Access control based on classification of altered data

By classifying data sensitivity and generating access control rules, the problem of data leakage in ransomware attacks is solved, and effective protection of data is achieved to prevent unauthorized access and leakage.

CN120354442APending Publication Date: 2025-07-22HEWLETT PACKARD ENTERPRISE DEV LP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410912671.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-01-22
Filing Date
2024-07-09
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

Existing ransomware protection systems cannot prevent attackers from leaking data after detecting data encryption, resulting in the risk of data sensitive information that cannot be effectively prevented.

Method used

By classifying the data to identify sensitive data and generating access control rules based on the sensitivity level, unauthorized data access is prevented and data breaches are prevented.

Benefits of technology

It effectively prevents unauthorized access and leakage of data in ransomware attacks, enhances data security, and reduces the impact of ransomware attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120354442A_ABST
    Figure CN120354442A_ABST
Patent Text Reader

Abstract

The invention relates to access control based on classification of altered data. In some examples, a replication manager detects altered data caused by an input / output (I / O) operation, where the replication manager is to copy data writes of the I / O operation to a storage system. A classifier classifies the altered data to identify a sensitivity of the altered data. The system determines an access control rule for a data object including the altered data based on the identified sensitivity of the altered data. The system performs access control of the data object based on the determined access control rule.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] Ransomware attacks involve encrypting data on a single computer or multiple computers connected via a network. In a ransomware attack, encryption keys can be used to encrypt the data, making it inaccessible to the user without paying a ransom to obtain the encryption keys. Ransomware attacks can cause significant damage to businesses, including commercial companies, government agencies, educational organizations, individuals, etc. Brief Description of the Drawings

[0002] Some embodiments of the present disclosure are described with reference to the following drawings.

[0003] Figure 1 is a block diagram of a computing arrangement including a computer system and an access security system according to some examples.

[0004] Figure 2 is a flowchart of a process for preventing data leakage according to some examples.

[0005] Figure 3 is a block diagram of a storage medium storing machine-readable instructions according to some examples.

[0006] Figure 4 is a block diagram of a system according to some examples.

[0007] Figure 5 is a flowchart of a process according to some examples.

[0008] In all the drawings, like reference numerals refer to similar but not necessarily identical elements. The drawings are not necessarily to scale, and the dimensions of some parts may be enlarged to more clearly illustrate the examples shown. Additionally, the drawings provide examples and / or embodiments consistent with the description; however, the description is not limited to the examples and / or embodiments provided in the drawings. Detailed Description

[0009] Double-extortion ransomware attacks may leak the victim's data and additionally encrypt the data. Then, the attacker demands a ransom in exchange for the encryption key to decrypt the encrypted data. The attacker also threatens to publicly disclose the data if the ransom is not paid. As a result, even if the victim can recover the encrypted data from a data backup system, the threat of publicly disclosing the data (some of which may be sensitive or confidential) may be sufficient to prompt the victim to pay the ransom.

[0010] Some ransomware protection systems may be able to detect a ransomware attack based on detecting that unauthorized data encryption is occurring. However, when a ransomware attack is detected based on detecting data encryption, the attacker may have obtained (exfiltrated) data that could be publicly exposed. It should be noted that the attacker's exfiltration of data occurs before the attacker encrypts the data. Therefore, a ransomware protection system or technology that detects a ransomware attack and is able to recover the original data does not prevent the attacker from exfiltrating data.

[0011] According to some embodiments of the present disclosure, a data protection system can prevent unauthorized access to data (e.g., as part of a ransomware attack or any other type of unauthorized access) by: classifying the data to identify sensitive data; and generating access control rules based on the identified sensitive data to prevent the leakage of sensitive data. In some examples of the present disclosure, a replication manager detects changed data caused by one or more input / output (I / O) operations. The replication manager is responsible for writing the data of the I / O operation to a replicated target storage structure. The data protection system classifies the changed data to identify the sensitivity of the changed data, and determines access control rules for a data object (e.g., a file, an image, a video, or any other data container) including the changed data based on the identified sensitivity of the changed data. The access control rules can be used to prevent data leakage. As an example, the access control rules can prevent certain types of users from accessing the data, so that unauthorized users will not be able to access the data (which prevents data leakage). As a further example, the access control rules can limit access to requests originating from certain programs, machines, or networks.

[0012] As used herein, data “exfiltration” can refer to any unauthorized obtaining of data, such as through a ransomware attack or any other form of unauthorized activity. “Changed data” can refer to new data written to a data store, or modified data that updates existing data in a data store, or deleted data that removes data from a data store. The “sensitivity” of data can refer to the level of risk or harm that the exposure of the data may cause to the owner or manager of the data.

