Storage access monitoring method and storage access monitoring device
The storage access monitoring method detects ransomware by analyzing volume operations for abnormal patterns, ensuring early detection and prevention of data breaches, even without endpoint software, thus enhancing security and reducing costs.
Patent Information
- Application Number
- JP2025036547
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-24
- Filing Date
- 2025-03-07
- Publication Date
- 2025-11-06
AI Technical Summary
Existing methods for detecting ransomware attacks are ineffective against unknown patterns, require endpoint software updates, and fail to prevent data encryption and theft, especially when endpoints lack proper security measures.
A storage access monitoring method that analyzes operational status of volumes in a storage device, comparing current and historical data to detect abnormal behavior indicative of ransomware, even without endpoint software, and outputs an alert.
Early detection of ransomware infections prevents data encryption and theft, minimizing business disruption and reducing operational costs by centralizing security monitoring across multiple endpoints.
Smart Images

Figure 2025166787000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a storage access monitoring method and a storage access monitoring device, and more particularly to a storage access monitoring method and a storage access monitoring device that enable detection of abnormal behavior in storage access caused by ransomware. [Background technology]
[0002] Ransomware is known as one of the methods of cyber attacks that has rapidly increased in recent years. Ransomware is malware that invades systems and encrypts or extracts data without permission. Data encrypted by ransomware becomes unusable, and a ransom is sometimes demanded to decrypt it. In addition, ransomware may threaten to make the data extracted public. For this reason, it is important to strengthen security to prevent ransomware attacks, and in the unlikely event that a system is infected with ransomware, to detect the ransomware attack early, before large-scale data encryption or extraction occurs.
[0003] Traditionally, ransomware attacks have been discovered by users, by security software, or by security operations centers (SOCs), but these traditional methods can lead to delayed detection of ransomware attacks, which can slow down the initial response time and cause the damage to spread.
[0004] The typical way to deal with a ransomware attack is to recover from backed-up data. However, identifying data from multiple backups that was not contaminated by ransomware requires examining the data chronologically, which can be time-consuming.
[0005] If you realize too late that your data has been encrypted by ransomware, there may no longer be uncontaminated backup data, which could require a huge amount of time and effort to recover, making data recovery impossible.
[0006] A known first countermeasure against conventional ransomware is to use endpoint virus checking software, such as a virus check function installed on a personal computer (PC). This first countermeasure allows the endpoint virus checking software to detect and remove ransomware intrusions, preventing ransomware intrusions and data encryption caused by attacks in advance.
[0007] A second countermeasure against traditional ransomware is to store backup data in a location that cannot be accessed from the outside (a vault area), thereby protecting the data from encryption and exploitation by ransomware in the unlikely event of a data loss. This second countermeasure is adopted by many storage vendors.
[0008] Furthermore, the technology disclosed in Patent Document 1 below is known as a third countermeasure against conventional ransomware. Patent Document 1 discloses a ransomware detection method executed by a computer. The ransomware detection method disclosed in Patent Document 1 periodically monitors a file access log, and if the frequency of file accesses typically performed by ransomware among the records of authorized file accesses exceeds a predetermined threshold, it determines that there is a possibility of a ransomware attack and takes countermeasures. The countermeasures include sending a command to a file access control means to block file access. [Prior art documents] [Patent documents]
[0009] [Patent Document 1] International Publication No. 2019 / 073720 Summary of the Invention [Problem to be solved by the invention]
[0010] However, the virus checking software used in the first measure above detects patterns that represent the characteristics of viruses and ransomware. Therefore, while it is effective against known ransomware, it cannot detect ransomware with patterns that represent unknown characteristics, and therefore has the problem of not being able to prevent ransomware attacks.
[0011] The first measure above also requires that virus check software be running on all endpoints connected to the network. Therefore, if there are endpoints that do not have virus check software running or that have not been properly updated with the latest pattern files, there is a problem in that even known ransomware may be able to infiltrate and launch attacks.
[0012] In the case of storing backup data in a Vault area, as in the second measure above, if the data before being stored in the Vault area has already been encrypted by ransomware, the ransomware-encrypted data will be stored in the Vault. Therefore, when recovery using backup data in the Vault area is actually required, there is still the issue that it takes time to identify data from a point in time that was not contaminated by ransomware. In addition, the second measure above cannot prevent ransomware attacks themselves, and in particular, it has the issue of not being able to deal with data theft by ransomware.
[0013] The third measure above requires monitoring endpoint file access logs. Similar to the virus check software in the first measure, the third measure requires that the file access log generation function be operating normally on all endpoints connected to the network. Therefore, if there are endpoints whose file access log generation function is not operating normally, or if ransomware causes the file access log generation function to stop or the logs to be tampered with, the ransomware cannot be detected, and ransomware attacks cannot be prevented.
