Storage Access Monitoring Using Behavioral Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting and preventing ransomware attacks are ineffective against unknown patterns, require endpoint software updates, and fail to prevent data encryption and exfiltration, especially when endpoint security measures are insufficient.
Innovation Solution
A storage access monitoring method that analyzes operation information from storage devices to detect ransomware by comparing current and past behavior patterns, ratios, and statistical trends, providing early detection and prevention of data encryption and exfiltration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If virus checking software is used to detect ransomware, then known ransomware patterns can be detected, but unknown ransomware patterns cannot be detected
Solution Approach 1:
The patent changes the detection parameters from static virus patterns to dynamic behavioral metrics. It monitors file access frequency, encryption rates, and operational patterns over time, transforming the detection approach from pattern-matching to statistical anomaly detection. This allows the system to adapt to unknown ransomware by detecting abnormal behavior rather than requiring pre-defined patterns.
Solution Approach 2:
The patent replaces the mechanical virus scanning system with a statistical analysis system. Instead of mechanically comparing files against known virus signatures, it uses statistical models to analyze file access patterns, encryption rates, and operational behaviors. This substitution enables detection of novel ransomware through behavioral anomalies rather than pattern matching.
2Reliability
If virus checking software is installed on all endpoints, then detection coverage is improved, but system complexity and maintenance burden increase
Solution Approach 1:
The patent introduces a storage device as an intermediary that performs centralized monitoring. Instead of requiring virus checking software on each endpoint, the storage device intercepts and analyzes file access patterns, encryption operations, and behavioral metrics from multiple hosts. This intermediary approach simplifies deployment while maintaining comprehensive detection coverage.
Solution Approach 2:
The patent merges the detection functionality from multiple distributed endpoints into a single centralized storage device. By consolidating the monitoring function, it eliminates the need to deploy and maintain software on each individual endpoint, reducing system complexity while achieving the same or better detection coverage through aggregated behavioral analysis.
3Reliability
If backup data is stored in a Vault area, then data protection from ransomware is improved, but identification of pre-infection backup data becomes time-consuming
Solution Approach 1:
The patent performs preliminary monitoring and detection of ransomware infection before it completes its encryption process. By detecting abnormal file access patterns and encryption behaviors early, the system can alert users to restore data from backups taken before infection occurred, rather than requiring time-consuming analysis of multiple backup versions after the fact.
Solution Approach 2:
The patent implements continuous feedback monitoring of file access patterns and encryption rates. This real-time feedback mechanism allows the system to detect ransomware activity as it occurs and alert users immediately, enabling them to take corrective action and restore from appropriate backups before significant damage spreads, thereby reducing recovery time.
4Reliability
If file access log monitoring is performed, then ransomware detection capability is improved, but detection fails if log generation is compromised
Solution Approach 1:
The patent uses the storage device as an intermediary that independently monitors and analyzes file access patterns. Rather than relying on log files generated by endpoint systems (which could be falsified), the storage device directly observes and records actual file access behaviors, encryption operations, and operational patterns, creating a tamper-resistant detection mechanism.
Solution Approach 2:
The patent replaces the log-file-based detection mechanism with direct behavioral monitoring. Instead of analyzing potentially falsified log entries, the system directly monitors file access patterns, encryption rates, and operational behaviors at the storage level, substituting mechanical log analysis with real-time statistical monitoring that cannot be easily compromised.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Even if ransomware countermeasures are not sufficiently implemented on an endpoint, it is possible to detect ransomware infections of endpoints at an early stage and prevent data encryption and data exfiltration. A storage access monitoring method according to the present invention acquires the operation status of a volume 40 constituting a storage device 30 from which an endpoint (host 10) can read/write data through a network 50 as operation information, and determines whether or not a behavior related to the latest operation information is abnormal by performing any one or more of a comparative analysis step, a pattern comparison step, or a trend comparison step. The comparative analysis step includes comparing the latest operation information with past operation information. The pattern comparison step includes determining whether or not there is a behavioral pattern that indicates a possibility of an effect of the ransomware in the latest operation information. The trend comparison step includes determining whether or not an operation related to the latest operation information is different from a normal operation related to the past operation information.