Invention Title:

RANSOMWARE DETECTION SYSTEM FOR NVME-OF BASED STORAGE USING THE AGGREGATION OF NVME SEQUENCES

Publication number:

US20260220265

Publication date:
Section:

Physics

Class:

G06F21/565

Inventors:

Assignee:

Applicant:

Smart overview of the Invention

The patent application introduces a system designed to detect ransomware attacks on storage devices using Nonvolatile Memory Express over Fabrics (NVMe-oF). The approach involves obtaining an NVMe-oF command stream, pre-processing it, and dividing it into chunks. These chunks are then analyzed using an artificial intelligence (AI) model to identify any malicious NVMe commands. If detected, a memory recovery operation is initiated to protect the storage device.

Background

Ransomware is a type of malware that restricts access to data on a user's device, demanding payment for data restoration. It can target various systems, including those based on NVMe-oF technology, which are prevalent in large data centers. Traditional detection methods often rely on operating system-level analysis, which can be circumvented by sophisticated attacks. Current techniques are limited in their ability to predict the impact of ransomware, as they often overlook the sequential nature of NVMe command patterns.

Technical Approach

The proposed system enhances ransomware detection by leveraging the sequential patterns of NVMe command streams. By dividing the command stream into chunks and analyzing them with an AI model, the system provides a more accurate detection mechanism. This method surpasses simple statistical analysis by considering the temporal changes within the NVMe series, allowing for a comprehensive defense solution that minimizes false alarms and optimizes recovery strategies.

Advantages

Unlike software-based protections, this system operates at a lower level, beyond user and administrative privileges, making it more resilient to OS manipulations. It offers cross-platform compatibility and reduces the central processing unit (CPU) workload by handling operations within the storage device. Additionally, it has access to data that might be inaccessible to software-only solutions, such as information in logically-erased blocks, enhancing its detection and recovery capabilities.

Applications

While primarily focused on ransomware detection, the system can also protect against other types of malware. For instance, it can mitigate crypto-mining attacks that exploit storage resources, like those used by cryptocurrencies such as Filecoin and Chia. By monitoring NVMe commands, the system can prevent unauthorized storage usage and maintain the health and performance of storage devices, safeguarding them against degradation from excessive program/erase cycles.