[0014] The present invention has been made in consideration of the above-mentioned problems, and aims to provide a storage access monitoring method and storage access monitoring device that, by monitoring access to a storage device, makes it possible to detect ransomware infection at an endpoint early and prevent data encryption and data exploitation, even if sufficient ransomware countermeasures are not implemented at the endpoint. [Means for solving the problem]
[0015] In order to achieve the above object, a storage access monitoring method according to the present invention is a storage access monitoring method implemented by a computer, and includes an operation information acquisition step of acquiring, as operation information, the operation status of a volume constituting a storage apparatus from which a host device can read / write data via a network; a ransomware operation determination step of determining whether or not there is a possibility that ransomware is operating in the host device based on the operation information of the volume; and an abnormality report notification step of outputting an abnormality report if there is a possibility that the ransomware is operating, wherein the ransomware operation determination step compares the latest operation information with past operation information to determine whether or not there is a possibility that the ransomware is operating in the host device. The method includes a comparative analysis step of determining that behavior related to operation information is abnormal; a pattern comparison step of determining that behavior related to the latest operation information is abnormal by determining whether or not there is a behavior pattern in the latest operation information that may be influenced by the ransomware; and a trend comparison step of determining that behavior related to the latest operation information is abnormal by determining whether or not the behavior related to the latest operation information is different from normal behavior related to the past operation information, and is characterized in that if it is determined that behavior related to the latest operation information is abnormal in one or more of the comparative analysis step, the pattern comparison step, and the trend comparison step, it is determined that there is a possibility that the ransomware is operating in the host device.
[0016] According to the above process, by monitoring the operational status of the volumes that make up the storage device, it is possible to determine whether ransomware is running on a host device that accesses data stored in the storage device via a network. Therefore, even if the endpoint host device does not have virus checking software installed or is not updated with the latest pattern files, it is possible to grasp the security status of the host device and detect ransomware infection. Furthermore, even if there are multiple host devices, the storage access monitoring device can centrally monitor the security status, thereby improving security levels and reducing operational costs.
[0017] The above process monitors the operating status of volumes that make up a storage device and detects abnormal behavior, making it possible to detect ransomware infections with unknown characteristics that cannot be detected by conventional virus check software. Furthermore, because abnormal behavior that may be caused by ransomware can be detected early, data encryption and data theft by ransomware can be prevented early. Furthermore, data recovery can be performed quickly, minimizing the impact on business operations.
[0018] In the storage access monitoring method according to the present invention, in the above processing, the operation information may include the number of sequential reads, the number of sequential writes, the number of random reads, and the number of random writes for each logical unit of the volume, as well as the number of sequential reads, the number of sequential writes, the number of random reads, and the number of random writes for each logical block address of the logical unit.
[0019] According to the above process, by monitoring the operating status of the volumes that make up the storage device, such as the number of sequential reads, the number of sequential writes, the number of random reads, and the number of random writes for each logical unit of the volume, as well as the number of sequential reads, the number of sequential writes, the number of random reads, and the number of random writes for each logical block address of the logical unit, it is possible to determine whether ransomware is operating on the host device.
[0020] The storage access monitoring method according to the present invention may, in the above processing, include a ratio calculation step of calculating a read / write ratio which is the ratio between the sum of the number of sequential reads and the number of random reads and the sum of the number of sequential writes and the number of random writes, and a sequential / random ratio which is the ratio between the sum of the number of sequential reads and the number of sequential writes and the sum of the number of random reads and the number of random writes, and may determine in the comparison and analysis step that the read / write ratio for the latest operation information and the read / write ratio for the past operation information are reversed, and if it is determined that the sequential / random ratio for the latest operation information and the sequential / random ratio for the past operation information are reversed, it may be determined that the behavior related to the latest operation information is abnormal.
[0021] According to the above process, if the read / write ratio and the sequential / random ratio are reversed over time, it can be determined that ransomware is running on the host device.
[0022] The storage access monitoring method of the present invention, in the above processing, includes a file information acquisition step of acquiring information related to the reading / writing of files in the volume by the host device as file information, and a mapping step of mapping the file information with the logical block address of the logical unit, and if it is determined in the pattern comparison step that only the header portion of the file has been rewritten, it may be determined that the behavior related to the latest operation information is abnormal.
[0023] According to the above process, if behavior occurs in which only the header portion of a file is being rewritten, it can be determined that ransomware is running on the host device.
[0024] The storage access monitoring method according to the present invention may, in the above processing, comprise a statistical quantity calculation step of calculating an average value and a standard deviation value for the latest operation information and an average value and a standard deviation value for the past operation information, and may determine in the trend comparison step that the behavior of the latest operation information is abnormal if it is determined that the statistical distribution obtained from the average value and the standard deviation value for the latest operation information deviates beyond a predetermined condition from the statistical distribution obtained from the average value and the standard deviation value for the past operation information.
[0025] According to the above process, if the operating status of a volume deviates from normal operation that is not affected by ransomware, it can be determined that ransomware is running on the host device.
