• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

SSD-Insider++ Promises Ransomware-free SSDs

TheLostSwede

News Editor
Joined
Nov 11, 2004
Messages
16,062 (2.26/day)
Location
Sweden
System Name Overlord Mk MLI
Processor AMD Ryzen 7 7800X3D
Motherboard Gigabyte X670E Aorus Master
Cooling Noctua NH-D15 SE with offsets
Memory 32GB Team T-Create Expert DDR5 6000 MHz @ CL30-34-34-68
Video Card(s) Gainward GeForce RTX 4080 Phantom GS
Storage 1TB Solidigm P44 Pro, 2 TB Corsair MP600 Pro, 2TB Kingston KC3000
Display(s) Acer XV272K LVbmiipruzx 4K@160Hz
Case Fractal Design Torrent Compact
Audio Device(s) Corsair Virtuoso SE
Power Supply be quiet! Pure Power 12 M 850 W
Mouse Logitech G502 Lightspeed
Keyboard Corsair K70 Max
Software Windows 10 Pro
Benchmark Scores https://valid.x86.fr/5za05v
Over the past couple of years there has been a huge increase in ransomware attacks, and now scientists claim to have a solution that could help protect SSDs from getting encrypted by ransomware. The SSD-Insider++, as the solution has been named, claims to be able to detect ransomware activity and reverse the encryption on the fly.

SSD-Insider++ was developed by a group of engineers from South Korea's Inha University, Daegu Institute of Science and Technology, and the Cyber Security Department at Ewha Womans University (EWU), as well as a researcher from the University of Central Florida in the US. It's a firmware level based protection that looks for patterns of ransomware activity on the drive and stops it before any damage has been done.



This is done by suspending the I/O to the SSD, and this will apparently give the user a chance to remove the ransomware on the system, before it has a chance to encrypt the data. The creators of SSD-Insider++ also claim that any damage that might have occurred before the ransomware was detected, can be reversed in a matter of seconds, simply by using data held in the NAND flash before the data has been trimmed.

Furthermore, there are claims of being able to detect 100 percent of ransomwares in the wild and reversing any damage caused within 10 seconds of the encryption starting, thanks to a firmware level implementation. SSD-Insider++ does come with an increase in SSD latency of somewhere between 12.8 and 17.3 percent in the test scenarios, as well a worst case drop in throughput of about eight percent. By implementing it on a firmware level, workaround ought to be harder, but maybe not impossible.

Outside of the performance hit on current SSD controllers, the creators of SSD-Insider++ seem to think that we're going to need faster Arm cores and/or additional computing resources such as an NPU or a faster encryption/decryption engine in future SSD controllers to add advanced features such as entropy-based detection.

As to whether we'll see this technology implemented by any of the SSD controller manufacturers is most likely just a matter of time, at least on the enterprise side of things. Several Korean SSD controller manufacturers have already been contacted, but so far there hasn't been any real interest.

View at TechPowerUp Main Site
 
Joined
Jul 10, 2017
Messages
2,671 (1.08/day)
Hmm, and what if someone tries to enable BitLocker or tries to encrypt files in RAR?
 
Joined
Jun 4, 2019
Messages
56 (0.03/day)
Hmm, and what if someone tries to enable BitLocker or tries to encrypt files in RAR?

Ransomware generally has unique patterns in the way it operates, atleast the majority of those currently in "cirulation".

Bitlocker for instance will encrypt everything, while Ransomware would ideally go for smaller files, like documents/pictures/etc. first, and overwrite these in place with the same but encrypted data.

Encrpyting files in 7-Zip or RAR archives is nowhere near the throughput of ransomware - ransomware usually needs to be fast to be effective, meaning it will encrypt tons of files at different locations on the drive. Knowing this fact however, we will see Ransomware that acts differently once drives with this technology should roll out.

However, applying this protection to the masses of unprotected drives out there would still have a net benefit, not every Ransomware is and will be refined to bypass it. Combine it with software and the security increases tremendously.
 
