Successive Backup Analysis Using Entropy to Detect Malware Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods fail to effectively detect and mitigate malware encryption of primary data using backup copies without relying on specific malware signatures, rendering backup data unusable and vulnerable to ransomware attacks.
Innovation Solution
An approach that analyzes successive versions of backup copies using multi-factor analysis, including entropy and similarity scores, to infer malware encryption, allowing detection of unknown malware attacks and safeguarding primary data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If backup copies are used to detect malware encryption, then detection capability is improved, but reliability of backup data is worsened when malware infects the source data
Solution Approach 1:
The system performs preliminary analysis of backup copies by comparing successive versions and calculating entropy scores before malware can completely compromise the data. This advance detection allows the system to identify encrypted data early, preventing total data loss and enabling timely recovery actions.
Solution Approach 2:
The patent replaces traditional malware signature-based detection with a mathematical/statistical approach using entropy calculation and similarity comparison. Instead of relying on known malware patterns, the system uses information theory principles to detect encryption regardless of the specific malware strain, making detection more reliable against novel threats.
2Measurement precision
If multi-factor analysis is applied to backup copies, then detection accuracy is improved, but system complexity is worsened
Solution Approach 1:
The analysis system is segmented into distinct functional modules: a retrieval module that obtains successive backup copies, a comparison module that calculates similarity scores, and an entropy calculation module that measures randomness. This segmentation allows each component to perform a specific function efficiently, reducing overall system complexity while maintaining high detection accuracy.
Solution Approach 2:
The system introduces intermediary metrics (entropy scores and similarity scores) that mediate between the raw backup data and the final encryption detection decision. These intermediary measurements simplify the complex task of detecting malware encryption by providing quantifiable indicators that can be threshold-based compared, reducing the need for complex analysis logic.
3Adaptability or versatility
If successive versions of backup copies are analyzed, then adaptability to unknown malware is improved, but loss of time for data processing is worsened
Solution Approach 1:
The system performs partial analysis by focusing only on the most recent successive versions of backup copies rather than analyzing the entire backup history. This selective approach provides sufficient information to detect encryption while significantly reducing processing time compared to a comprehensive analysis of all backup data.
Solution Approach 2:
The system changes the parameter of analysis from examining individual file contents to comparing statistical properties (entropy and similarity scores) across successive versions. This parameter transformation enables rapid detection of encryption patterns without requiring detailed inspection of file data, thus reducing processing time while maintaining adaptability to unknown malware.
Data Source
AI summary
Backup data is leveraged to determine whether primary data has been encrypted by malware. The disclosed approach does not rely on recognizing particular malware instances or malware provenance, and thus can be applied to any body of data. Even a novel and previously unknown malware attack can be detected in this way. An illustrative data storage management system analyzes secondary copies it created over time, applies a multi-factor analysis to data recovered from the secondary copies and, based on the analysis, infers whether the primary data from which the secondary copies were created may be encrypted. The present approach uses successive versions of backup copies to find indicia of malware encryption, rather than trying to trace or identify the malware itself. Indicia of entropy correlate highly with encryption, such as encryption performed by malware attacks. Conversely, indicia of similarity correlate highly with lack of encryption of successive versions of documents.


