Successive Backup Analysis Using Entropy to Detect Malware Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods fail to effectively detect and mitigate malware encryption of primary data using backup copies without relying on specific malware signatures, rendering backup data unusable and vulnerable to ransomware attacks.

Innovation Solution

An approach that analyzes successive versions of backup copies using multi-factor analysis, including entropy and similarity scores, to infer malware encryption, allowing detection of unknown malware attacks and safeguarding primary data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If backup copies are used to detect malware encryption, then detection capability is improved, but reliability of backup data is worsened when malware infects the source data

Engineering Contradiction:
Improvemalware encryption detectionVSAvoidbackup data availability
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The system performs preliminary analysis of backup copies by comparing successive versions and calculating entropy scores before malware can completely compromise the data. This advance detection allows the system to identify encrypted data early, preventing total data loss and enabling timely recovery actions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional malware signature-based detection with a mathematical/statistical approach using entropy calculation and similarity comparison. Instead of relying on known malware patterns, the system uses information theory principles to detect encryption regardless of the specific malware strain, making detection more reliable against novel threats.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If multi-factor analysis is applied to backup copies, then detection accuracy is improved, but system complexity is worsened

Engineering Contradiction:
Improveencryption detection accuracyVSAvoidanalysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The analysis system is segmented into distinct functional modules: a retrieval module that obtains successive backup copies, a comparison module that calculates similarity scores, and an entropy calculation module that measures randomness. This segmentation allows each component to perform a specific function efficiently, reducing overall system complexity while maintaining high detection accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces intermediary metrics (entropy scores and similarity scores) that mediate between the raw backup data and the final encryption detection decision. These intermediary measurements simplify the complex task of detecting malware encryption by providing quantifiable indicators that can be threshold-based compared, reducing the need for complex analysis logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If successive versions of backup copies are analyzed, then adaptability to unknown malware is improved, but loss of time for data processing is worsened

Engineering Contradiction:
Improvedetection of novel malwareVSAvoiddata processing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs partial analysis by focusing only on the most recent successive versions of backup copies rather than analyzing the entire backup history. This selective approach provides sufficient information to detect encryption while significantly reducing processing time compared to a comprehensive analysis of all backup data.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system changes the parameter of analysis from examining individual file contents to comparing statistical properties (entropy and similarity scores) across successive versions. This parameter transformation enables rapid detection of encryption patterns without requiring detailed inspection of file data, thus reducing processing time while maintaining adaptability to unknown malware.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250217485A1Analysis of backup copies to identify malware-encrypted primary data
Publication Date: 2025.07.03 COMMVAULT SYSTEMS INC
  • US20250217485A1 patent drawing
  • US20250217485A1 patent drawing
  • US20250217485A1 patent drawing

AI summary

Backup data is leveraged to determine whether primary data has been encrypted by malware. The disclosed approach does not rely on recognizing particular malware instances or malware provenance, and thus can be applied to any body of data. Even a novel and previously unknown malware attack can be detected in this way. An illustrative data storage management system analyzes secondary copies it created over time, applies a multi-factor analysis to data recovered from the secondary copies and, based on the analysis, infers whether the primary data from which the secondary copies were created may be encrypted. The present approach uses successive versions of backup copies to find indicia of malware encryption, rather than trying to trace or identify the malware itself. Indicia of entropy correlate highly with encryption, such as encryption performed by malware attacks. Conversely, indicia of similarity correlate highly with lack of encryption of successive versions of documents.