[0013] Figure 1 is a block diagram of an example arrangement including a computer system 102 and an access security system 104. Examples of computer systems can include any one or some combination of the following: a collection of computers (e.g., server computers, desktop computers, laptop computers, tablet computers, or other types of computers), a collection of smartphones, a collection of Internet of Things (IoT) devices, a collection of household appliances, a collection of vehicles, a collection of gaming devices, or a collection of other types of electronic devices. As used herein, a “collection” of items can refer to a single item or multiple items.

[0014] As further discussed below, in the example of Figure 1 Computer system 102 includes a data replication manager 118 and a sensitive data classifier 130. The data replication manager 118 and the sensitive data classifier 130 may be implemented using the hardware processing circuitry of computer system 102 or as machine-readable instructions executable on the processing resources of computer system 102. Although Figure 1 the data replication manager 118 and the sensitive data classifier 130 are shown as part of computer system 102, in other examples, the data replication manager 118 and / or the sensitive data classifier 130 may be external to computer system 102.

[0015] Computer system 102 may store data in a storage system 106 coupled to computer system 102. The storage system 106 may be part of computer system 102 or may be external to computer system 102. The storage system 106 may be implemented using a collection of storage devices. Examples of storage devices may include any one or some combination of the following: disk-based storage devices, solid-state drives, or other types of storage devices.

[0016] An access security system 104 enforces access control over data associated with computer system 102 (e.g., data in storage system 106) for a remote requester such as requester 150. Requester 150 may refer to a person, a program, or a machine.

[0017] Although Figure 1 only one computer system 102 is depicted in

[0018] In some examples, computer system 102 executes one or more programs (including machine-readable instructions) that may perform data transactions for reading and writing data in storage system 106. Examples of programs may include virtual entities such as a virtual machine (VM) 108. A VM refers to a virtualized computing environment that emulates a physical computing environment. A guest operating system (OS) and one or more applications may execute within VM 108.

[0019] In other examples, other virtual entities executable within computer system 102 may include containers, which are isolated computing environments in which applications may execute. In further examples, the virtualized computing environment is not implemented within computer system 102; in such examples, programs may execute in an environment provided by a host OS (not shown) of computer system 102.

[0020] In an example where VM 108 is executing in computer system 102, there is also a hypervisor 110 in computer system 102. The hypervisor is also known as a virtual machine monitor (VMM). The hypervisor 110 creates and controls the execution of VM 108. The hypervisor 110 is also responsible for presenting to each of the VMs 108 emulated instances of the physical resources (e.g., processing resources, storage resources, communication resources, or other resources) of computer system 102.

[0021] More generally, hypervisor 110 is an example of a virtualization hypervisor running on computer system 102. Another example of a virtualization hypervisor is a container engine that can start and manage containers in computer system 102.

[0022] Some examples involving the use of VMs are described below. It should be noted that the techniques or mechanisms according to some examples of the present disclosure can be applied to other types of virtual entities (such as containers), or to computer systems that do not implement a virtualized computing environment.

[0023] In Figure 1 the example, VM 108 can perform a data transaction 112 on the data in storage system 106. The data transaction 112 can include reading and writing of data in storage system 106. The data transaction can be performed in response to a request issued by VM 108, where the request can include a read request, a write request, or more generally a request involving one or more data operations.

[0024] In some examples, hypervisor 110 includes a driver 114 that can split data transaction 112 into block I / O operations 116. A "driver" can refer to a program that manages access to storage system 106. In other examples, the driver can be part of a container engine or the host OS of computer system 102.

[0025] A block I / O operation refers to a data operation on a data block, where the data block has a specified size (e.g., 16 megabytes or a different size). Each block I / O operation can read a data block from storage system 106 or write a data block to that storage system. In response to a request from VM 108 for data transaction 112, driver 114 generates block I / O operations 116 to read and / or write data blocks of storage system 106.

[0026] Changed data classification

[0027] The data replication manager 118 monitors block I / O operations 116 provided by the driver 114. The block I / O operations 116 can include write operations (referred to as "write block I / O operations") and read operations (referred to as "read block I / O operations"). The data replication manager 118 is capable of detecting write block I / O operations within the block I / O operations 116. Each block I / O operation has an indicator as to whether the block I / O operation is a read operation or a write operation. The data replication manager 118 uses this indicator to determine whether any given block I / O operation involves reading or writing of data.

[0028] The data replication manager 118 manages the replication of data writes to a target storage structure. The "replication" of a data write can refer to providing a representation of a write I / O operation (or more specifically, a write block I / O operation) that writes data to a storage system such as the storage system 106 (or more specifically, to a data block in the storage system). The representation of the write I / O operation can include the changed data (new data or modified data or deleted data) being written to the storage system. The representation of the write I / O operation can also include information about the type of write operation (such as an insert operation that adds new data, or an update operation that updates data, or a delete operation that deletes data).

