Ransomware Detection via File Statistics and Automatic Repair
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions fail to detect ransomware attacks in a timely manner, leading to file system encryption and requiring full system restore from backups, which is time-consuming and can result in data loss if no backup is available, forcing users to pay attackers for file recovery.
Innovation Solution
A ransomware detection and management system that includes a hierarchical storage management client to collect file statistics, identify affected files, lock down access, undo reconciliation processing, and automatically repair encrypted files by moving them to a quarantine folder and restoring previous versions from backups.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current ransomware detection solutions are used, then detection occurs after file system encryption, but this results in significant data loss and requires full system restore
Solution Approach 1:
The system performs preliminary actions by collecting file statistics and creating baselines before ransomware encryption occurs. The hierarchical storage client continuously monitors file access patterns, deduplication rates, and compression ratios, establishing normal behavior profiles that enable early detection of ransomware activity before significant damage occurs.
Solution Approach 2:
The system implements feedback mechanisms by continuously comparing current file statistics against established baselines. When anomalies are detected (such as sudden changes in deduplication rates or compression ratios), the system triggers alerts and can automatically lock down the file system, creating a closed-loop detection and response system that prevents further encryption.
2Reliability
If full system restore from backup is performed, then affected files can be recovered, but this causes extensive operational disruption and data loss
Solution Approach 1:
The system divides the file system into individual file units for targeted protection and recovery. Instead of restoring the entire file system, the system identifies and recovers only the specific files affected by ransomware, maintaining file-level granularity throughout the backup and restoration process.
Solution Approach 2:
The system applies different recovery strategies to different files based on their infection status. Uninfected files continue to operate normally while infected files are isolated and restored from backup, allowing partial file system availability during recovery operations rather than complete system shutdown.
3Reliability
If no backup is available, then file recovery is impossible, but this forces users to pay ransomware attackers
Solution Approach 1:
The system performs preliminary backup actions before ransomware infection occurs. By continuously backing up files and maintaining version histories, the system ensures that clean copies of files are available before encryption happens, eliminating the need to pay ransoms for file recovery.
Solution Approach 2:
The system prepares compensatory measures in advance by maintaining redundant file copies and version histories. When ransomware infection is detected, these pre-prepared backup copies serve as cushioning that protects against data loss and eliminates the need for ransom payment.
4Speed
If file statistics collection and analysis is performed continuously, then near real-time ransomware detection is achieved, but this increases system overhead
Solution Approach 1:
The system performs partial monitoring by focusing on specific file statistics that are most indicative of ransomware activity, such as deduplication rates and compression ratios, rather than analyzing all possible file attributes. This selective monitoring reduces computational overhead while maintaining detection effectiveness.
Solution Approach 2:
The system uses periodic sampling of file statistics rather than continuous monitoring. By collecting and analyzing file metrics at regular intervals and comparing them against baselines, the system achieves near real-time detection capability while reducing the computational burden of constant analysis.
Data Source
AI summary
A method and system for detecting ransomware and repairing data following an attack. The method includes, collecting file statistics for files in a file system, identifying an affected file based on collected file statistics, locking down of access to the file system in response to identifying the affected file, undoing of reconcile processing, repairing the affected files, and unlocking access to the file system. The system includes a computer node, a file system, a plurality of disc storage components, a backup client, a backup client, and a hierarchical storage client. The hierarchical storage client is configured to collect file statistics for files in file system, identify affected files based on collected file statistics for the file, lock down of access to the file system in response to an identified affected file, undo reconcile processing, repair the affected file; and unlock access to the file system.