[0026] In the storage access monitoring method according to the present invention, in the above processing, if the numerical value of the average value ± standard deviation value for the latest operation information is outside the range determined by the average value ± 2 × standard deviation value for the past operation information, it may be determined that the behavior of the latest operation information is abnormal.
[0027] According to the above process, the average value and standard deviation value representing the operating status of the volume are calculated, and if the average value and standard deviation value exceed predetermined conditions, it can be determined that ransomware is operating on the host device.
[0028] The storage access monitoring method of the present invention may determine that there is a possibility that the ransomware is operating on the host device if, in the above processing, it is determined that the behavior related to the latest operating information is abnormal in all steps of the comparison analysis step, the pattern comparison step, and the trend comparison step.
[0029] According to the above process, if abnormal behavior is detected in all steps of the comparison analysis step, pattern comparison step, and trend comparison step, it is determined that ransomware is running on the host device, thereby reliably detecting cases where the impact of ransomware is more likely and reducing false positives.
[0030] In order to achieve the above object, the storage access monitoring device according to the present invention comprises an operation information acquisition unit that acquires, as operation information, the operation status of a volume that constitutes a storage device from which a host device can read / write data via a network; a ransomware operation determination unit that determines whether or not there is a possibility that ransomware is operating in the host device based on the operation information of the volume; and an abnormality report notification unit that outputs an abnormality report when there is a possibility that the ransomware is operating, and the ransomware operation determination unit compares the latest operation information with past operation information to determine that behavior related to the latest operation information is abnormal. a pattern comparison process for determining whether the latest operation information has a behavior pattern that may be influenced by the ransomware, thereby determining that the behavior related to the latest operation information is abnormal; and a trend comparison process for determining whether the behavior related to the latest operation information is different from the normal behavior related to the past operation information, thereby determining that the behavior related to the latest operation information is abnormal. When it is determined that the behavior related to the latest operation information is abnormal in one or more of the comparison analysis process, the pattern comparison process, and the trend comparison process, it is determined that the ransomware may be operating in the host device.
[0031] According to the above configuration, by monitoring the operational status of the volumes constituting the storage device, it is possible to determine whether ransomware is running on a host device that accesses data stored in the storage device via a network. Therefore, even if the endpoint host device does not have virus checking software installed or is not updated with the latest pattern files, it is possible to grasp the security status of the host device and detect ransomware infection. Furthermore, even if there are multiple host devices, the storage access monitoring device can centrally monitor the security status, thereby improving security and reducing operational costs.
[0032] The above configuration monitors the operating status of volumes that make up a storage device and detects abnormal behavior, making it possible to detect ransomware infections with unknown characteristics that cannot be detected by conventional virus check software. Furthermore, because abnormal behavior that may be caused by ransomware can be detected early, data encryption and data exploitation by ransomware can be prevented early. Furthermore, data recovery can be performed quickly, minimizing the impact on business operations. [Effects of the Invention]
[0033] The present invention has the advantage that by monitoring access to a storage device, ransomware infection at an endpoint can be detected early, preventing data encryption and data exploitation, and minimizing the impact on business operations, even if sufficient ransomware countermeasures are not implemented at the endpoint. The present invention also has the advantage of being able to detect infection by unknown ransomware at an early stage. [Brief explanation of the drawings]
[0034] [Figure 1] 1 is a system configuration diagram illustrating an example of a network system according to an embodiment of the present invention. [Figure 2] 1 is a functional block diagram illustrating an example of a configuration of a storage access monitoring device according to an embodiment of the present invention. [Figure 3] FIG. 10 is a diagram illustrating an example of a logical unit performance information management table according to the embodiment of the present invention. [Figure 4] FIG. 4 is a diagram illustrating an example of a file-specific operation information management table according to the embodiment of the present invention. [Figure 5] FIG. 4 is a flowchart showing an example of an operation of the storage access monitoring device according to the embodiment of the present invention. [Figure 6] FIG. 6 is a diagram showing the logical unit performance information management table updated in step ST2 of the flowchart shown in FIG. 5. [Figure 7] 6 is a diagram showing a file-specific operation information management table updated in step ST2 of the flowchart shown in FIG. 5. FIG. [Figure 8] 6 is a diagram showing a file-specific operation information management table updated in step ST3 of the flowchart shown in FIG. 5. FIG. [Figure 9] FIG. 6 is a diagram showing the logical unit performance information management table updated in step ST4 of the flowchart shown in FIG. 5. [Figure 10] 6 is a diagram showing an area of a logical unit performance information management table referenced in step ST5 of the flowchart shown in FIG. 5. FIG. [Figure 11] 6 is a diagram showing an area of a file-specific operation information management table referred to in step ST7 of the flowchart shown in FIG. 5. FIG. [Figure 12] FIG. 10 is a system configuration diagram showing an example of a network system in a first derivative example of an embodiment of the present invention. [Figure 13] FIG. 10 is a system configuration diagram showing an example of a network system in a second derivative example of the embodiment of the present invention. [Figure 14] FIG. 1 is a schematic block diagram showing an example of the configuration of a computer capable of executing processing in an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0035] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.