[0029] The "target storage structure" to which the representation of the write I / O operation is added for replicating the data write can refer to any persistent storage structure that can maintain its content when the computer system 102 is power cycled or reset. In some examples, the target storage structure is in the form of a log 120 stored in the persistent memory 122. Persistent memory refers to a memory that can maintain the data stored in the memory even when the memory is powered off. In some examples, the persistent memory 122 is implemented using a collection of persistent memory devices (such as flash memory devices, electrically erasable programmable read-only memory (EEPROM) devices, or other forms of non-volatile memory devices).

[0030] The log 120 generally refers to a record that maintains information about write I / O operations. In some examples, the log 120 does not store information about read I / O operations. The representation of the write I / O operations in the log 120 can be used to recover the written data in the event that the computer system 102 experiences a failure or the data in the storage system 106 is corrupted.

[0031] In other examples, the target storage structure to which the data writes are replicated can include remote replicated storage (such as a backup storage system) or any other type of storage.

[0032] In an example according to Figure 1 the log 120 includes a sequence of representations of write block I / O operations. Each representation of a write block I / O operation is depicted asFigure 1 Changed data instances (CDIs) in log 120. Each CDI in the CDI sequence (CDI1, CDI 2, …, CDI N, where N≥1) in log 120 includes a representation of a write block I / O operation.

[0033] According to some embodiments of the present disclosure, the sensitive data classifier 130 in the computer system 102 can be used to perform classification of the changed data in each CDI in log 120. In some examples, the sensitive data classifier 130 can be triggered to apply classification of the changed data in the CDIs in log 120 in response to the expiration of a timer. Alternatively, after the count of CDIs added to log 120 exceeds a specified threshold, the sensitive data classifier 130 can be triggered to apply classification of the changed data in the CDIs in log 120. In other examples, the sensitive data classifier 130 can be triggered in response to other events.

[0034] In some examples, the sensitive data classifier 130 can perform binary classification, where the changed data in the CDI is classified as sensitive or non-sensitive. In other examples, the sensitive data classifier 130 is capable of assigning the changed data of the CDI to one of multiple sensitivity levels, where each sensitivity level corresponds to a different sensitivity of the changed data.

[0035] More generally, the sensitive data classifier 130 is capable of assigning M (M≥2) sensitivity levels to the changed data in the CDI. If M = 2, the sensitivity levels include a first sensitivity level indicating that the changed data is non-sensitive (e.g., "0") and a second sensitivity level indicating that the changed data is sensitive (e.g., "1"). If M>2, the sensitivity levels include a first sensitivity level indicating that the changed data is non-sensitive (e.g., "0"), a second sensitivity level indicating that the changed data has a lower sensitivity (e.g., "1"), a third sensitivity level indicating that the changed data has a higher sensitivity (e.g., "2"), and further sensitivity levels (if applicable).

[0036] In some examples, the sensitive data classifier 130 can perform content-based analysis on the changed data in the CDI, which determines whether the changed data contains sensitive data. Examples of sensitive data can include a person's social security number or any other government-issued identifier, employee number, salary information, personal user information, content marked with certain labels (e.g., "proprietary" label, "confidential" label, "secret" label, etc.), and so on. It should be noted that some data may be more sensitive than other data. For example, a social security number may have a higher sensitivity level than a user's username.

[0037] Analyze the content of the changed data in the CDI based on content to identify whether there is sensitive data. The content-based analysis can employ heuristics that can produce solutions (e.g., approximate classification of sensitive data). Alternatively, the sensitive data classifier 130 can include a machine learning model that can be trained to classify the changed data to produce a classification result indicating whether the changed data includes sensitive data.

[0038] For each classification of the changed data in the CDI, the changed data classification result 134 output by the sensitive data classifier 130 is sent to the access security system 104. The changed data classification result 134 can be in the form of a message, an information element, or any other indicator of the sensitive data classification performed by the sensitive data classifier 130. Each changed data classification result 134 can include the classification result for the changed data in a single CDI or the changed data in multiple CDIs. The changed data classification result 134 can include an identifier associated with a given CDI (e.g., the data block number of the data block containing the changed data or any other identifier that differentiates one CDI from another) and the sensitivity level assigned by the sensitive data classifier 130 to the changed data in the given CDI. The changed data classification result 134 can also identify the category of the changed data. In an example where the changed data classification result 134 includes the classification results for multiple CDIs, the changed data classification result 134 can include the identifiers associated with the multiple CDIs and the sensitivity levels (and data categories) assigned to the corresponding changed data in the multiple CDIs. The changed data classification result 134 can also include other information discussed further below.

[0039] In other examples, instead of analyzing the changed data at the granularity of the CDI, the sensitive data classifier 130 can analyze a larger data object that contains the changed data of one or more CDIs (e.g., a file in a file system to which the changed data is to be written, or any other type of data object). The file system is used to organize and manage files in a storage system such as the storage system 106. Files can be stored in various directories of the file system. More generally, data can be stored in data objects, which can include files, images, videos, or any other type of data unit.

