A security company claims to have developed a flash drive with built-in ransomware prevention support that can protect data stored on it from being stolen or encrypted by malware. The Cigent Secure SSD+ has a built-in processor that uses machine learning algorithms to constantly monitor access to the drive and will intervene to block access if it detects ransomware activity, we were told.

Cigent also claims that this differs from existing approaches to combating ransomware, providing organizations with a proactive solution rather than dealing with an attack that has already taken place.
"Endpoint Detection and Response (EDR) products are based on 'detection and response' after an attack has already occurred," the company's Chief Revenue Officer Tom Ricoy said in a statement.
Instead, he claimed, “Cigent has placed automated attack prevention as close to the data – in the storage itself – where it can consistently prevent attackers from decrypting files, even if EDR has been bypassed.”
Cigent already offers a Secure SSD line that protects data through full-disk encryption and supports multi-factor authentication, while the company sells a Data Defense Software as a Service (SaaS) platform for protecting data on endpoint systems.
We asked Professor Bernard van Gastel of the Institute of Computer and Information Sciences in Nijmegen, the Netherlands, how likely he thinks it would be to create something like this.
Professor van Gastel told us he could answer “from a conceptual point of view” and added: “For something like this to be functional, you need to (1) properly detect ransomware and (2) have effective measures in place to act on it.”
“For the first, you can detect patterns in how a drive. If all the data is overwritten, that’s an indication that ransomware is active. You can even detect it early, if a significant chunk of data to the drive in a few minutes. But as with all these detection mechanisms (like spam, intrusion detection, etc.), there needs to be a proper calibration of false negatives and false positives. A false positive means that data is locked and the system will experience downtime. A false negative means that ransomware can actually work.”
“For the second, you have to ‘fix’ the contents of the drive,” the professor added. “At least make sure that no additional data. But there may already be data loss, because detection is always done ‘after the fact.’”
He said the company itself points this out “in point 3 under ‘Some Important Notes’ in its data sheet. So it’s not complete protection, because there can be false negatives and it can show up very late, so some damage has already been done. And it can cost you the availability of systems because of false positives.”
Professor van Gastel warned that: “In the end, you still need high-quality backup and recovery processes. So I wouldn’t consider such a new approach as a bulletproof solution to the ransomware problem. But we live in an imperfect world, in which backup and recovery processes often don’t work as they should. Therefore, this kind of ransomware detection on a disk can work and I see it helping organizations in practice.”
Brian Honan of BH Consulting echoed this note of caution, saying: “I have to say that I am skeptical of these claims, particularly that the act of encrypting data as part of a ransomware attack is the final step in a long chain of events. Before that happens, systems have already been compromised and your data may have been compromised.”

Service connection
It appears that the Secure SSD+ is actually designed to work with the Data Defense platform, as the company believes this allows it to initiate a company-wide data lockdown in response to ransomware detection.
This activates a “Shields Up” state that requires multi-factor authentication to access all protected files, Cigent said. The drive itself can optionally be put into a read-only mode to protect data from modification, deletion or encryption.
Cognet told The Register that each Secure SSD+ includes a client license for Cognet Data Defense software.
Meanwhile, the Data Defense SaaS platform allows IT and security staff to monitor and manage disks, set policies, reset PINs and receive ransomware alerts, Cigent said.
It can also be used to manage Data Defense software on the rest of the organization's computers and enable "Shields Up" mode to protect them from ransomware, even if they don't have a Secure SSD+ drive.
The Secure SSD+ is said to have safeguards against disabling security checks, specifically a built-in “storage firmware heartbeat” that detects if the Cigent software is disabled. Access to protected data is blocked in this case, we were told.
Planned updates are going to include features that prevent cloning, erasing, or accessing the drive if the system is booting from another disk.
Cigent CEO and co-founder John Benkert is a veteran of USAF Intelligence and the NSA, according to the company's website, and also the CEO of data recovery equipment maker CPR Tools. The company serves both commercial and public organizations, including government agencies.
We asked Cigent for more details about the Secure SSD+ and its built-in processing. The company told us that it uses a dedicated MCU (microcontroller unit) to inspect low-level telemetry data from the SSD controller, analyzing it with machine learning algorithms for signs of ransomware activity.
The MCU is separate from the SSD controller, but connects to it via a dedicated communication bus that is separate from the data pathway. This design is intended to ensure that the drive can maintain its performance, Cigent notes.
By analyzing the stored telemetry outside of the SSD controller, it is claimed that there is almost no impact on normal read/write operations
However, the product data sheet doesn't contain many specifications, as it doesn't mention exact read/write performance. Cigent confirmed that the drives will be available in 480GB, 960GB, and 1920GB capacities when they're ready to ship, which will be sometime in May 2023.
The data sheet reveals that the Secure SSD+ ships in a double-sided M.2 2280 form factor, meaning it is 22mm wide and 80mm long and may not fit in some ultra-thin laptops.
Professor Alan Woodward, a computer scientist at the University of Surrey and a security expert, told us that this device seems like an exciting idea, but it raises a lot of questions.
Cigent claims that its machine learning algorithms are proven to provide protection against even newer ransomware , while detection sensitivity can be dynamically adjusted to reduce false positives.
The Data Sheet also specifies that the Secure SSD+ must be installed as a boot drive on an endpoint system and support currently only includes Windows , but Linux support will be available soon.
Drives that incorporate some processing capability in this way are sometimes considered an emerging field labeled Computational Storage. A typical example is Samsung. Such devices may incorporate a CPU, FPGA, or ASIC to provide acceleration of certain storage functions, such as compression, decompression, or erasure coding.
Information source: theregister.com
