Ransomware Detection from Client File-System Changes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data management systems fail to effectively detect and mitigate malicious software, such as ransomware, during data backup and restoration processes, leading to potential disruption and loss of critical data.
Innovation Solution
An information management system utilizing machine-learning algorithms and trained classifiers to monitor file system changes on client computing devices, track anomalies, and provide a graphical user interface for anomaly detection and restoration of data, including the ability to instantiate virtual machines for data recovery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional backup systems are used to store primary data, then data backup and restoration functionality is provided, but malicious software such as ransomware can infiltrate the backup system and propagate throughout the backup architecture, causing disruption and data loss
Solution Approach 1:
The system performs preliminary classification of backup data into trusted and untrusted categories before restoration operations. Data agents on client devices classify data as trusted or untrusted based on security policies and threat intelligence. This preliminary classification prevents malicious software from propagating during restoration by identifying and isolating untrusted data before it can infect the restored system.
Solution Approach 2:
The patent introduces a classification mechanism as an intermediary layer between the backup storage system and the restoration process. This intermediary classifies data into trusted and untrusted categories, allowing the system to selectively restore only trusted data or to alert users about untrusted data before restoration. This intermediary classification system acts as a security buffer that prevents direct propagation of malicious software.
2Productivity
If backup data is restored without classification, then restoration speed is maximized, but malicious software may be reintroduced to the system
Solution Approach 1:
The system performs data classification in advance during the backup process, categorizing data as trusted or untrusted. This preliminary classification is stored with the backup data metadata. During restoration, the pre-classified information is used to quickly determine which data should be restored, avoiding the need for real-time analysis that would slow down the restoration process while still maintaining security.
3Reliability
If all backup data is restored to ensure complete data recovery, then data recovery completeness is achieved, but any malicious software in the backup is also restored
Solution Approach 1:
The patent extracts and separates trusted data from untrusted data through classification. The system identifies untrusted data portions and excludes them from the restoration process or presents them separately for user review. This extraction approach allows complete recovery of trusted data while deliberately leaving out or isolating malicious components, achieving both recovery completeness and security.
Solution Approach 2:
The classification mechanism serves as an intermediary that mediates between the goal of complete data recovery and the need to prevent malicious software reintroduction. By classifying data into trusted and untrusted categories, the intermediary enables selective restoration that achieves completeness for legitimate data while blocking harmful data from being restored.
Data Source
AI summary
An information management system includes one or more client computing devices in communication with a storage manager and a secondary storage computing device. The storage manager manages the primary data of the one or more client computing devices and the secondary storage computing device manages secondary copies of the primary data of the one or more client computing devices. Each client computing device may be configured with a ransomware protection monitoring application that monitors for changes in their primary data. The ransomware protection monitoring application may input the changes detected in the primary data into a machine-learning classifier, where the classifier generates an output indicative of whether a client computing device has been affected by malware and/or ransomware. Using a virtual machine host, a virtual machine copy of an affected client computing device may be instantiated using a secondary copy of primary data of the affected client computing device.