[0040] If the sensitive data classifier 130 has the ability to identify which larger data object the changed data of the CDI is a part of, the sensitive data classifier 130 can perform an analysis of the larger data object to determine whether the larger data object contains sensitive data. In such an example, the changed data classification result 134 sent from the sensitive data classifier 130 to the access security system 104 identifies a specific data object (e.g., the file name of a file or an identifier of another type of data object), the sensitivity level assigned by the sensitive data classifier 130 to the data object, and the category of the data object.

[0041] The following provides an example of how the sensitive data classifier 130 may be able to identify the file containing the changed data of the CDI. Specifically, the sensitive data classifier 130 may be able to perform a mapping between the block I / O operations represented by the CDI and the corresponding files.

[0042] The sensitive data classifier 130 may include a parser 132 that determines whether the block I / O operation is part of a file system operation. In different examples, the parser 132 may be separate from the sensitive data classifier 130. Determining whether the block I / O operation includes a file system operation may be done by the parser 132, which reads the prefix of the command specifying the block I / O operation to determine whether the prefix includes a command identifier for a file system operation (e.g., "FILE"). A "command" may refer to a signal, information element, message, or any other information specifying an I / O operation to be performed on the storage system 106.

[0043] If the parser 132 determines that the block I / O operation is part of a file system operation, the parser 132 may extract a set of attributes (single or multiple attributes) from the command for the block I / O operation. For example, the command may include delimiters that can be recognized by the parser 132 to extract the fields corresponding to the delimiters. A "delimiter" refers to an indication (e.g., a specified string or symbol) in the command that indicates separate fields in the command. The set of data fields may include an identifier of the file that is the subject of the block I / O operation. The set of data fields may also identify the directory to which the file belongs. The extracted information about the file may be provided by the parser 132 to the sensitive data classifier 130, which can then apply a sensitivity classification to the file.

[0044] Further details regarding mapping block I / O operations to files can be found in U.S. Patent Application No. 18 / 495,142, filed on October 26, 2023, entitled "Filesystem Operations in Storage Devices".

[0045] More generally, the parser 132 can read a portion of a command specifying a block I / O operation to determine whether the command includes an indication that the command is for an operation involving a data object. If so, the parser 132 can identify the data object based on further information in the command.

[0046] Access security based on sensitivity classification

[0047] The following describes how the access security system 104 processes the changed data classification result 134 from the sensitive data classifier 130. The access security system 104 can be implemented using one or more computers. In some examples, the access security system 104 can be part of a cloud computing environment, or a data center, or any other computing environment.

[0048] The access security system 104 includes an access control engine 140 and a memory 142. As used herein, "engine" can refer to one or more hardware processing circuits, which can include any one or some combination of a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or other hardware processing circuits. Alternatively, "engine" can refer to a combination of one or more hardware processing circuits and machine-readable instructions (software and / or firmware) executable on the one or more hardware processing circuits.

[0049] In some examples, the access control engine 140 can implement access control using a zero trust network access (ZTNA) model. With ZTNA, a requester (e.g., 150) is authenticated before access to data can be granted. If ZTNA is implemented, the access control engine 140 can perform authentication and authorization to authenticate the requester and authorize the requester's activities. In other examples, the access control engine 140 can employ other types of access control techniques.

[0050] The memory 142 can store various security policies 144. Different security policies can be applied to different scenarios, which can be based on one or more factors, including the sensitivity level of the changed data (changed data in the CDI set or changed data in a larger data object containing the changed data in the CDI set) and possibly additional factors such as any one or some combination of the following: the category of the changed data, the computing environment in which the data write is performed, the protocol employed, the identifier of the entity (e.g., VM, container, program, user, etc.) requesting the data write, the location of the entity requesting the data write, the time of the data write, or other factors.

[0051] Provide the sensitivity level of the changed data in the changed data classification result 134 received by the access control engine 140 from the sensitive data classifier 130. The category of the changed data may refer to the data type of the changed data, such as the following categories: basic personally identifiable information (PII), medical data, company confidential information, and so on.

[0052] The computing environment where data writing is performed may refer to a server computer, a virtualized computing environment, or any other type of computing environment. The computing environment can be identified by an identifier of the computing environment, such as an identifier of a server computer (e.g., a network address or other identifier), a VM identifier, or any other type of identifier.

[0053] Examples of protocols that can be adopted in data writing include any one or some combination of the following: Remote Desktop Protocol (RDP), File Transfer Protocol (FTP), Secure Shell (SSH) protocol, Hypertext Transfer Protocol (HTTP), or any other protocol.

