Slack-Space File System for Data Exfiltration Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems inadequately prevent data exfiltration and are ineffective against destructive wiper malware and crypto-ransomware, which can compromise or destroy data stored in a system.

Innovation Solution

Implementing a slack-space storage system by modifying packing algorithms to create additional slack space and using alternate data streams to store sensitive information, making the slack-space file system persistent and evading detection, while storing secure data in alternate data streams to prevent exfiltration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is stored in conventional file systems, then data is easily accessible and manageable, but data is vulnerable to exfiltration and destruction by malware

Engineering Contradiction:
Improvedata protectionVSAvoidstorage system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a slack-space file system that is nested within the conventional file system's unused slack space. The hidden file system is embedded in the gaps between allocated file clusters, creating a nested structure where the protective layer is contained within the existing system without requiring separate physical storage infrastructure.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent transitions from storing data only in allocated file spaces to utilizing the third dimension of slack space (unused space within allocated clusters). By exploiting this previously wasted dimensional space, the system creates a hidden storage layer that is invisible to conventional file system operations and malware.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Quantity of substance

If packing algorithms are optimized for storage efficiency, then storage space is maximized, but slack space is reduced and cannot be used for hidden storage

Engineering Contradiction:
Improvestorage capacityVSAvoiddata protection capability
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent segments the storage space into two distinct layers: the conventional allocated file space for normal operations and the slack space layer for hidden protective storage. This segmentation allows the system to maintain efficient packing in the visible layer while simultaneously utilizing the previously wasted slack space for security purposes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent modifies the packing algorithm parameters to intentionally leave controlled amounts of slack space rather than completely filling allocated clusters. By changing the packing density parameter, the system creates sufficient unused space to accommodate the hidden file system while maintaining overall storage efficiency.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If a hidden file system is implemented in slack space, then data protection is improved, but detection by security systems and users becomes more difficult

Engineering Contradiction:
Improvedata protectionVSAvoiddetectability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent extracts the file system metadata and allocation tables from the conventional file system structure and places them exclusively in the slack space layer. By removing the visible indicators of file system presence from the main system, the hidden file system becomes undetectable through conventional means while remaining fully functional.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a mediator layer that intercepts file system calls and redirects operations to the appropriate storage layer. This intermediary mechanism allows the hidden file system to operate transparently without exposing its presence to users or security software, while still providing data protection functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If sensitive data is stored in alternate data streams, then exfiltration is prevented, but data accessibility and standard file operations are reduced

Engineering Contradiction:
Improveexfiltration preventionVSAvoiddata accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs preliminary actions by automatically detecting sensitive data and migrating it to the slack-space hidden file system before any exfiltration attempt can occur. This proactive approach ensures that sensitive data is protected in advance while maintaining normal file operations for non-sensitive data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service functionality where the hidden file system automatically manages its own contents by monitoring file system operations and automatically moving sensitive files to protected storage. This self-managing approach maintains data accessibility while providing automatic exfiltration prevention without requiring external intervention.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11580248B2Data loss prevention
Publication Date: 2023.02.14 NOBLIS INC
  • US11580248B2 patent drawing
  • US11580248B2 patent drawing
  • US11580248B2 patent drawing

AI summary

Techniques for providing data loss prevention, including data exfiltration prevention and crypto-ransomware prevention, are provided. In some embodiments, a slack-space file system is created by using a modified packing algorithm to increase and/or optimize an amount of slack space created by files stored in a standard file system. A program for accessing and indexing the slack-space file system may be stored, and requests by a user to store data on a storage medium of a computer system may cause the information to be stored in the slack-space file system, where it may be protected from destructive malware that operates solely on the standard file system. In some embodiments, sensitive information may be hidden by storing the information in an alternate data stream of a file and by replacing the information in the unnamed data stream of the file with non-sensitive information that may appear to be sensitive.