Storage Honeypot Files for Proactive Ransomware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing ransomware detection methods are passive and ineffective in protecting user data, as they detect attacks only after data is tampered or encrypted, failing to provide proactive defense mechanisms.

Innovation Solution

Implementing honeypot files in storage systems that mimic normal files based on file features, deceiving attackers and allowing proactive detection of ransomware attacks by analyzing operation behaviors on these decoy files.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If honeypot files are deployed in the storage system, then ransomware attack detection reliability is improved, but the complexity of the storage system increases

Engineering Contradiction:
Improveransomware attack detection reliabilityVSAvoidstorage system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces honeypot files as intermediary decoy objects that mediate between the storage system and potential ransomware attacks. These honeypot files serve as a buffer layer that allows detection of malicious operations without directly exposing real user data to ransomware encryption, thereby improving detection reliability while maintaining system functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The storage system is segmented into multiple components: real user files, honeypot decoy files, and detection mechanisms. This segmentation allows the system to monitor operations on honeypot files separately from real data, enabling reliable ransomware detection without compromising the integrity or accessibility of actual user data

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If honeypot files are generated based on file features of normal files, then accuracy of ransomware detection is improved, but the time required for honeypot file generation increases

Engineering Contradiction:
Improveransomware detection accuracyVSAvoidhoneypot file generation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-generating honeypot files with realistic file features (names, sizes, types, timestamps) before actual ransomware attacks occur. This advance preparation ensures that when attacks happen, the detection can immediately compare operational patterns against pre-established honeypot behavior profiles, improving accuracy without time pressure

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs parameter changes by varying file features such as names, sizes, types, and timestamps when generating honeypot files. These parameter variations create diverse decoy files that can simulate different normal file scenarios, enhancing detection accuracy by covering multiple possible attack targets while managing generation time through selective parameter variation

Inventive Principle:
Principle #35Parameter changes

3Reliability

If honeypot files are decoupled from normal files, then protection of normal files from ransomware is improved, but the difficulty of detecting and measuring attack behavior increases

Engineering Contradiction:
Improvenormal file protectionVSAvoidattack behavior detection difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

Honeypot files serve as intermediary targets that decouple the detection mechanism from real user files. Attack behavior is detected by monitoring operations on honeypot files rather than directly on normal files, which protects normal files while still enabling effective attack detection through the honeypot mediation layer

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system employs distinctive markers or metadata (analogous to color changes) on honeypot files that allow easy identification and tracking of attack behaviors. These markers enable the detection mechanism to quickly identify which honeypot file is being targeted and what type of operation is being performed, reducing the difficulty of detecting and measuring attack behavior despite the decoupling from normal files

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS20260044600A1Ransomware Attack Detection Method and Apparatus, and Storage System
Publication Date: 2026.02.12 HUAWEI TECH CO LTD
  • US20260044600A1 patent drawing
  • US20260044600A1 patent drawing
  • US20260044600A1 patent drawing

AI summary

A ransomware attack detection method comprises a computer device that generates one or more honeypot files based on a file feature of a file in a storage system, deploys the one or more honeypot files in the storage system, and determines, based on operation behavior for the one or more honeypot files, whether the storage system is under a ransomware attack. The honeypot file proactively deceives an attacker to perform a ransomware attack, to detect the ransomware attack.