SmartNIC Boot Snapshots for Ransomware Recovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing ransomware protection methods focus on data protection, but if the IHS boot path is compromised, they require time-consuming manual intervention to restore the system, making it difficult to recover from boot device encryption.
Innovation Solution
A ransomware protection SmartNIC creates secure snapshots of the boot device and configures an alternate boot device in the boot order, allowing automatic recovery to the secure alternate device in case of an attack, with periodic snapshot creation and real-time ransomware detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing ransomware protection methods focus on data protection, then data security is improved, but the system requires time-consuming manual intervention to restore the boot device after compromise
Solution Approach 1:
The system creates secure snapshots of the boot device periodically in advance, storing them on a separate storage device. When ransomware compromises the boot device, these pre-created snapshots are immediately available for restoration, eliminating the need for time-consuming manual intervention to recreate the boot device from scratch.
Solution Approach 2:
The system creates a copy (snapshot) of the boot device's contents and stores it on a separate storage device. This copy can be restored to the boot device quickly during recovery operations, replacing the need for manual reconstruction of the boot device and significantly reducing restoration time.
2Object-affected harmful factors
If the IHS boot path is compromised by ransomware, then the system can encrypt and protect data, but the system becomes unusable and requires manual restoration
Solution Approach 1:
The system performs preliminary actions by creating secure snapshots of the boot device before ransomware can compromise it. These snapshots are stored on a separate storage device and remain intact even if the primary boot device is encrypted, allowing the system to be restored to full functionality without manual intervention.
Solution Approach 2:
The system introduces an intermediary storage device that holds secure snapshots of the boot device. This intermediary storage acts as a safe haven for boot device contents, allowing restoration without direct interaction with the compromised boot device and maintaining system availability during recovery.
3Reliability
If manual intervention is required to restore the boot device, then data can be protected from ransomware, but productivity is reduced due to system downtime
Solution Approach 1:
The system enables self-service recovery by automatically restoring the boot device from pre-created secure snapshots stored on a separate storage device. This eliminates the need for manual intervention and allows the system to recover autonomously, minimizing downtime and maintaining productivity while still providing robust ransomware protection.
Solution Approach 2:
The system creates secure snapshots in advance and stores them on separate storage devices, so that when ransomware attacks occur, the restoration process can begin immediately without manual intervention. This preliminary preparation ensures rapid recovery and minimizes productivity loss while maintaining reliable ransomware protection.
Data Source
AI summary
A ransomware protection smart network interface controller (SmartNIC) is configured to create a secure snapshot of a boot device of an information handling system (IHS), create a secure alternate boot device on each boot of the IHS, and export the boot device and the secure alternate boot device to the IHS. The IHS is configured to set a boot order of the IHS, with the secure alternate boot device immediately after the boot device in the boot order. The ransomware protection SmartNIC may also be configured to create a read and writeable snapshot from the secure snapshot of the IHS boot device, and may delete, on each subsequent boot of the IHS, the read and writeable snapshot for the prior boot, and create a new read and writeable snapshot from a secure snapshot of the IHS boot device from the subsequent boot of the IHS.