[0036] First, the system configuration of this embodiment will be described with reference to Fig. 1. Fig. 1 is a system configuration diagram showing an example of a network system according to this embodiment.
[0037] 1 is roughly composed of a host device 10 (hereinafter referred to as host 10), a storage device 30, and a storage access monitoring device 100. The host 10, the storage device 30, and the storage access monitoring device 100 can be connected to a network 50 such as the Internet.
[0038] The host 10 is an information terminal device such as a personal computer (PC) or tablet terminal that can be used by a user. The host 10 may also be a server device that manages each user's information terminal device as a client. The host 10 is configured to be able to access the storage device 30 via the network 50 and to read / write files stored in the storage device 30.
[0039] As shown in Figure 1, there may be multiple hosts 10. Multiple users may each own a host 10, or multiple users may share one host 10. However, there is no particular limit to the number of hosts 10, and there may be only one host 10. The host 10 may also be called a client computing device or an endpoint.
[0040] An agent 11 runs on the host 10. The agent 11 is a function that executes a specific task by executing an agent program on the host 10.
[0041] The agent 11 in this embodiment has a function of identifying files that the host 10 has accessed and read / written by accessing the storage device 30 on the network 50, and recording log information (e.g., information on the operation performed on the file and the date and time) relating to the reading / writing of files in the storage device 30 as file information. Furthermore, the agent 11 in this embodiment has a function of working in conjunction with the storage access monitoring device 100 to provide the storage access monitoring device 100 with the file information.
[0042] The storage device 30 has a data storage function for saving files. The storage device 30 in this embodiment operates as a network storage that can be accessed via a network 50. The host 10 can access the storage device 30 via the network 50 and read / write files stored in the storage device 30.
[0043] The storage device 30 provides a physical space for storing data and is configured with multiple volumes 40. A volume 40 is a logical area for storing data and is configured with multiple logical units (LU). Normally, one file is stored in one volume 40. FIG. 1 schematically illustrates a state in which each file is stored in each volume 40.
[0044] The storage access monitoring device 100 has a function of monitoring whether or not an abnormality has occurred in the behavior of each volume 40 managed by the storage device 30, based on the operating status of the storage device 30. In addition, if an abnormality has occurred in the behavior of each volume 40, the storage access monitoring device 100 has a function of notifying an administrator of an abnormality report. The storage access monitoring device 100 in this embodiment is configured to be able to detect abnormal behavior caused by the effects of ransomware.
[0045] The configuration of the storage access monitoring device 100 in this embodiment will be described with reference to Fig. 2. Fig. 2 is a functional block diagram showing an example of the configuration of the storage access monitoring device 100 in this embodiment.
[0046] 2 is mainly configured to include a processor 110, a communication interface (communication I / F) 120, an input / output interface (input / output I / F) 130, a memory 140, and a storage 150. The processor 110, the communication I / F 120, the input / output I / F 130, the memory 140, and the storage 150 are connected by a bus 160.
[0047] The processor 110 is a central processing unit (CPU) or the like, and has the function of performing control processing and arithmetic processing in the storage access monitoring device 100. The processor 110 executes various programs, thereby enabling the storage access monitoring device 100 to realize various functions corresponding to the various programs.
[0048] The communication I / F 120 has a function of communicating with various external devices via the network 50. The storage access monitoring device 100 in this embodiment is capable of acquiring the operating status of each volume 40 from the storage device 30 as operating information, and acquiring file information from the agent 11 of the host 10, via the communication I / F 120 and the network 50.
[0049] The input / output I / F 130 is an interface that can connect various devices that allow an operator to operate the storage access monitoring device 100. The input / output I / F 130 can be connected to a console that includes input devices such as a keyboard and a mouse, and output devices such as a display and a speaker.
[0050] The memory 140 is a main storage device available to the processor 110, and the storage 150 is an auxiliary storage device accessible to the processor 110. When the processor 110 executes various programs, the programs are stored in the memory 140. The processor 110 is also capable of processing various data stored in the storage 150. Figure 2 illustrates a state in which the processor 110 has read out various programs included in the system management application 200 and stored them in the memory 140, and a state in which the management table 300 is stored in the storage 150.
[0051] The system management application 200 executable by the processor 110 includes an operational information acquisition program 211, a management table update program 212, a file information acquisition program 213, a mapping program 214, a numerical analysis program 215, a comparative analysis program 216, a pattern comparison program 217, a trend comparison program 218, and an abnormality report output program 219.
[0052] The performance information acquisition program 211 is executed by the processor 110 of the storage access monitoring device 100, thereby implementing the function of an performance information acquisition unit in the storage access monitoring device 100. The performance information acquisition unit realized by the performance information acquisition program 211 has a function of periodically acquiring the performance status of each volume 40 of the storage device 30 as performance information.
