SSD Ransomware Detection via NVMe Log Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current protection methods against ransomware attacks, which lock or encrypt data on storage devices, are inadequate, as they rely mainly on software-based solutions that are insufficient and require significant computational resources, and do not effectively detect malicious activities at the storage device level.
Innovation Solution
A storage system with a built-in protection module that uses machine-learning algorithms to analyze storage commands and detect ransomware operations, providing notifications to the host device or user, thereby reducing the workload on the central processing unit and enhancing detection capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software-based protection methods (antivirus, firewall) are used to detect ransomware, then detection capability is provided, but computational resources and processing time are significantly consumed
Solution Approach 1:
The patent segments the ransomware detection function into two parts: (1) the storage device performs initial filtering and analysis of storage commands using its own processor, and (2) only suspicious commands are forwarded to the host system for further analysis. This segmentation reduces the computational burden on the host system while maintaining detection capability.
Solution Approach 2:
The storage device performs preliminary analysis of storage commands before they reach the host system. By pre-filtering and pre-analyzing commands at the storage device level, the system reduces the amount of data that needs to be processed by the host, thereby reducing overall computational resource consumption.
2Reliability
If software-based protection methods are used, then ransomware detection is provided, but the protection is insufficient and cannot effectively detect malicious activities at the storage device level
Solution Approach 1:
The patent merges the ransomware detection functionality directly into the storage device by integrating a machine learning model and analysis engine within the storage device's processor. This combination enables the storage device to autonomously detect ransomware activities without requiring complex external software layers, thereby improving detection effectiveness while avoiding excessive system complexity.
Solution Approach 2:
The storage device acts as an intermediary between the host system and the storage medium, performing local analysis of storage commands. This intermediary role allows the system to detect malicious activities at the storage device level without requiring complex host-based software, simplifying the overall protection architecture while improving detection capability.
3Reliability
If traditional antivirus software is used for protection, then some level of security is provided, but it requires significant storage and computing capacity
Solution Approach 1:
The storage device performs self-service by autonomously analyzing its own storage commands using integrated machine learning models. This self-service capability eliminates the need for extensive external software and computing resources, reducing storage and computing capacity requirements while maintaining security protection levels.
Data Source
AI summary
A storage system, including a host device; and a storage device including a memory and at least one processor configured to implement a storage internal protection (SIP) module, wherein the SIP module is configured to: obtain, from the host device, a plurality of storage commands corresponding to the memory, filter the plurality of storage commands to obtain a filtered plurality of storage commands, apply information about the filtered plurality of storage commands to a machine-learning ransomware detection algorithm, and based on the machine-learning ransomware detection algorithm indicating that a ransomware operation is detected, provide a notification to the host device.


