O QUE FOI APRESENTADO
Finalidade da operação
Ransomware attacks are increasingly threatening critical services and disrupting IT systems, leading to huge monetary losses. Due to delayed or failed detection and human error, data becomes unavailable, while current solutions still lack an effective and efficient solution for full data recovery upon the success of these attacks. The main goal of INOCULUM is to develop a self-configurable ransomware-resilient storage system, as depicted in the Architecture Figure annexed to this proposal. Such requires considering the trade-off between usability, security, performance, and storage costs, while addressing the following objectives. O1. To ensure portability, the solution must be compliant with standard file-based interfaces and protocols (e.g., NFS, SMB). Our system will provide a standard…
Ler a descrição publicada na íntegra
Ransomware attacks are increasingly threatening critical services and disrupting IT systems, leading to huge monetary losses. Due to delayed or failed detection and human error, data becomes unavailable, while current solutions still lack an effective and efficient solution for full data recovery upon the success of these attacks. The main goal of INOCULUM is to develop a self-configurable ransomware-resilient storage system, as depicted in the Architecture Figure annexed to this proposal. Such requires considering the trade-off between usability, security, performance, and storage costs, while addressing the following objectives. O1. To ensure portability, the solution must be compliant with standard file-based interfaces and protocols (e.g., NFS, SMB). Our system will provide a standard POSIX API, enabling the support of multiple operating systems (e.g., Linux, Windows, OSX) and ensuring full compatibility with existing applications (e.g., databases, web services). O2. INOCULUM aims to research a secure-by-design storage system. The proposed solution will employ a Write-Once-Read-Many (WORM) strategy, meaning that stored files cannot be updated in place. This strategy will be accomplished through advanced Copy-on-Write (CoW) techniques, ensuring that an immutable copy is generated whenever data is created or updated. As a result, ransomware attacks that succeed in evading detection mechanisms and encrypting files at the storage system will always write encrypted content on a separate copy, leaving the previous content of files unmodified and recoverable. O3. When ransomware attacks succeed in encrypting data, one must be able to efficiently recover compromised information to a previous and coherent state. For this, INOCULUM will research the most appropriate metadata structures that enable users and applications to quickly restore previous versions of their files. O4. Advanced data reduction mechanisms (i.e., deduplication, delta encoding, and compression) will be integrated within our solution to address the increasing storage space costs associated with CoW techniques. Further, we aim to explore caching and prefetching optimizations that will improve the performance of CoW and data recovery mechanisms and, subsequently, the practicality of our solution. O5. Knowing that users and applications will store a mixture of critical and non-critical information, we can further reduce storage space costs. In that sense, INOCULUM will be the first to explore different strategies (e.g., data aging, access patterns) to provide personalized data protection, retaining fewer immutable copies for less critical data while ensuring its recoverability. O6. INOCULUM will explore AI to design a self-configurable storage system, easing the burden of error-prone configurations introduced by the optimizations from O4 and O5. We will research state-of-the-art Machine Learning algorithms to explore the tradeoffs between different configurations based on data characteristics (e.g., history, aging, and access patterns). This objective will improve storage performance and ensure optimal resource utilization while maintaining the solution's resiliency to ransomware. In sum, the project will address complementary research topics to explore the main building blocks for the first secure-by-design storage system tailored for critical services that is resilient to the evolution of ransomware attacks and to human error.
PROGRAMA E OBJETIVOS
Como a operação está enquadrada
- Programa
- Programa Regional do Norte
- Fundo
- Fundo Europeu de Desenvolvimento Regional
- Objetivo estratégico
- + Inteligente
- Objetivo específico
- Reforçar a investigação, inovação e adoção de tecnologias avançadas.
- Área temática
- Investigação, Desenvolvimento e Inovação
- Atividade económica
- Outras atividades relacionadas com as tecnologias da informação e informática
- Modalidade
- Subvenção
- Taxa de cofinanciamento
- 40%
ONDE
Distribuição territorial publicada
Localização observada no ficheiro de 30 de junho de 2026.
QUANDO
Calendário publicado
- Início previsto
- 15 de maio de 2026
- Início efetivo
- Não indicada
- Conclusão prevista
- 13 de maio de 2029
- Conclusão efetiva
- Não indicada