Secure Storage Device with Auxiliary Processor for Ransomware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer security systems are ineffective against sophisticated malware, particularly ransomware, which can evade detection by using encryption and polymorphism, and can interfere with data storage, leading to data theft and loss.
Innovation Solution
A secure storage device with a dedicated auxiliary processor that intercepts and analyzes data traffic between the host system and storage, using cryptographic keys to decrypt data packets and detect malicious software, while maintaining a file system semantic map to identify security threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If anti-malware software is used to detect and incapacitate malicious software, then malware detection capability is improved, but malware can employ obfuscation and polymorphism strategies to evade detection
Solution Approach 1:
The patent introduces an intermediary component - a security appliance positioned between the host system and storage device - that intercepts and analyzes storage traffic independently of the host's anti-malware software. This intermediary can detect malware using techniques such as analyzing storage access patterns, detecting encrypted data characteristics, and monitoring for ransomware behavior without being subject to the same evasion tactics that compromise host-based detection systems.
2Reliability
If encryption is used to protect data on storage devices, then data security is improved, but malware such as ransomware can encrypt files and demand payment for decryption
Solution Approach 1:
The security appliance performs preliminary analysis of storage traffic to detect ransomware encryption activities before they can complete their malicious purpose. By monitoring storage access patterns, detecting mass encryption operations, and identifying suspicious encryption algorithms, the system can intervene and block ransomware attacks before files are permanently encrypted and held hostage for ransom.
Solution Approach 2:
The system implements feedback mechanisms where the security appliance continuously monitors storage operations and provides real-time analysis of encryption activities. When ransomware behavior is detected through patterns such as rapid file encryption, unusual encryption algorithms, or mass file modification, the system can trigger alerts and take corrective actions to prevent data loss.
3Difficulty of detecting and measuring
If malware divides malicious activities among multiple agents, then detection difficulty increases, but this increases system complexity for legitimate security operations
Solution Approach 1:
The patent consolidates multiple security functions into a single integrated security appliance that combines traffic interception, analysis, decryption capabilities, and threat detection in one device. This merging of functions simplifies the overall system architecture compared to distributed approaches, while still being capable of detecting divided malware activities by analyzing the aggregate storage traffic patterns that result from multiple malicious agents operating simultaneously.
Data Source
Figure 1~2
Figure 3-A~3-B
Figure 4~5
AI summary
Described systems and methods allow protecting a host system against computer security threats, and in particular against ransomware and unauthorized access to private data. In some embodiments, a conventional non-volatile storage unit (e.g., magnetic, optical, or solid state drive) is paired with a dedicated security processor, forming a secure storage device which may connect to the primary processor of the host system via a conventional storage interface, such as a SATA, PCI, or USB connector. The primary processor and the security processor exchange messages and data via the storage interface. The security processor controls access of the primary processor to the storage unit, and may execute security and data encryption operations.