IP Library Patent Application 16142737
Patent Application
App. No. 16/142,737

Enterprise Non-Encryption Enforcement And Detection of Ransomware

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/142,737
Abstract

An enterprise storage system and method detects the probability of encryption of data by comparing the level of randomness in the data to a set of increasing thresholds to determine the severity of encryption. Encryption exceeding a high predetermined threshold is determined to be due to ransomware. Upon determining the level of encryption, an appropriate action is taken based upon one or both of the policy of the enterprise or local governmental regulations as to encryption or non-encryption of data.

Claims (31)

1 . A method of detecting encryption of data in an enterprise data storage system, comprising:

providing a virtualization system for managing the storage of data received by said virtualization system from a data source;

analyzing said received data to determine a probability of encryption of said received data prior to writing said received data to data storage;

comparing said determined probability with each one of a set of threshold levels having increasing values to determine a severity level of said encryption; and

taking an action determined by a policy of said enterprise based upon said severity level of said encryption.

2 . The method of claim 1 , wherein said analyzing comprises analyzing a predetermined number, L, blocks of sequential data in real time to determine a measure of randomness in said data, and detecting encryption based upon said measure of randomness.

3 . The method of claim 2 , wherein said predetermined number of blocks is selected based upon the type of data received and the source of said received data.

4 . The method of claim 2 , wherein said analyzing said received data comprises determining a measure of entropy in said received data and applying another statistic to determine a deviation in said randomness in said data from an expected result.

5 . The method of claim 4 , wherein said applying another statistic comprises using Chi square to differentiate encryption of said received data from compression of said received data.

6 . The method of claim 1 , wherein, upon determining that said severity level of encryption exceeds a predetermined threshold level, determining that said encryption is due to ransomware, and taking said action comprises issuing an alert and blocking writing of said data to said storage.

7 . The method of claim 1 , wherein said taking said action comprises ensuring that said encryption of said data complies with governmental regulations applicable to a location of said enterprise data storage.

8 . The method of claim 1 , wherein said virtualization system comprises centralized platform independent software defined storage, and wherein said method of detecting encryption is performed by a virtual machine of said virtualization system.

9 . A non-transitory storage medium embodying executable instructions for controlling a processor to perform a method of detecting encryption of data in an enterprise data storage system, the method comprising:

providing a virtualization system for managing the storage of data received by said virtualization system from a data source;

analyzing said received data to determine a probability of encryption of said received data prior to writing said received data to data storage;

comparing said determined probability with each one of a set of threshold levels having increasing values to determine a severity level of said encryption; and

taking an action determined by a policy of said enterprise based upon said severity level of said encryption.

10 . The non-transitory storage medium of claim 9 , wherein said analyzing comprises analyzing a predetermined number, L, blocks of sequential data in real time to determine a measure of randomness in said data, and detecting encryption based upon said measure of randomness.

11 . The non-transitory storage medium of claim 10 , wherein said analyzing said received data comprises determining a measure of entropy in said received data in combination with applying another statistic to determine a deviation in said randomness in said data from an expected result.

12 . The non-transitory storage medium of claim 9 , wherein, upon determining that said severity level of encryption exceeds a predetermined threshold level, determining that said encryption is due to ransomware, and taking said action comprises issuing an alert and blocking writing of said data to said storage.

13 . The non-transitory storage medium of claim 9 , wherein, upon determining that said severity level of encryption exceeds a predetermined threshold level, determining that said encryption is due to ransomware, and taking said action comprises issuing an alert and blocking writing of said data to said storage.

14 . The non-transitory storage medium of claim 9 , wherein said taking said action comprises ensuring that said encryption of said data complies with governmental regulations applicable to a location of said enterprise data storage.

15 . The non-transitory storage medium of claim 9 , wherein said virtualization system comprises platform independent software defined storage, and wherein said method of detecting encryption is performed at a centralized location of said enterprise.

16 . An enterprise data storage system, comprising:

a server receiving data for storage from a network, the server comprising a virtualization system for managing the storage of said received data;

a virtual machine monitor configured to analyze in real time blocks of said received data to determine a probability of encryption of said received data;

a virtual machine processor configured to compare said probability of encryption to each one of a set of thresholds having increasing values to determine a severity level of said encryption; and

a storage server configured to take an action determined by a policy of said enterprise, said policy being determined by one or both of said severity level of said encryption or local regulations regarding encryption of data that are applicable to said location of said storage system.

17 . The enterprise data storage system of claim 16 , wherein said virtualization system comprises a central platform independent software defined storage application executing on a virtual machine of said system.

18 . The enterprise storage system of claim 16 , wherein said monitor is configured to determine a measure of randomness in a sequence of said received data, and to determine a deviation in said measure of randomness from an expected result.

19 . The enterprise storage system 16 , wherein said storage server is configured to provide an alert and to block storage of said received data upon determining that said encryption is due to ransomware.

Assignments (3)
CORRECTIVE NOTICE TO RELEASE SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Jun 30, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 053529/0862 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2018
From: GOLAN, ORON; WOLFSON, KFIR; ZAMIR, AMOS; SHEMER, UDI
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 046982/0058 →