Storage Array Encryption Attack Detection Through Bit Density

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Storage arrays are vulnerable to cyber-attacks, particularly encryption-related attacks that encrypt and overwrite data, which current host-based detection methods fail to detect in real-time.

Innovation Solution

Intercept IO write requests, analyze bit density and entropy scores, and implement machine learning to identify and mitigate cyber-attacks by comparing access rates and bit densities against predefined thresholds.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If host-based detection methods are used to monitor storage array access, then detection capability is provided, but real-time detection of encryption attacks is not achieved

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by establishing baseline access patterns and bit density thresholds before attacks occur. The system pre-configures entropy thresholds and access rate limits that trigger automated responses, enabling detection and mitigation before encryption attacks complete their malicious cycles

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops that monitor storage access patterns, bit densities, and entropy scores in real-time. When anomalies are detected, the system immediately feeds this information back to adjust monitoring parameters and trigger mitigation responses, creating a closed-loop detection system that operates without delay

Inventive Principle:
Principle #23Feedback

2Quantity of substance

If storage arrays store vast amounts of data without monitoring, then storage capacity is maximized, but vulnerability to cyber-attacks increases

Engineering Contradiction:
Improvestorage capacityVSAvoidcyber-attack vulnerability
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary detection layer that sits between the storage array and access requests. This intermediary monitors bit densities, entropy scores, and access patterns without interfering with normal storage operations, detecting malicious patterns while allowing legitimate data storage and access to continue uninterrupted

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service by automatically detecting anomalies and triggering mitigation responses without external intervention. When the monitoring system detects encryption attack patterns, it autonomously initiates response protocols including alerting security systems and potentially blocking suspicious access operations

Inventive Principle:
Principle #25Self-service

3Reliability

If IO write requests are intercepted and analyzed, then attack detection capability is improved, but processing overhead increases

Engineering Contradiction:
Improveattack detectionVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by focusing analysis only on specific characteristics of IO requests that indicate potential attacks. Instead of analyzing entire data sets, the system concentrates computational resources on calculating entropy scores and bit density metrics for suspicious access patterns, reducing overall processing overhead while maintaining detection effectiveness

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts monitoring parameters based on observed access patterns and threat levels. When normal operation is detected, monitoring intensity is reduced; when anomalies are detected, the system increases analysis depth and frequency, optimizing processing overhead relative to actual detection needs

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12432227B2Encryption detection
Publication Date: 2025.09.30 DELL PROD LP
  • US12432227B2 patent drawing
  • US12432227B2 patent drawing
  • US12432227B2 patent drawing

AI summary

One or more aspects of the present disclosure relate to protecting the integrity of datasets stored by a storage array. In embodiments, one or more IO write requests from an input/output (IO) workload are intercepted. Additionally, a likely cyber-attack event is identified based on a bit density of write data corresponding to the one or more IO requests. Further, the cyber-attack event is mitigated.