IP Library › Granted Patent US 12,572,655
Granted Patent B2
US 12,572,655 · App. 18/599,003 · Granted Mar 10, 2026

Detecting ransomware activity in data storage systems

Inventors: Roman Alexander Pletka (Uster, CH); Slavisa Sarafijanovic (Adliswil, CH); Dionysios Diamantopoulos (Zurich, CH); Charalampos Pozidis (Thalwil, CH); Yves Alexandre Beraldo Dos Santos (Houston, TX); Andrew D. Walls (San Jose, CA)
Assignee: International Business Machines Corporation
G06F21/565H04L63/1416H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,572,655
App. No.
18/599,003
Granted
Mar 10, 2026
Kind
B2
Abstract

A computer-implemented method, according to one approach, is for detecting ransomware activity in storage systems. The computer-implemented method includes: receiving a write request having a plurality of sectors, and each of the sectors further includes a number of sub-sectors. A degree of randomness is determined across the sub-sectors of each of the respective sectors, and a determination is made as to whether any deviations exist in the degrees of randomness. In response to determining a deviation exists in the degrees of randomness, this information on the deviation is used as an indicator of the write request including ransomware activity.

Claims (77)

1 . A computer-implemented method (CIM) for detecting ransomware activity in storage systems, comprising:

receiving a write request having a plurality of sectors, wherein each of the sectors includes a number of sub-sectors;

causing the sub-sectors in the respective sectors of the write request to be performed;

determining degrees of randomness across the sub-sectors of the respective sectors by:

determining entropy values associated with the performing the sub-sectors in the respective sectors of the write request, and

determining a difference between the entropy values of the sub-sectors in the respective sectors;

determining whether any deviations exist in the degrees of randomness; and

in response to determining a deviation exists in the degrees of randomness, using information associated with the deviation to determine that one or more of the sub-sectors in one or more of the respective sectors includes data encrypted by ransomware.

2 . The CIM of claim 1 , wherein the determining of the difference between the entropy values of the sub-sectors in the respective sectors includes:

calculating a median absolute deviation (MAD) value for the entropy values of the sub-sectors.

3 . The CIM of claim 2 , further comprising:

aggregating MAD values calculated for write requests over a time interval, wherein the MAD values are aggregated in a histogram.

4 . The CIM of claim 1 , wherein the determining of the entropy values associated with performing the sub-sectors in the respective sectors includes:

calculating a first value, the first value being selected from the group consisting of: a Shannon entropy value, a Chi-Square value, a Monte-Carlo value, and a Pi value; and

using the first value to derive the entropy value.

5 . The CIM of claim 1 , wherein the write request includes a read-modify-write operation, wherein the determining of the degrees of randomness across the sub-sectors includes, for the respective sectors:

reading original data stored in memory at target addresses that correspond to the sub-sectors of a given sector of the write request;

in response to the write request being initiated, evaluating new data in a write cache;

determining entropy values associated with performing the respective sub-sectors in the given sector by comparing the original data and the new data; and

determining a difference between the entropy values of the sub-sectors in the given sector.

6 . The CIM of claim 5 , further comprising:

determining whether any of the target addresses include at least a portion of a known honeypot file; and

in response to determining that one or more of the target addresses include at least a portion of the known honeypot file, identifying the given sector of the write request as including ransomware activity.

7 . The CIM of claim 1 , further comprising:

receiving a second write request which impacts less than a full sector, the second write request having a first set of sub-sectors in an identified sector; and

determining a second set of sub-sectors in the identified sector not being part of the second write request;

reading original data stored in memory at target addresses that correspond to the first and second sets of sub-sectors;

determining a degree of randomness across the first set of sub-sectors in the identified sector; and

determining a degree of randomness across the second set of sub-sectors in the identified sector.

8 . The CIM of claim 1 , wherein the determining of the degrees of randomness across the sub-sectors of the respective sectors includes, determining a number of degrees of randomness across the sub-sectors of a given one of the respective sectors, wherein each degree of randomness is determined using a different combination of sub-sector sizes and/or groupings of sub-sectors of the given sector, wherein the determining of whether any deviations exist in the degrees of randomness is based at least in part on the number of degrees of randomness that are determined.

9 . A computer program product (CPP) for detecting ransomware activity in storage systems, comprising:

a set of one or more computer-readable storage media; and

program instructions, collectively stored in the set of one or more storage media, for causing a processor set to perform the following computer operations:

receive a write request having a plurality of sectors, wherein each of the sectors includes a number of sub-sectors;

cause the sub-sectors in the respective sectors of the write request to be performed;

determine degrees of randomness across the sub-sectors of the respective sectors by:

determining entropy values associated with the performing the sub-sectors in the respective sectors of the write request, and

determining a difference between the entropy values of the sub-sectors in the respective sectors;

determine whether any deviations exist in the degrees of randomness; and

in response to determining a deviation exists in the degrees of randomness, using information associated with the deviation to determine that one or more of the sub-sectors in one or more of the respective sectors includes data encrypted by ransomware.

10 . The CPP of claim 9 , wherein the determining of the difference between the entropy values of the sub-sectors in the respective sectors includes:

calculating a median absolute deviation (MAD) value for the entropy values of the sub-sectors.

11 . The CPP of claim 10 , wherein the program instructions are for causing the processor set to further perform the following computer operations:

aggregate MAD values calculated for write requests over a time interval, wherein the MAD values are aggregated in a histogram.

12 . The CPP of claim 9 , wherein the determining of the entropy values associated with performing the sub-sectors in the respective sectors includes:

calculating a first value, the first value being selected from the group consisting of: a Shannon entropy value, a Chi-Square value, a Monte-Carlo value, and a Pi value; and

using the first value to derive the entropy value.