[0054] In some examples, different security policies can be applied to different sensitivity levels, data categories, different computing environments, and / or different protocols. A security policy can include a set of conditions and a set of actions to be performed when the set of conditions applies. For example, a security policy can have the following form:

[0055] (1) If the sensitivity level is 1 [condition] and the data category is u [condition], then perform the access control action A [action];

[0056] (2) If the sensitivity level is 2 [condition] and the server is X [condition], then perform the access control action B [action];

[0057] (3) If the sensitivity level is 1 [condition] and the data category is v [condition] and FTP is used [condition], then perform the access control action C [action];

[0058] (4) If the sensitivity level is 3 [condition] and the server is Y [condition] and SSH is used [condition], then perform the access control actions D, E [action].

[0059] Security policy (1) specifies that if the classified changed data has a sensitivity level of 1 and the category of the changed data is data category u, access control action A is to be applied. Security policy (2) specifies that if the classified changed data has a sensitivity level of 2 and data writing occurs on server X, access control action B is to be applied. Security policy (3) specifies that if the classified changed data has a sensitivity level of 1, the category of the changed data is data category v, and the FTP protocol is used, access control action C is to be applied. Security policy (4) specifies that if the classified changed data has a sensitivity level of 3, data writing occurs on server Y, and the SSH protocol is used, access control actions D and E are to be applied.

[0060] "Access control action" refers to an action performed to control access to data in response to a data access request (such as data access request 152 from requester 150). For example, access control action A is an action to prevent non-admin users from downloading data. As another example, access control action B is an action to prevent non-admin users from reading and writing data. As a further example, access control action D prevents any user from writing to the data, and access control action E prevents non-admin users from reading the data.

[0061] The rule generator 148 can create access control rules 146 based on various security policies 144. In some examples, the rule generator 148 is part of the access control engine 140 (e.g., implemented using the hardware processing circuitry of the access control engine 140 or utilizing machine-readable instructions executed by the access control engine 140). In other examples, the rule generator 148 is separate from the access control engine 140. The access control rules 146 created by the rule generator 148 are stored in the memory 142.

[0062] In response to receiving the changed data classification result 134 from the sensitive data classifier 130, the rule generator 148 selects a given security policy from the security policies 144 in the memory 142 that applies to the conditions associated with the changed data classification result 134. The conditions can include any one or some combination of the following: the sensitivity level of the changed data, the category of the changed data, the computing environment where data writing is performed, the protocol employed, the identifier of the entity requesting data writing, the location of the entity requesting data writing, the time of data writing, or other factors. The changed data classification result 134 can include any one or some combination of the aforementioned information (e.g., sensitivity level, category, computing environment, protocol, requesting entity, requesting entity location, time, etc.) used by the rule generator 148 to determine which security policy applies.

[0063] Then, the rule generator 148 creates access control rules 146 based on the given security policy. "Creating" access control rules 146 based on security policy 144 can refer to generating access control rules 146 that include the actions of security policy 144. For example, the access control rule generated based on security policy (1) includes access control action A. As another example, the access control rule generated based on security policy (4) includes access control actions D and E.

[0064] The access control rules 146 are associated with corresponding data objects (e.g., files) in the storage system 106. For example, the access control engine 140 can maintain mapping information 149 that relates data objects to access control rules. In some examples, the changed data classification result 134 from the sensitive data classifier 130 can include an identifier of the data object associated with the changed data classification result 134. As discussed above, the parser 132 can map write block I / O operations to corresponding data objects. The access control rules 146 generated in response to the changed data classification result 134 are related in the mapping information 149 to the data object identified by the changed data classification result 134.

[0065] The access control engine 140 uses the applicable access control rules 146 to process a data access request (e.g., 152) from a requester (e.g., 150) for a given data object. The access control engine 140 determines whether to grant or deny the data access request 152 based on the applicable access control rules. If the data access request 152 is granted, the access control engine 140 allows the data access request 152 to be passed to the computer system 102 that performs a data transaction based on the data access request 152.

[0066] However, if the data access request 152 is denied based on the applicable access control rules, the access control engine 140 prevents the data access request 152 from being passed to the computer system 102 and can directly discard the data access request 152. The access control engine 140 provides a data access response 154 to the requester 150, where if the access control engine 140 grants the data access request 152, the data access response 154 can include a successful result of the data access request 152, or if the access control engine 140 denies the data access request 152, the data access response 154 can include a failure indication of the data access request 152.

[0067] The applied access control rule 146 can prevent attempts to disclose data objects, such as data objects stored in the storage system 106. The applied access control rule 146 can also prevent data encryption, such as by blocking data writes. In this way, data security is enhanced, and ransomware attacks or other forms of attacks can be blocked or are less likely to succeed.

