Storage Controller Snapshot Differential Ransomware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional techniques for detecting and combating ransomware attacks in information processing systems are inefficient, leading to delayed detection and increased file encryption, resulting in significant adverse impacts on victims.

Innovation Solution

Implementing a snapshot-based detection and remediation system that monitors differentials between snapshots of storage volumes to accurately and efficiently detect ransomware attacks, allowing for automated remediation through the selection of a suitable snapshot for data recovery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If conventional techniques are used to detect ransomware attacks, then the detection process is simple, but the detection time is unduly long and more files are encrypted

Engineering Contradiction:
Improvedetection timeVSAvoidfile encryption rate
Core Design Contradiction:
Loss of timeVSProductivity

Solution Approach 1:

The system performs preliminary actions by continuously creating snapshots of storage volumes and pre-calculating their hashes before any ransomware attack occurs. This allows the system to have baseline data ready for immediate comparison when changes are detected, eliminating the need for time-consuming analysis during an active attack.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces conventional file-by-file scanning mechanisms with a hash-based comparison system. Instead of mechanically examining individual files during an attack, the system substitutes this with a computational approach using pre-calculated hashes and differential analysis, dramatically speeding up detection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If frequent snapshots are taken to improve detection speed, then detection accuracy improves, but storage system complexity increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoidsnapshot management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts only the essential information needed for detection by calculating and storing only hash values of snapshot data, rather than maintaining complete copies of all snapshots. This differential approach takes out only the critical identification data, reducing storage overhead and management complexity while maintaining detection accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the parameter representation from storing complete snapshot data to storing hash values. This parameter transformation allows for efficient storage and comparison while maintaining the ability to accurately detect ransomware attacks through hash differential analysis.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive monitoring is implemented to reduce false positives, then detection reliability improves, but processing time increases

Engineering Contradiction:
Improvefalse positive rateVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic snapshot creation at predetermined intervals rather than continuous monitoring. This periodic action reduces processing time by batching operations while maintaining reliability through consistent baseline comparisons at regular intervals, preventing both false positives and detection delays.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11030314B2Storage system with snapshot-based detection and remediation of ransomware attacks
Publication Date: 2021.06.08 EMC IP HLDG CO LLC
  • US11030314B2 patent drawing
  • US11030314B2 patent drawing
  • US11030314B2 patent drawing

AI summary

A storage system in one embodiment comprises a plurality of storage devices and a storage controller. The storage controller is configured to generate a plurality of snapshots of a storage volume of the storage system at respective different points in time, to monitor a differential between a given one of the snapshots and the storage volume, and to generate an alert indicative of at least a potential ransomware attack on the storage system based at least in part on the monitored differential satisfying one or more specified conditions. The one or more specified conditions illustratively comprise a specified minimum amount of change in the storage volume relative to the given snapshot of the storage volume. Compressibility of the storage volume is also taken into account in generating the alert in some embodiments. The storage controller illustratively initiates restoration of the storage volume utilizing a selected snapshot responsive to confirmation of an actual attack.