New SSDs Have Built-In Protection Against Ransomware, Data Theft
tomshardware.com
tomshardware.com
My money says that their "dynamic data defense engine" is functionally independent of the SSD, and only requires their branded SSD to be installed as a licensing dongle. Describing this as a feature of the SSD is entirely a marketing ploy. And, because hardware companies are generally not very good at making decisions about software, the software they're bundling is probably less effective than a standalone security suite would have been.
A ransomware attack will rewrite large sections of the drive. Initial phases aren't distinguishable from things like updates but as it progresses the intent becomes more clear. An SSD can leave a ring buffer of old blocks around and transparently revert back if an attack is discovered.
You could also do this as part of the filesystem, but the SSD already has to perform wear levelling and so is quite adept at transparently remapping blocks. It also has the benefit of hardware acceleration in the controller. It's not necessarily a bad place to implement the recovery.
I think the hangup is the assumption the drive has to do 100% of the work. It is only needed to accelerate the snapshots for restoration after an attack is detected. Determining whether the system is under attack and the correct response can be done in software.
On a larger note the remapping engine in an SSD makes for a great primitive. It would be awesome if SSDs exposed this in a more general way.
Source: have written FTLs that shipped in products
In any case users don't expect snapshots to be free.
SSD firmware is simply NOT the place to do this. This is the same reason we do not implement HTML parsers in the kernel or javascript runtimes in BIOS. Too high level of a concept in too low level of a place
I don't think we disagree the remapping hardware could be repurposed for assisting the creation of COW snapshots, though obviously the disk space wouldn't come for free.
I'm not convinced it does at all. Encrypting a bunch of files one by one is going to be indistinguishable at the block layer from other common operations like updating software, transcoding media files, or creating a compressed archive.
Besides, I still haven't heard a convincing argument that the SSD controller could detect and respond to this any better than the OS could. At best, it might be able to do a poor job of it.
Traditional AV software still has to do the detection and its capable of that long before the entire drive is rewritten.
Thanks, but no thanks. That’s about as bad as eMailing password reminders because you stored them in plaintext or reversible encryption. There is just no way of fully and properly protecting your data, then.