[0068] Further examples

[0069] Figure 2 is a flowchart of a process performed by the data replication manager 118, the sensitive data classifier 130, and the access control engine 140 according to some examples. Although Figure 2 shows a particular order of tasks, in other examples, tasks can be performed in a different order, some tasks can be omitted, and other tasks can be added.

[0070] For example, the data replication manager 118 copies (at 202) write block I / O operations to the log 120 by adding the corresponding CDI to the log 120 ( Figure 1 ). When triggered, the sensitive data classifier 130 classifies (at 204) the changed data in the CDI (or alternatively, classifies the data object containing the changed data in the CDI).

[0071] The sensitive data classifier 130 outputs (at 206) the changed data classification result (e.g., Figure 1 134 in) to the access control engine 140. The changed data classification result 134 can include the classification result for the changed data in the CDI or the changed data in the data object. The changed data classification result 134 can include an identifier associated with a given CDI (or data object) and a sensitivity level assigned by the sensitive data classifier 130 to the changed data. The changed data classification result 134 can also identify the category of the changed data.

[0072] The rule generator 148 in the access control engine 140 selects (at 208) a security policy (from a plurality of security policies 144) based on conditions applicable to the received changed data classification result 134. As described above, the conditions can be based on any one or some combination of the following factors: the sensitivity level of the changed data, the category of the changed data, the computing environment in which the data write is performed, the protocol employed, the identifier of the entity requesting the data write, the location of the entity requesting the data write, the time of the data write, or other factors. Thus, the selected security policy is a security policy that includes conditions applicable to the received changed data classification result 134.

[0073] Based on the selected security policy, rule generator 148 creates (at 210) an access control rule that includes the (multiple) access control actions of the selected security policy. Rule generator 148 saves (at 212) the access control rule in a memory (e.g., Figure 1 142 in). Rule generator 148 may also update mapping information 149 that associates the access control rule with a corresponding data object.

[0074] Access control engine 140 receives (at 214) a data access request such as from a requester (e.g., Figure 1 150 in). Access control engine 140 selects (at 216) an access control rule to apply based on the data object sought by the data access request. For example, access control engine 140 may access mapping information 149 to determine which access control rule applies to the data object. Access control engine 140 determines (at 218) whether to grant or deny the data access request based on the selected access control rule.

[0075] In some examples, the classification of sensitive data and the generation of access control rules for sensitive data may be performed "in real time", i.e., at the time when an I / O operation for writing data to a storage system is occurring. Performing the classification of sensitive data and the generation of access control rules "in real time" is contrasted with an offline process in which the classification of sensitive data and the generation of access control rules are performed some time after the data write has occurred. Such an offline process may not prevent data leakage because an attack may have occurred by the time the offline process is executed. Generating access control rules in real time may allow attempts at data leakage to be blocked.

[0076] Figure 3 is a block diagram of a non-transitory machine-readable or computer-readable storage medium 300 that stores machine-readable instructions that, when executed, cause a system to perform various tasks. For example, the system may include Figure 1 computer system 102 and access security system 104 of.

[0077] The machine-readable instructions include changed data detection instructions 302 for detecting changed data caused by an I / O operation using a replication manager. The replication manager writes a copy of the data of the I / O operation to a storage system. An example of a replication manager is Figure 1 data replication manager 118. Detection of changed data may be based on identifying write I / O operations in a sequence of I / O operations (e.g., Figure 1 block I / O operation 116 in).

[0078] The machine-readable instructions include sensitivity classification instructions 304 for classifying the changed data to identify the sensitivity of the changed data. For example, sensitivity classification instructions 304 may beFigure 1 as part of the sensitive data classifier 130. For example, classifying changed data may refer to classifying the changed data in one or more CDIs of the log 120, or classifying a data object (e.g., a file) that contains the changed data.

[0079] The machine-readable instructions include access control rule determination instructions 306 for determining an access control rule for a data object that includes changed data based on the identified sensitivity of the changed data. For example, the access control rule may be generated by Figure 1 the rule generator 148. The generated access control rule may be further based on one or more other factors.

[0080] The machine-readable instructions include access control instructions 308 for performing access control on the data object based on the determined access control rule. For example, the access control instructions 308 may be Figure 1 part of the access control engine 140.

[0081] In some examples, classifying changed data includes identifying the sensitivity level of the changed data from a plurality of sensitivity levels. The identified sensitivity level may be for the changed data in one or more CDIs, or for a data object that contains the changed data.

[0082] In some examples, determining an access control rule for a data object is based on a security policy (e.g., Figure 1 144 in) for the identified sensitivity level. Different sensitivity levels are associated with different security policies related to access control.

[0083] In some examples, determining an access control rule for a data object is further based on the category of the changed data.

[0084] In some examples, determining an access control rule for a data object is further based on one or more additional factors selected from: an identifier of the computing environment, the protocol employed, an identifier of the entity requesting data write, the location of the entity requesting data write, or the time of data write.