Joined
Jan 8, 2017
Messages
8,931 (3.35/day)
System Name Good enough
Processor AMD Ryzen R9 7900 - Alphacool Eisblock XPX Aurora Edge
Motherboard ASRock B650 Pro RS
Cooling 2x 360mm NexXxoS ST30 X-Flow, 1x 360mm NexXxoS ST30, 1x 240mm NexXxoS ST30
Memory 32GB - FURY Beast RGB 5600 Mhz
Video Card(s) Sapphire RX 7900 XT - Alphacool Eisblock Aurora
Storage 1x Kingston KC3000 1TB 1x Kingston A2000 1TB, 1x Samsung 850 EVO 250GB , 1x Samsung 860 EVO 500GB
Display(s) LG UltraGear 32GN650-B + 4K Samsung TV
Case Phanteks NV7
Power Supply GPS-750C
Encrpyting files in 7-Zip or RAR archives is nowhere near the throughput of ransomware - ransomware usually needs to be fast to be effective, meaning it will encrypt tons of files at different locations on the drive. Knowing this fact however, we will see Ransomware that acts differently once drives with this technology should roll out.

As far as I know ransomwares simply scramble the data since it's never actually meant to be decrypted anyway.
 
Joined
Jul 10, 2017
Messages
2,671 (1.08/day)
As far as I know ransomwares simply scramble the data since it's never actually meant to be decrypted anyway.
Uhm, how does the attacker actually gain from this? Most ransomware are providing you with a decryption key once you pay.

Ransomware generally has unique patterns in the way it operates, atleast the majority of those currently in "cirulation".

Bitlocker for instance will encrypt everything, while Ransomware would ideally go for smaller files, like documents/pictures/etc. first, and overwrite these in place with the same but encrypted data.

Encrpyting files in 7-Zip or RAR archives is nowhere near the throughput of ransomware - ransomware usually needs to be fast to be effective, meaning it will encrypt tons of files at different locations on the drive. Knowing this fact however, we will see Ransomware that acts differently once drives with this technology should roll out.

However, applying this protection to the masses of unprotected drives out there would still have a net benefit, not every Ransomware is and will be refined to bypass it. Combine it with software and the security increases tremendously.
Good idea but it will easily be defeated with a small software patch in malware's code, while it still will be a huge effort to keep up when it comes to SSD firmware.

Plus, I prefer some digital hygiene over increased complexity, price and power consumption of the SSD. Plus, I'd hate to update my SSD's 'antivirus' every month just to be able to thwart a possible ransomware attack.
 
Joined
Feb 20, 2020
Messages
9,340 (6.13/day)
Location
Louisiana
System Name Ghetto Rigs z490|x99|Acer 17 Nitro 7840hs/ 5600c40-2x16/ 4060/ 1tb acer stock m.2/ 4tb sn850x
Processor 10900k w/Optimus Foundation | 5930k w/Black Noctua D15
Motherboard z490 Maximus XII Apex | x99 Sabertooth
Cooling oCool D5 res-combo/280 GTX/ Optimus Foundation/ gpu water block | Blk D15
Memory Trident-Z Royal 4000c16 2x16gb | Trident-Z 3200c14 4x8gb
Video Card(s) Titan Xp-water | evga 980ti gaming-w/ air
Storage 970evo+500gb & sn850x 4tb | 860 pro 256gb | Acer m.2 1tb/ sn850x 4tb| Many2.5" sata's ssd 3.5hdd's
Display(s) 1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24"/ 3rd LG 43" series
Case D450 | Cherry Entertainment center on Test bench
Audio Device(s) Built in Realtek x2 with 2-Insignia 2.0 sound bars & 1-LG sound bar
Power Supply EVGA 1000P2 with APC AX1500 | 850P2 with CyberPower-GX1325U
Mouse Redragon 901 Perdition x3
Keyboard G710+x3
Software Win-7 pro x3 and win-10 & 11pro x3
Benchmark Scores Are in the benchmark section
Hi,
Looks like along with ddr5, latency is hosed lol
 