[0053] The performance information acquired by the storage access monitoring device 100 includes an operation history of the host 10 accessing the storage device 30 and reading / writing data in each volume 40. Specifically, the performance information includes, for example, the number of inputs / outputs (I / O) within a unit time, I / O characteristics for logical units (LUs), and I / O characteristics for files (logical block addresses (LBAs)).
[0054] The number of I / Os per unit time is the number of reads / writes of data stored in each volume 40 per unit time. The unit time can be set appropriately depending on the load on the storage device 30 and the storage access monitoring device 100, etc. The unit time is the sampling time of the target data, and as an example, by setting the unit time to a short period (for example, about 1 second to 1 minute), behavioral abnormalities caused by the influence of ransomware can be discovered early. The time interval at which the storage access monitoring device 100 periodically obtains operation information from the storage device 30 may be the same as the unit time.
[0055] The I / O characteristics for a logical unit (LU) are the number of sequential reads / writes and the number of random reads / writes for each logical unit in each volume 40.
[0056] Here, sequential read / write and random read / write refer to methods of accessing data. Sequential read refers to a data access mode in which data is read sequentially. Sequential write refers to a data access mode in which data is written sequentially. Random read refers to a data access mode in which data is read randomly. Random write refers to a data access mode in which data is written randomly.
[0057] The number of sequential reads / writes per logical unit in each volume 40 is a value obtained by measuring the number of sequential reads and sequential writes per logical unit in each volume 40. The number of random reads / writes per logical unit in each volume 40 is a value obtained by measuring the number of random reads and random writes per logical unit in each volume 40. The number of sequential reads / writes and the number of random reads / writes per logical unit in each volume 40 can be expressed as a rate divided by unit time (for example, a rate per second).
[0058] The I / O characteristics for a file (logical block address (LBA)) are the number of sequential reads / writes and the number of random reads / writes for each logical block address in each volume 40.
[0059] The number of sequential reads / writes for each logical block address in each volume 40 is a value obtained by measuring the number of sequential reads and sequential writes for each logical block address in each volume 40. The number of random reads / writes for each logical block address in each volume 40 is a value obtained by measuring the number of random reads and random writes for each logical block address in each volume 40. The number of sequential reads / writes and the number of random reads / writes for each logical block address in each volume 40 can be expressed as a rate divided by unit time (for example, a rate per second).
[0060] The management table update program 212 is executed by the processor 110 of the storage access monitoring device 100, thereby implementing the function of a management table update unit in the storage access monitoring device 100. The management table update unit realized by the management table update program 212 has the function of reading and referencing the management table 300 stored in the storage 150, and writing information acquired or calculated by the storage access monitoring device 100 to the management table 300 to update it.
[0061] The file information acquisition program 213 is executed by the processor 110 of the storage access monitoring device 100, thereby implementing the function of a file information acquisition unit in the storage access monitoring device 100. The file information acquisition unit realized by the file information acquisition program 213 has the function of acquiring file information from the agent 11 of the host 10.
[0062] The mapping program 214 is executed by the processor 110 of the storage access monitoring device 100, thereby implementing the function of a mapping unit in the storage access monitoring device 100. The mapping unit realized by the mapping program 214 has the function of mapping file information acquired from the agent 11 of the host 10 with block addresses on each volume 40 of the storage device 30.
[0063] The numerical analysis program 215 is executed by the processor 110 of the storage access monitoring device 100, thereby implementing the function of a numerical analysis unit in the storage access monitoring device 100. The numerical analysis unit realized by the numerical analysis program 215 has the function of calculating numerical values such as ratios and statistics using the values stored in the management table 300.
[0064] The comparison analysis program 216 is executed by the processor 110 of the storage access monitoring device 100, thereby implementing the function of a comparison analysis unit in the storage access monitoring device 100. The comparison analysis unit realized by the comparison analysis program 216 has the function of comparing the operation information acquired from the storage device 30 with the operation information acquired previously, and checking for any abnormalities. The comparison analysis program 216 constitutes part of the ransomware operation determination program, and the comparison analysis unit realized by the comparison analysis program 216 constitutes part of the ransomware operation determination unit realized by the ransomware operation determination program.
[0065] The pattern comparison program 217 is executed by the processor 110 of the storage access monitoring device 100, thereby implementing the function of a pattern comparison unit in the storage access monitoring device 100. The pattern comparison unit realized by the pattern comparison program 217 has a function of checking whether or not there is a change pattern that is thought to be the influence of ransomware (i.e., an abnormal pattern that is different from normal) in the operation information acquired from the storage device 30. The pattern comparison program 217 constitutes a part of the ransomware operation determination program, and the comparison analysis unit realized by the pattern comparison program 217 constitutes a part of the ransomware operation determination unit realized by the ransomware operation determination program.
[0066] The trend comparison program 218 is executed by the processor 110 of the storage access monitoring device 100, thereby implementing the function of a trend comparison unit in the storage access monitoring device 100. The trend comparison unit realized by the trend comparison program 218 has a function of analyzing whether statistics calculated from operation information acquired from the storage device 30 show an abnormal trend compared to the statistics of operation information during normal operation. The trend comparison program 218 constitutes a part of the ransomware operation determination program, and the trend comparison unit realized by the trend comparison program 218 constitutes a part of the ransomware operation determination unit realized by the ransomware operation determination program.