[0085] In some examples, the security policy includes one or more conditions and one or more access control actions to be applied if the one or more conditions are met. Determining the access control rule includes including one or more access control actions in the access control rule.

[0086] In some examples, classifying changed data includes classifying a first data object that contains the changed data, wherein the identified sensitivity of the changed data is the sensitivity of the first data object.

[0087] In some examples, the machine-readable instructions cause I / O operations on changed data to be mapped to a first data object. The mapping can include reading a portion of a command that specifies a write I / O operation to determine that the command contains an indication that the command is for an operation involving a data object, and identifying the first data object based on further information in the command.

[0088] Figure 4 is a block diagram of a system 400 according to some examples. The system 400 includes processing resources 402, which include one or more hardware processors. The hardware processors can include a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or another hardware processing circuit.

[0089] The system 400 includes a storage medium 404 that stores machine-readable instructions executable by the processing resources 402 to perform various tasks. The machine-readable instructions in the storage medium 404 include write I / O copy instructions 406 for copying write I / O operations as an addition to a representation. For example, the representation can be in the form of CDIs added to Figure 1 a log 120.

[0090] The machine-readable instructions in the storage medium 404 include classification instructions 408 for classifying changed data in the representation using a classifier to identify a sensitivity level of the changed data in each respective write I / O operation in the write I / O operations. Classifying the changed data in the respective write I / O operations results in a sensitivity classification result.

[0091] The machine-readable instructions in the storage medium 404 include access control rule generation instructions 410 for generating a first access control rule for a first data object that contains changed data in a first write I / O operation among the write I / O operations. The first access control rule is based on a first sensitivity level assigned by the classifier to the changed data in the first write I / O operation. The first access control rule can also be based on other factors.

[0092] The machine-readable instructions in the storage medium 404 include access control instructions 412 for performing access control on the first data object based on the first access control rule.

[0093] Figure 5 is a flowchart of a process 500 according to some examples. For example, the process 500 can be performed by Figure 1 a data replication manager 118, a sensitive data classifier 130, and an access control engine 140.

[0094] Process 500 includes the copy manager copying (at 502) write I / O operations as changed data instances to a persistent record. The changed data instances among these changed data instances include the changed data of the write I / O operations. For example, an example of the persistent record is Figure 1 log 120 of

[0095] Process 500 includes the classifier classifying (at 504) the changed data in the changed data instances to assign a sensitivity level to the changed data in the changed data instances. The sensitivity level can include two or more sensitivity levels.

[0096] Process 500 includes selecting (at 506) a security policy based on the sensitivity level of the changed data assigned to the changed data instances among these changed data instances. The selected security policy can be further based on other factors. For example, the selection of the security policy can be performed by rule generator 148.

[0097] Process 500 includes creating (at 508) access control rules for a data object based on the sensitivity level assigned by the classifier, where the data object contains the changed data. For example, the creation of the access control rules can be performed by rule generator 148.

[0098] Process 500 includes performing (at 510) access control on the data object based on the access control rules. The access control is for a data access request received from a requester.

[0099] A storage medium (e.g., Figure 3 300 in or Figure 4 404 in) can include any one or some combination of the following: semiconductor memory devices, such as dynamic or static random access memory (DRAM or SRAM), erasable programmable read only memory (EPROM), EEPROM, and flash memory; magnetic disks, such as fixed disks, floppy disks, and removable disks; another magnetic medium, including magnetic tape; optical media, such as compact discs (CDs) or digital video discs (DVDs); or another type of storage device. It should be noted that the instructions discussed above can be provided on one computer-readable or machine-readable storage medium, or alternatively, can be provided on multiple computer-readable or machine-readable storage media distributed in a large system with potentially multiple nodes. Such one or more computer-readable or machine-readable storage media are considered to be part of an article (or article of manufacture). An article or article of manufacture can refer to any single manufactured component or multiple components. One or more storage media can be located in a machine running machine-readable instructions, or at a remote site from which the machine-readable instructions can be downloaded via a network for execution.

[0100] In this disclosure, unless the context clearly indicates otherwise, the use of the terms "a", "an", or "the" is intended to include the plural forms as well. Similarly, as used in this disclosure, the terms "includes", "including", "comprises", "comprising", "have", "having" specify the presence of the stated elements but do not preclude the presence or addition of other elements.

[0101] In the foregoing description, numerous details are set forth to facilitate an understanding of the subject matter disclosed herein. However, embodiments may be practiced without some of these details. Other embodiments may include modifications and variations of the details discussed above. The appended claims are intended to cover such modifications and variations.

Claims

1. A non-transitory machine-readable storage medium comprising instructions that, when executed, cause a system to perform the following operations: Detect changed data caused by input / output (I / O) operations using a copy manager, the copy manager being used to write data of I / O operations to a copy in a storage system; Classify the changed data to identify the sensitivity of the changed data; Determine access control rules for a data object including the changed data based on the identified sensitivity of the changed data; And Perform access control on the data object based on the determined access control rules.