Joined
Jan 8, 2017
Messages
8,931 (3.35/day)
System Name Good enough
Processor AMD Ryzen R9 7900 - Alphacool Eisblock XPX Aurora Edge
Motherboard ASRock B650 Pro RS
Cooling 2x 360mm NexXxoS ST30 X-Flow, 1x 360mm NexXxoS ST30, 1x 240mm NexXxoS ST30
Memory 32GB - FURY Beast RGB 5600 Mhz
Video Card(s) Sapphire RX 7900 XT - Alphacool Eisblock Aurora
Storage 1x Kingston KC3000 1TB 1x Kingston A2000 1TB, 1x Samsung 850 EVO 250GB , 1x Samsung 860 EVO 500GB
Display(s) LG UltraGear 32GN650-B + 4K Samsung TV
Case Phanteks NV7
Power Supply GPS-750C
Uhm, how does the attacker actually gain from this? Most ransomware are providing you with a decryption key once you pay.
They lie, why would they care ? You can look this up, once you pay you never hear from them again. They're not gonna send you anything, that why they minimize exposure to the absolute minimum.
 
Joined
Jul 10, 2017
Messages
2,671 (1.08/day)
They lie, why would they care ? You can look this up, once you pay you never hear from them again. They're not gonna send you anything, that why they minimize exposure to the absolute minimum.
Exactly the opposite from what I heard. I guess it's polarized?
 
Joined
Oct 16, 2014
Messages
671 (0.19/day)
System Name Work in progress
Processor AMD Ryzen 5 3600
Motherboard Asus PRIME B350M-A
Cooling Wraith Stealth Cooler, 4x140mm Noctua NF-A14 FLX 1200RPM Case Fans
Memory Corsair 16GB (2x8GB) CMK16GX4M2A2400C14R DDR4 2400MHz Vengeance LPX DIMM
Video Card(s) GTX 1050 2GB (for now) 3060 12GB on order
Storage Samsung 860 EVO 500GB, Lots of HDD storage
Display(s) 32 inch 4K LG, 55 & 48 inch LG OLED, 40 inch Panasonic LED LCD
Case Cooler Master Silencio S400
Audio Device(s) Sound: LG Monitor Built-in speakers (currently), Mike: Marantz MaZ
Power Supply Corsair CS550M 550W ATX Power Supply, 80+ Gold Certified, Semi-Modular Design
Mouse Logitech M280
Keyboard Logitech Wireless Solar Keyboard K750R (works best in summer)
VR HMD none
Software Microsoft Windows 10 Home 64bit OEM, Captur 1 21
Benchmark Scores Cinebench R20: 3508 (WIP)
Nature abhors a vacuum?
 
Joined
Nov 7, 2017
Messages
1,468 (0.62/day)
Location
Ibiza, Spain.
System Name Main
Processor R7 5950x
Motherboard MSI x570S Unify-X Max
Cooling D5 clone, 280 rad, two F14 + three F12S bottom/intake, two P14S + F14S (Rad) + two F14 (top)
Memory 2x8 GB Corsair Vengeance bdie 3600@CL16 1.35v
Video Card(s) GB 2080S WaterForce WB
Storage six M.2 pcie gen 4
Display(s) Sony 50X90J
Case Tt Level 20 HT
Audio Device(s) Asus Xonar AE, modded Sennheiser HD 558, Klipsch 2.1 THX
Power Supply Corsair RMx 750w
Mouse Logitech G903
Keyboard GSKILL Ripjaws
VR HMD NA
Software win 10 pro x64
Benchmark Scores TimeSpy score Fire Strike Ultra SuperPosition CB20
lol. probably outdated code/fw by the time consumer buys/installs it.
and to me sounds "very smart".
like "Hey, front door cant be locked anymore.."
..installs security cam...
 
Joined
Feb 1, 2019
Messages
2,582 (1.35/day)
Location
UK, Leicester
System Name Main PC
Processor 13700k
Motherboard Asrock Z690 Steel Legend D4 - Bios 13.02
Cooling Noctua NH-D15S
Memory 32 Gig 3200CL14
Video Card(s) 3080 RTX FE 10G
Storage 1TB 980 PRO (OS, games), 2TB SN850X (games), 2TB DC P4600 (work), 2x 3TB WD Red, 2x 4TB WD Red
Display(s) LG 27GL850
Case Fractal Define R4
Audio Device(s) Asus Xonar D2X
Power Supply Antec HCG 750 Gold
Software Windows 10 21H2 LTSC
Good idea, but will need to be constantly updated probably, ransomware authors will work round it if it is widespread enough "and" effective.
 
Top