[0067] The abnormality report output program 219 is executed by the processor 110 of the storage access monitoring device 100, thereby implementing the function of an abnormality report output unit in the storage access monitoring device 100. The abnormality report output unit realized by the abnormality report output program 219 has the function of outputting an abnormality report indicating that a behavior abnormality has occurred. The abnormality report may be notified through a console connected to the input / output I / F 130, or may be notified by email or the like to a specified email address.
[0068] The management tables 300 that the processor 110 can refer to and update include a logical unit performance information management table 400 and a file performance information management table 500 .
[0069] The logical unit performance information management table 400 will be described with reference to FIG. 3. FIG. 3 is a diagram showing an example of the logical unit performance information management table 400 in this embodiment. Note that, as an example, in FIG. 3, the logical unit performance information management table 400 is expressed as a tabular table in which rows (records) and columns are set, but this is not limiting and any data storage structure can be adopted. Furthermore, although only the columns used in this embodiment are shown in the logical unit performance information management table 400 shown in FIG. 3, other columns may also be set.
[0070] The logical unit performance information management table 400 shown in FIG. 3 stores performance information indicating the performance status of the storage device 30 as a data record (row) for each logical unit, and is also capable of storing numerical values calculated by executing the numerical analysis program 215.
[0071] The columns of the logical unit performance information management table 400 shown in FIG. 3 include a “logical unit name” column 401, an “acquisition date and time” column 402, an “acquisition data” column 410, and an “analysis” column 420.
[0072] The "logical unit name" column 401 stores logical unit identification information for identifying the logical unit of each volume 40. The "acquisition date and time" column 402 stores the date and time when the operating information of each logical unit was acquired.
[0073] The "obtained data" column 410 stores operational information for each logical unit of each volume 40 that constitutes the storage device 30. The "obtained data" column 410 includes a "number of sequential reads" column 411, a "number of sequential writes" column 412, a "number of random reads" column 413, and a "number of random writes" column 414.
[0074] The "Number of Sequential Reads" column 411 stores the number of sequential reads included in the acquired operational information. The "Number of Sequential Writes" column 412 stores the number of sequential writes included in the acquired operational information. The "Number of Random Reads" column 413 stores the number of random reads included in the acquired operational information. The "Number of Random Writes" column 414 stores the number of random writes included in the acquired operational information.
[0075] The analysis results for the acquired operational information are stored in the "Analysis" column 420. In the "Analysis" column 420, a "Sequential Read Statistics" column 430, a "Sequential Write Statistics" column 440, a "Random Read Statistics" column 450, and a "Random Write Statistics" column 460 are set.
[0076] The "Sequential Read Statistics" column 430 stores statistics calculated from the number of sequential reads, and is configured with an "Average" column 431 that stores the average value, and a "Standard Deviation" column 432 that stores the standard deviation value. The "Sequential Write Statistics" column 440 stores statistics calculated from the number of sequential writes, and is configured with an "Average" column 441 that stores the average value, and a "Standard Deviation" column 442 that stores the standard deviation value. The "Random Read Statistics" column 450 stores statistics calculated from the number of random reads, and is configured with an "Average" column 451 that stores the average value, and a "Standard Deviation" column 452 that stores the standard deviation value. The "Random Write Statistics" column 460 stores statistics calculated from the number of random writes, and is configured with an "Average" column 461 that stores the average value, and a "Standard Deviation" column 462 that stores the standard deviation value.
[0077] Furthermore, the "Analysis" column 420 contains a "Read / Write Ratio" column 470 and a "Sequential / Random Ratio" column 480. The "Read / Write Ratio" column 470 stores the ratio between the sum of the number of sequential reads and the number of sequential writes and the sum of the number of random reads and the number of random writes. The "Sequential / Random Ratio" column 480 stores the ratio between the sum of the number of sequential reads and the number of random reads and the sum of the number of sequential writes and the number of random writes.
[0078] The performance information is periodically acquired at predetermined time intervals. The performance information management table 400 for each logical unit stores the performance information and its analysis results as data records for each acquisition date and time.
[0079] The file-specific performance information management table 500 will be described with reference to FIG. 4. FIG. 4 is a diagram showing an example of the file-specific performance information management table 500 in this embodiment. Note that, as an example, in FIG. 4, the file-specific performance information management table 500 is expressed as a tabular table in which rows (records) and columns are set, but this is not limitative and any data storage structure can be adopted. Furthermore, although the file-specific performance information management table 500 shown in FIG. 4 shows only the columns used in this embodiment, other columns may also be set.
[0080] The file-specific operational information management table 500 shown in Figure 4 stores operational information indicating the operational status of the storage device 30 as a data record (row) for each block address, and is also able to store file information obtained from the agent 11 of the host 10 in association with each block address through mapping.