2. The non-transitory machine-readable storage medium according to claim 1, wherein, Classifying the changed data includes identifying a sensitivity level of the changed data from a plurality of sensitivity levels.

3. The non-transitory machine-readable storage medium according to claim 2, wherein, Determining the access control rules for the data object is based on a security policy for the identified sensitivity level.

4. The non-transitory machine-readable storage medium according to claim 3, wherein, Different sensitivity levels are associated with different security policies related to access control.

5. The non-transitory machine-readable storage medium according to claim 3, wherein, Determining the access control rules for the data object is further based on the category of the changed data.

6. The non-transitory machine-readable storage medium according to claim 3, wherein, Determining the access control rules for the data object is further based on one or more additional factors selected from: an identifier of a computing environment, a protocol employed, an identifier of an entity requesting data write, a location of the entity requesting data write, or a time of data write.

7. The non-transitory machine-readable storage medium according to claim 3, wherein, The security policy includes one or more conditions and one or more access control actions to be applied if the one or more conditions are met, and wherein determining the access control rules includes including the one or more access control actions in the access control rules.

8. The non-transitory machine-readable storage medium according to claim 1, wherein, Classifying the changed data includes classifying a first data object containing the changed data, and the identified sensitivity of the changed data is the sensitivity of the first data object.

9. The non-transitory machine-readable storage medium according to claim 8, wherein, The instructions, when executed, cause the system to perform the following operations: Map the I / O operation that caused the changed data to the first data object.

10. The non-transitory machine-readable storage medium according to claim 1, wherein, The detecting of the changed data includes: Receiving, by the copy manager, a plurality of I / O operations; and Identifying the I / O operations among the plurality of I / O operations that perform data write.

11. The non-transitory machine-readable storage medium according to claim 10, wherein, The plurality of I / O operations include block I / O operations, and the data write performed by the identified I / O operations includes writing of data blocks.

12. The non-transitory machine-readable storage medium according to claim 11, wherein, The data write of the identified I / O operations is copied as a changed data instance to a log in a persistent memory.

13. The non-transitory machine-readable storage medium according to claim 12, wherein, Classifying the changed data includes classifying the changed data in the changed data instances in the log.

14. The non-transitory machine-readable storage medium according to claim 12, wherein, Each changed data instance in the changed data instances includes a representation of a data write.

15. A system, comprising: Processing resources; And A non-transitory storage medium storing instructions that can be executed by the processing resources to perform the following operations: Copy a write input / output (I / O) operation as a representation added to a record; Classify the changed data in the representation using a classifier to identify the sensitivity level of the changed data in each respective write I / O operation of the write I / O operations, and the classification of the changed data in the respective write I / O operations results in a sensitivity classification; Generate a first access control rule for a first data object that includes the changed data in a first write I / O operation of the write I / O operations, the first access control rule being based on a first sensitivity level assigned by the classifier to the changed data in the first write I / O operation; And Perform access control on the first data object based on the first access control rule.

16. The system according to claim 15, wherein The representation added to the representation in the record includes the changed data of the respective write I / O operations.

17. The system according to claim 15, wherein The instructions are executable by the processing resources to perform the following operations: Generate a second access control rule for a second data object that includes the changed data in a second write I / O operation of the write I / O operations, the second access control rule being based on a second sensitivity level assigned by the classifier to the changed data in the second write I / O operation; And Perform access control on the second data object based on the second access control rule.

18. The system according to claim 15, wherein, The instructions are executable by the processing resources to perform the following operations: Map the changed data in the first write I / O operation to the first data object based on the following operations: Read a portion of a command that specifies the first write I / O operation to determine that the command includes an indication that the command is for an operation involving a data object, and Identify the first data object based on further information in the command.

19. A method, comprising: A replication manager copies a write input / output (I / O) operation as a changed data instance to a persistent record, wherein the changed data in the changed data instance includes the changed data of the write I / O operation; A classifier classifies the changed data in the changed data instance to assign a sensitivity level to the changed data in the changed data instance; A system including a hardware processor selects a security policy based on a sensitivity level of first changed data assigned by the classifier to a first changed data instance in the changed data instance; The system creates an access control rule for a data object based on the sensitivity level assigned by the classifier, wherein the data object includes the first changed data; and The system performs access control on the data object based on the access control rule.

20. The method of claim 19, comprising: Map the first changed data to the data object based on the following operations: Read a portion of a command that specifies a write I / O operation involving the first changed data to determine that the command includes an indication that the command is for an operation involving a data object, and Identify the data object based on further information in the command.

Citation Information

Patent Citations

  • Filesystem operations in storage devices

    US12314589B2