SSD Ransomware Detection via NVMe Log Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current protection methods against ransomware attacks, which lock or encrypt data on storage devices, are inadequate, as they rely mainly on software-based solutions that are insufficient and require significant computational resources, and do not effectively detect malicious activities at the storage device level.

Innovation Solution

A storage system with a built-in protection module that uses machine-learning algorithms to analyze storage commands and detect ransomware operations, providing notifications to the host device or user, thereby reducing the workload on the central processing unit and enhancing detection capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software-based protection methods (antivirus, firewall) are used to detect ransomware, then detection capability is provided, but computational resources and processing time are significantly consumed

Engineering Contradiction:
Improveransomware detection capabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the ransomware detection function into two parts: (1) the storage device performs initial filtering and analysis of storage commands using its own processor, and (2) only suspicious commands are forwarded to the host system for further analysis. This segmentation reduces the computational burden on the host system while maintaining detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The storage device performs preliminary analysis of storage commands before they reach the host system. By pre-filtering and pre-analyzing commands at the storage device level, the system reduces the amount of data that needs to be processed by the host, thereby reducing overall computational resource consumption.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If software-based protection methods are used, then ransomware detection is provided, but the protection is insufficient and cannot effectively detect malicious activities at the storage device level

Engineering Contradiction:
Improveransomware detection effectivenessVSAvoidprotection system architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the ransomware detection functionality directly into the storage device by integrating a machine learning model and analysis engine within the storage device's processor. This combination enables the storage device to autonomously detect ransomware activities without requiring complex external software layers, thereby improving detection effectiveness while avoiding excessive system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The storage device acts as an intermediary between the host system and the storage medium, performing local analysis of storage commands. This intermediary role allows the system to detect malicious activities at the storage device level without requiring complex host-based software, simplifying the overall protection architecture while improving detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If traditional antivirus software is used for protection, then some level of security is provided, but it requires significant storage and computing capacity

Engineering Contradiction:
Improvesecurity protection levelVSAvoidstorage capacity requirement
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The storage device performs self-service by autonomously analyzing its own storage commands using integrated machine learning models. This self-service capability eliminates the need for extensive external software and computing resources, reducing storage and computing capacity requirements while maintaining security protection levels.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240037233A1Ransomware and malicious software protection in SSD/UFS by nvme instructions log analysis based on machine-learning
Publication Date: 2024.02.01 SAMSUNG ELECTRONICS CO LTD
  • US20240037233A1 patent drawing
  • US20240037233A1 patent drawing
  • US20240037233A1 patent drawing

AI summary

A storage system, including a host device; and a storage device including a memory and at least one processor configured to implement a storage internal protection (SIP) module, wherein the SIP module is configured to: obtain, from the host device, a plurality of storage commands corresponding to the memory, filter the plurality of storage commands to obtain a filtered plurality of storage commands, apply information about the filtered plurality of storage commands to a machine-learning ransomware detection algorithm, and based on the machine-learning ransomware detection algorithm indicating that a ransomware operation is detected, provide a notification to the host device.