13 . The CPP of claim 9 , wherein the write request includes a read-modify-write operation, wherein the determining of the degrees of randomness across the sub-sectors includes, for the respective sectors:

reading original data stored in memory at target addresses that correspond to the sub-sectors of a given sector of the write request;

in response to the write request being initiated, evaluating new data in a write cache;

determining entropy values associated with performing the respective sub-sectors in the given sector by comparing the original data and the new data; and

determining a difference between the entropy values of the sub-sectors in the given sector.

14 . The CPP of claim 13 , wherein the program instructions are for causing the processor set to further perform the following computer operations:

determine whether any of the target addresses include at least a portion of a known honeypot file; and

in response to determining that one or more of the target addresses include at least a portion of the known honeypot file, identify the given sector of the write request as including ransomware activity.

15 . The CPP of claim 9 , wherein the program instructions are for causing the processor set to further perform the following computer operations:

receive a second write request which impacts less than a full sector, the second write request having a first set of sub-sectors in an identified sector; and

determine a second set of sub-sectors in the identified sector not being part of the second write request;

read original data stored in memory at target addresses that correspond to the first and second sets of sub-sectors;

determine a degree of randomness across the first set of sub-sectors in the identified sector; and

determine a degree of randomness across the second set of sub-sectors in the identified sector.

16 . A computer system (CS), comprising:

a processor set;

a set of one or more computer-readable storage media;

program instructions, collectively stored in the set of one or more storage media, for causing the processor set to perform the following computer operations:

receive a write request having a plurality of sectors, wherein each of the sectors includes a number of sub-sectors;

cause the sub-sectors in the respective sectors of the write request to be performed;

determine degrees of randomness across the sub-sectors of the respective sectors by:

determining entropy values associated with the performing the sub-sectors in the respective sectors of the write request, and

determining a difference between the entropy values of the sub-sectors in the respective sectors;

determine whether any deviations exist in the degrees of randomness; and

in response to determining a deviation exists in the degrees of randomness, using information associated with the deviation to determine that one or more of the sub-sectors in one or more of the respective sectors includes data encrypted by ransomware.

17 . The CS of claim 16 , wherein the write request includes a read-modify-write operation, wherein the determining of the degrees of randomness across the sub-sectors includes, for the respective sectors:

reading original data stored in memory at target addresses that correspond to the sub-sectors of a given sector of the write request;

in response to the write request being initiated, evaluating new data in a write cache;

determining entropy values associated with performing the respective sub-sectors in the given sector by comparing the original data and the new data; and

determining a difference between the entropy values of the sub-sectors in the given sector.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2024
From: PLETKA, ROMAN ALEXANDER; SARAFIJANOVIC, SLAVISA; DIAMANTOPOULOS, DIONYSIOS; POZIDIS, CHARALAMPOS; SANTOS, YVES ALEXANDRE BERALDO DOS; WALLS, ANDREW D.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 066719/0100 →
Continuity (1)
Related Publication 20250284803A1 · Sep 11, 2025
References Cited (22)
US 10055582B1 · Weaver et al. · 2018 [cited by applicant]
US 10121003B1 · Adams · 2018 [cited by applicant]
US 11113156B2 · Brewer et al. · 2021 [cited by applicant]
US 11663336B1 · Armangau · 2023 [cited by examiner]
US 11748475B1 · Berk · 2023 [cited by examiner]
US 12306937B1 · Siu · 2025 [cited by examiner]
US 20170093886A1 · Ovcharik · 2017 [cited by examiner]
US 20170324755A1 · Dekel · 2017 [cited by examiner]
US 20200097653A1 · Mehta · 2020 [cited by examiner]
US 20200387609A1 · Hansen · 2020 [cited by applicant]
US 20230273995A1 · Chen · 2023 [cited by examiner]
US 20240134976A1 · Shachar · 2024 [cited by examiner]
US 20240333759A1 · Zhang · 2024 [cited by examiner]
US 20240346150A1 · Dar · 2024 [cited by examiner]
Constantinescu et al., “Sentinel—Ransomware Detection in File Storage,” Proceedings of the 14th ACM International Conference on Systems and Storage (SYSTOR '21), Jun. 2021, 1 page. [cited by applicant]
Lee et al., “Effective Ransomware Detection Using Entropy Estimation of Files for Cloud Services,” Sensors, vol. 23, 2023, pp. 1-18. [cited by applicant]
Davies et al., “Comparison of Entropy Calculation Methods for Ransomware Encrypted File Identification,” Entropy, vol. 24, Oct. 21, 2022, pp. 1-24. [cited by applicant]
Davies et al., “Differential Area Analysis for Ransomware Attack Detection within Mixed File Datasets,” arXiv, 2021, pp. 1-13, retrieved from https://arxiv.org/abs/2106.14418. [cited by applicant]
Hirano et al., Machine Learning Based Ransomware Detection Using Storage Access Patterns Obtained From Live-forensic Hypervisor, IEEE, 2019, 6 pages. [cited by applicant]
Hirano et al., “RanSAP: An open dataset of ransomware storage access patterns for training machine learning models,” Forensic Science International: Digital Investigation, vol. 40, 2022, pp. 1-22. [cited by applicant]
Gagulic et al., “Ransomware Detection with Machine Learning in Storage Systems,” Master Project—Communication Systems, University of Zurich Department of Informatics (IFI), Feb. 13, 2023, 114 pages. [cited by applicant]
Shafiq et al., “Embedded Malware Detection Using Markov n-Grams”, DIMVA 2008, pp. 88-107. [cited by applicant]