Virtual File Honeypots for Injected Ransomware Thread Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional file honeypots are ineffective in detecting malicious threads injected into benign processes, and existing solutions fail to efficiently protect computing systems from ransomware without adding significant system overhead.
Innovation Solution
The implementation of virtual file honeypots (VFHs) that are generated on-demand, tailored to specific threat characteristics, and do not require storage or backup, allowing for early detection of ransomware by monitoring system operations and using machine learning to generate targeted VFHs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional file honeypots are used to detect malware, then suspicious processes can be identified, but they fail to detect malicious threads injected into benign processes and add significant system overhead
Solution Approach 1:
The patent creates virtual file honeypots (VFHs) that are virtual copies of real system files, placed in the filesystem to attract and detect malicious threads. These VFHs are not physical files but virtual representations that consume minimal storage space while effectively luring malware, thereby reducing system overhead compared to conventional file honeypots while maintaining detection reliability
Solution Approach 2:
The patent introduces a virtualization layer that mediates between the real filesystem and malicious processes. The virtual file honeypots act as intermediaries that intercept malicious file access attempts, allowing the system to detect injected threads without requiring actual malicious files to be present, thus reducing system complexity while improving detection capability
2Reliability
If file honeypots are deployed to protect against ransomware, then malware can be detected, but storage space is consumed and backup operations are burdened
Solution Approach 1:
The patent implements virtual file honeypots that are virtual representations rather than physical file copies. These VFHs exist as software abstractions in the virtualization layer, consuming negligible storage space compared to conventional file honeypots that require actual file copies to be deployed in the filesystem
Solution Approach 2:
The patent extracts the essential functionality of file honeypots from physical file storage and relocates it to the virtualization layer. By separating the honeypot function from actual file storage, the system maintains ransomware protection capabilities while eliminating the storage overhead associated with deploying conventional file-based honeypots
3Measurement precision
If conventional honeypots are used, then independent malicious processes can be identified, but injected malicious threads in trusted processes remain undetected
Solution Approach 1:
The patent creates a universal detection mechanism that handles both independent malicious processes and injected malicious threads through the same virtual file honeypot interface. The VFHs are placed in the virtualization layer where they can intercept file access attempts from any context, making the detection system versatile against multiple attack vectors without requiring separate detection mechanisms
Solution Approach 2:
The patent moves the honeypot deployment from the filesystem dimension to the virtualization layer dimension. This dimensional shift allows VFHs to intercept malicious file access attempts regardless of whether they originate from independent processes or injected threads, as the virtualization layer sits above both execution contexts and can monitor all file access operations
Data Source
AI summary
Systems and methods for ransomware protection in advanced injection-based attacks. Events from a driver are analyzed to identify a potentially malicious actor. A confidence level is calculated for the potentially malicious actor identification to weigh the probability that the actor is malware or a source of malware. Behavior associated with the potentially malicious actor can be collected, if it is likely that the potentially malicious actor is associated with malware, such as if the confidence level is over a predetermined threshold. Subsequently, one or more virtual honeypots are generated for the suspicious processes and the response to the virtual honeypots is included in anti-ransomware heuristic analysis.


