Storage Controller Snapshot Differential Ransomware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques for detecting and combating ransomware attacks in information processing systems are inefficient, leading to delayed detection and increased file encryption, resulting in significant adverse impacts on victims.
Innovation Solution
Implementing a snapshot-based detection and remediation system that monitors differentials between snapshots of storage volumes to accurately and efficiently detect ransomware attacks, allowing for automated remediation through the selection of a suitable snapshot for data recovery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If conventional techniques are used to detect ransomware attacks, then the detection process is simple, but the detection time is unduly long and more files are encrypted
Solution Approach 1:
The system performs preliminary actions by continuously creating snapshots of storage volumes and pre-calculating their hashes before any ransomware attack occurs. This allows the system to have baseline data ready for immediate comparison when changes are detected, eliminating the need for time-consuming analysis during an active attack.
Solution Approach 2:
The patent replaces conventional file-by-file scanning mechanisms with a hash-based comparison system. Instead of mechanically examining individual files during an attack, the system substitutes this with a computational approach using pre-calculated hashes and differential analysis, dramatically speeding up detection.
2Measurement precision
If frequent snapshots are taken to improve detection speed, then detection accuracy improves, but storage system complexity increases
Solution Approach 1:
The system extracts only the essential information needed for detection by calculating and storing only hash values of snapshot data, rather than maintaining complete copies of all snapshots. This differential approach takes out only the critical identification data, reducing storage overhead and management complexity while maintaining detection accuracy.
Solution Approach 2:
The patent changes the parameter representation from storing complete snapshot data to storing hash values. This parameter transformation allows for efficient storage and comparison while maintaining the ability to accurately detect ransomware attacks through hash differential analysis.
3Reliability
If comprehensive monitoring is implemented to reduce false positives, then detection reliability improves, but processing time increases
Solution Approach 1:
The system implements periodic snapshot creation at predetermined intervals rather than continuous monitoring. This periodic action reduces processing time by batching operations while maintaining reliability through consistent baseline comparisons at regular intervals, preventing both false positives and detection delays.
Data Source
AI summary
A storage system in one embodiment comprises a plurality of storage devices and a storage controller. The storage controller is configured to generate a plurality of snapshots of a storage volume of the storage system at respective different points in time, to monitor a differential between a given one of the snapshots and the storage volume, and to generate an alert indicative of at least a potential ransomware attack on the storage system based at least in part on the monitored differential satisfying one or more specified conditions. The one or more specified conditions illustratively comprise a specified minimum amount of change in the storage volume relative to the given snapshot of the storage volume. Compressibility of the storage volume is also taken into account in generating the alert in some embodiments. The storage controller illustratively initiates restoration of the storage volume utilizing a selected snapshot responsive to confirmation of an actual attack.


