Storage Honeypot Files for Proactive Ransomware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing ransomware detection methods are passive and ineffective in protecting user data, as they detect attacks only after data is tampered or encrypted, failing to provide proactive defense mechanisms.
Innovation Solution
Implementing honeypot files in storage systems that mimic normal files based on file features, deceiving attackers and allowing proactive detection of ransomware attacks by analyzing operation behaviors on these decoy files.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If honeypot files are deployed in the storage system, then ransomware attack detection reliability is improved, but the complexity of the storage system increases
Solution Approach 1:
The patent introduces honeypot files as intermediary decoy objects that mediate between the storage system and potential ransomware attacks. These honeypot files serve as a buffer layer that allows detection of malicious operations without directly exposing real user data to ransomware encryption, thereby improving detection reliability while maintaining system functionality
Solution Approach 2:
The storage system is segmented into multiple components: real user files, honeypot decoy files, and detection mechanisms. This segmentation allows the system to monitor operations on honeypot files separately from real data, enabling reliable ransomware detection without compromising the integrity or accessibility of actual user data
2Measurement precision
If honeypot files are generated based on file features of normal files, then accuracy of ransomware detection is improved, but the time required for honeypot file generation increases
Solution Approach 1:
The system performs preliminary actions by pre-generating honeypot files with realistic file features (names, sizes, types, timestamps) before actual ransomware attacks occur. This advance preparation ensures that when attacks happen, the detection can immediately compare operational patterns against pre-established honeypot behavior profiles, improving accuracy without time pressure
Solution Approach 2:
The patent employs parameter changes by varying file features such as names, sizes, types, and timestamps when generating honeypot files. These parameter variations create diverse decoy files that can simulate different normal file scenarios, enhancing detection accuracy by covering multiple possible attack targets while managing generation time through selective parameter variation
3Reliability
If honeypot files are decoupled from normal files, then protection of normal files from ransomware is improved, but the difficulty of detecting and measuring attack behavior increases
Solution Approach 1:
Honeypot files serve as intermediary targets that decouple the detection mechanism from real user files. Attack behavior is detected by monitoring operations on honeypot files rather than directly on normal files, which protects normal files while still enabling effective attack detection through the honeypot mediation layer
Solution Approach 2:
The system employs distinctive markers or metadata (analogous to color changes) on honeypot files that allow easy identification and tracking of attack behaviors. These markers enable the detection mechanism to quickly identify which honeypot file is being targeted and what type of operation is being performed, reducing the difficulty of detecting and measuring attack behavior despite the decoupling from normal files
Data Source
AI summary
A ransomware attack detection method comprises a computer device that generates one or more honeypot files based on a file feature of a file in a storage system, deploys the one or more honeypot files in the storage system, and determines, based on operation behavior for the one or more honeypot files, whether the storage system is under a ransomware attack. The honeypot file proactively deceives an attacker to perform a ransomware attack, to detect the ransomware attack.


