Investigação, Desenvolvimento e Inovação · Aceite pela Entidade

Fortalecer a Imunidade de Sistemas de Armazenamento Contra Ransomware

INESC TEC - INSTITUTO DE ENGENHARIA DE SISTEMAS E COMPUTADORES, TECNOLOGIA E CIÊNCIA

Fundo aprovado
69 638,40 €
Fundo executado
0,00 €
Fundo pago
0,00 €

Esta ficha organiza os campos publicados no Portugal 2030. Mostra financiamento e execução administrativa; não avalia o mérito da candidatura nem confirma resultados no terreno.

NORTE2030-FEDER-00868400

O QUE FOI APRESENTADO

Finalidade da operação

Ransomware attacks are increasingly threatening critical services and disrupting IT systems, leading to huge monetary losses. Due to delayed or failed detection and human error, data becomes unavailable, while current solutions still lack an effective and efficient solution for full data recovery upon the success of these attacks. The main goal of INOCULUM is to develop a self-configurable ransomware-resilient storage system, as depicted in the Architecture Figure annexed to this proposal. Such requires considering the trade-off between usability, security, performance, and storage costs, while addressing the following objectives. O1. To ensure portability, the solution must be compliant with standard file-based interfaces and protocols (e.g., NFS, SMB). Our system will provide a standard…

Ler a descrição publicada na íntegra

Ransomware attacks are increasingly threatening critical services and disrupting IT systems, leading to huge monetary losses. Due to delayed or failed detection and human error, data becomes unavailable, while current solutions still lack an effective and efficient solution for full data recovery upon the success of these attacks. The main goal of INOCULUM is to develop a self-configurable ransomware-resilient storage system, as depicted in the Architecture Figure annexed to this proposal. Such requires considering the trade-off between usability, security, performance, and storage costs, while addressing the following objectives. O1. To ensure portability, the solution must be compliant with standard file-based interfaces and protocols (e.g., NFS, SMB). Our system will provide a standard POSIX API, enabling the support of multiple operating systems (e.g., Linux, Windows, OSX) and ensuring full compatibility with existing applications (e.g., databases, web services). O2. INOCULUM aims to research a secure-by-design storage system. The proposed solution will employ a Write-Once-Read-Many (WORM) strategy, meaning that stored files cannot be updated in place. This strategy will be accomplished through advanced Copy-on-Write (CoW) techniques, ensuring that an immutable copy is generated whenever data is created or updated. As a result, ransomware attacks that succeed in evading detection mechanisms and encrypting files at the storage system will always write encrypted content on a separate copy, leaving the previous content of files unmodified and recoverable. O3. When ransomware attacks succeed in encrypting data, one must be able to efficiently recover compromised information to a previous and coherent state. For this, INOCULUM will research the most appropriate metadata structures that enable users and applications to quickly restore previous versions of their files. O4. Advanced data reduction mechanisms (i.e., deduplication, delta encoding, and compression) will be integrated within our solution to address the increasing storage space costs associated with CoW techniques. Further, we aim to explore caching and prefetching optimizations that will improve the performance of CoW and data recovery mechanisms and, subsequently, the practicality of our solution. O5. Knowing that users and applications will store a mixture of critical and non-critical information, we can further reduce storage space costs. In that sense, INOCULUM will be the first to explore different strategies (e.g., data aging, access patterns) to provide personalized data protection, retaining fewer immutable copies for less critical data while ensuring its recoverability. O6. INOCULUM will explore AI to design a self-configurable storage system, easing the burden of error-prone configurations introduced by the optimizations from O4 and O5. We will research state-of-the-art Machine Learning algorithms to explore the tradeoffs between different configurations based on data characteristics (e.g., history, aging, and access patterns). This objective will improve storage performance and ensure optimal resource utilization while maintaining the solution's resiliency to ransomware. In sum, the project will address complementary research topics to explore the main building blocks for the first secure-by-design storage system tailored for critical services that is resilient to the evolution of ransomware attacks and to human error.

PROGRAMA E OBJETIVOS

Como a operação está enquadrada

Programa
Programa Regional do Norte
Fundo
Fundo Europeu de Desenvolvimento Regional
Objetivo estratégico
+ Inteligente
Objetivo específico
Reforçar a investigação, inovação e adoção de tecnologias avançadas.
Área temática
Investigação, Desenvolvimento e Inovação
Atividade económica
Outras atividades relacionadas com as tecnologias da informação e informática
Modalidade
Subvenção
Taxa de cofinanciamento
40%

ONDE

Distribuição territorial publicada

BragaCávado · Norte
100% da localização

Localização observada no ficheiro de 30 de junho de 2026.

QUANDO

Calendário publicado

Início previsto
15 de maio de 2026
Início efetivo
Não indicada
Conclusão prevista
13 de maio de 2029
Conclusão efetiva
Não indicada

PROVENIÊNCIA

Fonte oficial e datas de corte

Operação e valores: 30 de abril de 2026. Localização: 30 de junho de 2026.

Consultar o portal oficial Portugal 2030 ↗Capturas validadas por SHA-256; última observação em 15 de agosto de 2026.
Fortalecer a Imunidade de Sistemas de Armazenamento Contra Ransomware | Impacto Público