Ransomware Detection via File Statistics and Automatic Repair

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions fail to detect ransomware attacks in a timely manner, leading to file system encryption and requiring full system restore from backups, which is time-consuming and can result in data loss if no backup is available, forcing users to pay attackers for file recovery.

Innovation Solution

A ransomware detection and management system that includes a hierarchical storage management client to collect file statistics, identify affected files, lock down access, undo reconciliation processing, and automatically repair encrypted files by moving them to a quarantine folder and restoring previous versions from backups.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current ransomware detection solutions are used, then detection occurs after file system encryption, but this results in significant data loss and requires full system restore

Engineering Contradiction:
Improveransomware detection accuracyVSAvoidsystem downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by collecting file statistics and creating baselines before ransomware encryption occurs. The hierarchical storage client continuously monitors file access patterns, deduplication rates, and compression ratios, establishing normal behavior profiles that enable early detection of ransomware activity before significant damage occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously comparing current file statistics against established baselines. When anomalies are detected (such as sudden changes in deduplication rates or compression ratios), the system triggers alerts and can automatically lock down the file system, creating a closed-loop detection and response system that prevents further encryption.

Inventive Principle:
Principle #23Feedback

2Reliability

If full system restore from backup is performed, then affected files can be recovered, but this causes extensive operational disruption and data loss

Engineering Contradiction:
Improvefile recovery capabilityVSAvoidfile system availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system divides the file system into individual file units for targeted protection and recovery. Instead of restoring the entire file system, the system identifies and recovers only the specific files affected by ransomware, maintaining file-level granularity throughout the backup and restoration process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different recovery strategies to different files based on their infection status. Uninfected files continue to operate normally while infected files are isolated and restored from backup, allowing partial file system availability during recovery operations rather than complete system shutdown.

Inventive Principle:
Principle #3Local quality

3Reliability

If no backup is available, then file recovery is impossible, but this forces users to pay ransomware attackers

Engineering Contradiction:
Improvefile recovery capabilityVSAvoiddata loss
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The system performs preliminary backup actions before ransomware infection occurs. By continuously backing up files and maintaining version histories, the system ensures that clean copies of files are available before encryption happens, eliminating the need to pay ransoms for file recovery.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system prepares compensatory measures in advance by maintaining redundant file copies and version histories. When ransomware infection is detected, these pre-prepared backup copies serve as cushioning that protects against data loss and eliminates the need for ransom payment.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

4Speed

If file statistics collection and analysis is performed continuously, then near real-time ransomware detection is achieved, but this increases system overhead

Engineering Contradiction:
Improvedetection speedVSAvoidcomputational overhead
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system performs partial monitoring by focusing on specific file statistics that are most indicative of ransomware activity, such as deduplication rates and compression ratios, rather than analyzing all possible file attributes. This selective monitoring reduces computational overhead while maintaining detection effectiveness.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system uses periodic sampling of file statistics rather than continuous monitoring. By collecting and analyzing file metrics at regular intervals and comparing them against baselines, the system achieves near real-time detection capability while reducing the computational burden of constant analysis.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12153679B2Automatic ransomware detection with an on-demand file system lock down and automatic repair function
Publication Date: 2024.11.26 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12153679B2 patent drawing
  • US12153679B2 patent drawing
  • US12153679B2 patent drawing

AI summary

A method and system for detecting ransomware and repairing data following an attack. The method includes, collecting file statistics for files in a file system, identifying an affected file based on collected file statistics, locking down of access to the file system in response to identifying the affected file, undoing of reconcile processing, repairing the affected files, and unlocking access to the file system. The system includes a computer node, a file system, a plurality of disc storage components, a backup client, a backup client, and a hierarchical storage client. The hierarchical storage client is configured to collect file statistics for files in file system, identify affected files based on collected file statistics for the file, lock down of access to the file system in response to an identified affected file, undo reconcile processing, repair the affected file; and unlock access to the file system.