetection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system creates a baseline behavioral profile of data files before ransomware infection by periodically cataloging file characteristics and establishing normal access patterns. This preliminary characterization enables rapid anomaly detection when ransomware strikes, eliminating the need for manual post-infection investigation and reducing detection time from days to minutes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors data file access patterns and compares them against established behavioral profiles, providing real-time feedback when deviations indicate ransomware activity. This automated feedback loop enables immediate detection and response, preventing the threat from spreading across multiple systems while reducing the time loss associated with manual detection methods.

Inventive Principle:
Principle #23Feedback

2Loss of time

If automated behavioral profiling is implemented to detect ransomware, then detection time is reduced, but the device complexity increases

Engineering Contradiction:
Improvedetection timeVSAvoidsystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

Instead of implementing complex real-time analysis algorithms, the system creates simplified copies of file behavior characteristics by periodically cataloging metadata and access patterns. These behavioral profiles serve as reference copies that enable rapid comparison and anomaly detection without requiring complex computational resources, thus reducing detection time while managing system complexity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system transforms the complex problem of ransomware detection into simpler parameter comparisons by monitoring specific file characteristics such as access frequency, file size changes, and modification patterns. By changing the detection approach from complex behavioral analysis to parameter-based comparison against established profiles, the system reduces detection time while keeping the implementation complexity manageable.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240028725A1Data Processing Arrangement and Method for Detecting Ransomware in a File Catalog
Publication Date: 2024.01.25 HUAWEI TECH CO LTD
  • US20240028725A1 patent drawing
  • US20240028725A1 patent drawing
  • US20240028725A1 patent drawing

AI summary

Provided is a data processing arrangement (100, 200, 300, 400) that is coupled to a data memory arrangement (102) and is configured to generate a file catalog including information describing characteristics of data files stored within the data memory arrangement. The file catalog is periodically updated so that it provides a temporal record of the information. The data processing arrangement is configured to determine a behavioral profile (404) indicative of temporal trends or patterns in the information, and to provide a warning indication in an event that the information for a given data file temporally changes in a manner that deviates more than a threshold amount from a model of expected temporal trends or patterns of the given data file.