Storage-Side Feature Extraction for Faster Ransomware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current ransomware detection methods cause network congestion and slow down infection detection due to the need to read large amounts of data from storage devices, compromising data security and efficiency.

Innovation Solution

Implementing data feature extraction directly on the storage device to provide data features to detection devices, reducing the need for data transfer and offloading calculation and storage loads to the storage device's CPU and interface card, thereby improving detection speed and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If all detected data is read from the storage device to the detection device for virus detection, then the detection device can perform comprehensive analysis, but network congestion occurs and detection speed decreases

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts only the essential data features (metadata, headers, signatures) from the complete data for transmission to the detection device, rather than transferring all data. This extraction approach maintains detection accuracy while significantly reducing network bandwidth consumption and improving detection speed.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms the detection approach from analyzing complete data in one dimension to analyzing extracted features in another dimension. By converting data to its essential特征 representation, the system achieves efficient detection without sacrificing accuracy.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If all detected data is read from the storage device to the detection device, then complete data analysis is possible, but network bandwidth is consumed and congestion occurs

Engineering Contradiction:
Improvedetection reliabilityVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts only the essential data features (metadata, headers, signatures) from the complete data for transmission to the detection device, rather than transferring all data. This extraction approach maintains detection accuracy while significantly reducing network bandwidth consumption and improving detection speed.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If data is frequently exposed to external devices for detection, then detection can be performed, but data security is compromised

Engineering Contradiction:
Improvedetection capabilityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent extracts only the essential data features (metadata, headers, signatures) from the complete data for transmission to the detection device, rather than transferring all data. This extraction approach maintains detection accuracy while significantly reducing network bandwidth consumption and improving detection speed.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250371150A1Data Processing Method, Processor, Storage Device, Interface Card, and Storage Medium
Publication Date: 2025.12.04 HUAWEI TECH CO LTD
  • US20250371150A1 patent drawing
  • US20250371150A1 patent drawing
  • US20250371150A1 patent drawing

AI summary

A data processing method includes receiving an infection detection request sent by the detection device; obtaining, based on the infection detection request, a data feature obtained by performing feature extraction on target data; and outputting, to the detection device, the data feature for detecting whether the target data is infected by a virus.