Ransomware Mitigation via Electromechanical Disconnect Switches

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ransomware attacks can infect backup data stored on connected or cloud storage devices, making it difficult to recover files without the decryption key and complicating tracing and prosecution of perpetrators, as digital currencies like Bitcoin are used for ransoms.

Innovation Solution

A system and method that involves receiving data segments for backup, determining if subsequent data segments contain ransomware, and preventing overwrite of stored data segments if they do, using electromechanical disconnect switches to isolate storage devices and comparing backup data for integrity checks to detect malware, thereby protecting backups from corruption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If frequent backups are performed to mitigate ransomware risk, then data recovery capability is improved, but the risk of backup devices being infected by ransomware increases

Engineering Contradiction:
Improvedata recovery capabilityVSAvoidransomware infection risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by isolating the backup storage device from the network before the ransomware infection can occur. The electromechanical disconnect switch is activated to physically disconnect the backup device from the network prior to any potential infection, preventing the harmful factor from reaching the backup data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The backup storage device is extracted from the network by using an electromechanical disconnect switch to physically separate it. This removes the backup device from the network environment where ransomware exists, eliminating the transmission path for the harmful factor while preserving the backup function.

Inventive Principle:
Principle #2Taking out (Extraction)

2Loss of information

If backup data is continuously updated to maintain current data, then data freshness is improved, but the risk of overwriting clean backups with infected data increases

Engineering Contradiction:
Improvedata freshnessVSAvoidbackup integrity
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The system activates the electromechanical disconnect switch in advance to prevent infected data from overwriting clean backups. By disconnecting the backup device before the overwrite operation, the system preserves the integrity of existing backups while allowing new clean backups to be created in separate operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The electromechanical disconnect switch acts as an intermediary between the network and the backup storage device. It controls the connection state, allowing the system to maintain backup integrity by preventing direct access while still enabling controlled backup operations when needed.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If storage devices remain connected to the network for continuous backup operations, then backup efficiency is improved, but the vulnerability to ransomware attacks increases

Engineering Contradiction:
Improvebackup efficiencyVSAvoidnetwork vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary disconnection of the backup storage device from the network using the electromechanical disconnect switch before ransomware infection can occur. This preliminary action maintains backup efficiency by allowing continuous backup operations when disconnected, while eliminating network vulnerability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system segments the backup operation from the network by physically disconnecting the backup device. This segmentation allows the backup function to operate independently from the network environment, maintaining productivity while eliminating exposure to network-based threats.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20220350887A1Ransomware mitigation device and method
Publication Date: 2022.11.03 ARRIS ENTERPRISES LLC
  • US20220350887A1 patent drawing
  • US20220350887A1 patent drawing
  • US20220350887A1 patent drawing

AI summary

A system and method for backing up data is disclosed. In one embodiment, the method comprises receiving N data segments, the N of data segments together defining first backup data read from a processing device, receiving L data segments, the L data segments together defining second backup data read from the processing device temporally subsequent to the reading of the N data segments, determining if the L data segments comprise ransomware, preventing overwriting of the stored N data segments if the L data segments comprise ransomware, and storing the received L data segments if the L data segments do not comprise ransomware.