[0081] Each column of the file-specific operational information management table 500 shown in Figure 4 includes a "logical unit name" column 501, a "file name" column 502, an "LBA flag" column 503, a "block address" column 504, an "acquisition date and time" column 505, and an "acquisition data" column 510.
[0082] The "logical unit name" column 501 stores logical unit identification information for identifying the logical units of each volume 40. The logical unit identification information stored in the "logical unit name" column 501 is the same as the logical unit identification information stored in the "logical unit name" column 401 of the per-logical-unit performance information management table 400 shown in Fig. 3. The data records of the per-logical-unit performance information management table 400 and the data records of the per-file performance information management table 500 are associated with each other by the same logical unit identification information.
[0083] The "file name" column 502 and the "LBA flag" column 503 store file information obtained from the agent 11 of the host 10. The "file name" column 502 stores the file name identified from the file information. The "LBA flag" column 503 stores flag information ({Y} or "N") indicating whether or not an LBA is included. The LBA includes the header portion of the file, and when writing is performed on data with flag information of "Y," this means that the header portion of the file has been rewritten.
[0084] It should be noted that file information is not explicitly associated with block addresses in each volume 40. For this reason, file information acquired from the agent 11 of the host 10 is referenced, and it is determined by mapping which block address in which volume 40 the file information corresponds to, and then, based on the mapping results, the file information is stored in the "file name" column 502 and "LBA flag" column 503 of the data record for the corresponding block address.
[0085] The "block address" column 504 stores block address identification information for identifying the block address in each logical unit of each volume 40.
[0086] The "acquired date and time" column 505 and the "acquired data" column 510 store operational information for each logical unit of each volume 40 constituting the storage device 30.
[0087] The "acquisition date and time" column 505 stores the date and time when the operational information related to each block address of each logical unit was acquired.
[0088] The "obtained data" column 510 stores, for each block address, operational information for each logical unit of each volume 40 constituting the storage device 30. The "obtained data" column 510 includes a "number of sequential reads" column 511, a "number of sequential writes" column 512, a "number of random reads" column 513, and a "number of random writes" column 514.
[0089] The "Number of Sequential Reads" column 511 stores the number of sequential reads included in the acquired operational information. The "Number of Sequential Writes" column 512 stores the number of sequential writes included in the acquired operational information. The "Number of Random Reads" column 513 stores the number of random reads included in the acquired operational information. The "Number of Random Writes" column 514 stores the number of random writes included in the acquired operational information.
[0090] The operation information is periodically acquired at predetermined time intervals. The file-specific operation information management table 500 stores the operation information as data records for each acquisition date and time.
[0091] Next, the operation of the storage access monitoring device 100 will be described with reference to the flow diagram of Fig. 5. Fig. 5 is a flow diagram showing an example of the operation of the storage access monitoring device 100 in this embodiment. Note that the operation shown in Fig. 5 will be described with the various programs included in the system management application 200 as the subject of the operation, but the subject of the operation may be interpreted as the processor 110 that executes the various programs, or as the various functional units that are realized by executing the various programs on the processor 110.
[0092] The performance information acquisition program 211 of the storage access monitoring device 100 acquires performance information from the storage device 30 (step ST1). The performance information acquisition program 211 constantly monitors input / output (I / O, i.e., reading and writing) to and from each volume 40 of the storage device 30, and can acquire the monitoring results as performance information.
[0093] The performance information acquired from the storage device 30 by the performance information acquisition program 211 in step ST1 includes at least the following three types of performance information.
[0094] Number of I / Os per unit time (Read / Write values) I / O characteristics for logical units (LUs) (Sequential Read / Write, Random Read / Write values) I / O characteristics (Sequential Read / Write, Random Read / Write values) for files (logical block address (LBA))
[0095] The management table update program 212 of the storage access monitoring device 100 registers the operation information of the storage device 30 acquired in step ST1 in the management table 300 (step ST2). The processing of step ST2 corresponds to the operation information acquisition step according to the present invention.
[0096] Specifically, in the logical unit performance information management table 400, a new data record (row) is created corresponding to each logical unit identification information stored in the "logical unit name" column 401, the acquisition date and time of the performance information is added to the "acquisition date and time" column 402, and various performance information is registered in the "acquisition data" column 410.
[0097] In the logical unit performance information management table 400, the number of sequential reads is stored in the "Number of Sequential Reads" column 411, the number of sequential writes is stored in the "Number of Sequential Writes" column 412, the number of random reads is stored in the "Number of Random Reads" column 413, and the number of random writes is stored in the "Number of Random Writes" column 414.
[0098] 6 shows the logical unit performance information management table 400 updated in step ST2. In step ST2, the acquisition date and time and numerical values related to the current performance information (latest performance information) are added to each column in area R1 shown in FIG.
[0099] Specifically, in the file-specific operation information management table 500, a new data record (row) is created corresponding to each block address identification information stored in the "block address" column 504, the acquisition date and time of the operation information is added to the "acquisition date and time" column 505, and various operation information is registered in the "acquisition data" column 510.
[0100] The number of sequential reads is stored in the "Number of Sequential Reads" column 511, the number of sequential writes is stored in the "Number of Sequential Writes" column 512, the number of random reads is stored in the "Number of Random Reads" column 513, and the number of random writes is stored in the "Number of Random Writes" column 514.
[0101] 7 shows the file-specific operation information management table 500 updated in step ST2. In step ST2, the acquisition date and time and numerical values related to the current operation information (latest operation information) are added to each column in area R2 shown in FIG.
[0102] Next, the file information acquisition program 213 of the storage access monitoring device 100 acquires file information from the agent 11 of the host 10, the mapping program 214 performs mapping between the file in the storage device 30 identified by the file information and the block address of each volume 40, and the management table update program 212 adds it to the management table 300 (step ST3). Step ST3 corresponds to the file information acquisition step and mapping step of the present invention.
[0103] The file information acquisition program 213, in cooperation with the agent 11 of the host 10, can acquire file information indicating which files the host 10 has accessed and read / written by accessing each volume 40. The mapping program 214 can identify, from the file information acquired from the agent 11 of the host 10, the block address of the data read / written by the host 10, and perform mapping between the file in the storage device 30 and the block address of each volume 40. Based on the mapping results, the management table update program 212 registers the file name in the "file name" column 502 of the file-specific operational information management table 500, and also registers flag information ({Y} or "N") indicating whether or not an LBA is included in the "LBA flag" column 503.
[0104] 8 shows the file-specific operation information management table 500 updated in step ST3. In step ST3, the currently acquired file information is written into each column in area R3 shown in FIG.
[0105] The numerical analysis program 215 of the storage access monitoring device 100 calculates the average value and standard deviation of reads and writes for a logical unit (LU), the read / write ratio, and the sequential / random ratio from the performance information acquired from the storage device 30 in step ST1, and the management table update program 212 adds these to the management table 300 (step ST4). Step ST4 corresponds to the ratio calculation step and statistics calculation step according to the present invention.
[0106] Specifically, in the logical unit performance information management table 400, statistics are calculated using the number of sequential reads in the "Number of Sequential Reads" column 411, the number of sequential writes in the "Number of Sequential Writes" column 412, the number of random reads in the "Number of Random Reads" column 413, and the number of random writes in the "Number of Random Writes" column 414 stored in step ST2, and the calculation results are registered in the "Analysis" column 420.
[0107] The numerical analysis program 215 calculates the mean value and standard deviation value of the normal distribution from the number of sequential reads, and stores the calculated mean value and standard deviation value in the "mean value" column 431 and "standard deviation" column 432 of the "Sequential Read Statistics" column 430, respectively.
[0108] In addition, the numerical analysis program 215 calculates the mean value and standard deviation value of the normal distribution from the number of sequential writes, and stores the calculated mean value and standard deviation value in the “mean value” column 441 and “standard deviation” column 442 of the “Sequential Write Statistics” column 440, respectively.
[0109] In addition, the numerical analysis program 215 calculates the mean value and standard deviation value of the normal distribution from the random read count, and stores the calculated mean value and standard deviation value in the “mean value” column 451 and “standard deviation” column 452 of the “Random Read Statistics” column 450, respectively.
[0110] In addition, the numerical analysis program 215 calculates the mean value and standard deviation value of the normal distribution from the random write number, and stores the calculated mean value and standard deviation value in the “mean value” column 461 and “standard deviation” column 462 of the “Random Write Statistics” column 460, respectively.
[0111] The numerical analysis program 215 also calculates the ratio between the sum of the number of sequential reads and the number of random reads and the sum of the number of sequential writes and the number of random writes, and stores the calculated read / write ratio in the “Read / Write ratio” column 470 .
[0112] The numerical analysis program 215 also calculates the ratio between the sum of the number of sequential reads and the number of sequential writes and the sum of the number of random reads and the number of random writes, and stores the calculated sequential / random ratio in the “Sequential / Random ratio” column 480.
[0113] 9 shows the logical unit performance information management table 400 updated in step ST4. In step ST4, statistics calculated from the current performance information (latest performance information) are added to each column in area R4 shown in FIG.
[0114] Next, the storage access monitoring device 100 executes the following comparative analysis process, pattern comparison process, and trend comparison process. Each of the comparative analysis process, pattern comparison process, and trend comparison process described below determines whether or not there is a possibility that ransomware is operating in the host 10 based on the operation information of the volume 40. The operation information of the volume 40 is periodically acquired, and by determining whether or not the behavior related to the latest operation information is abnormal, it is possible to determine in real time whether or not there is a possibility that ransomware is operating in the host 10.
[0115] 5, the comparative analysis process, the pattern comparison process, and the trend comparison process are executed in this order, but these three processes may be executed in a different order, or may be executed in parallel. The following steps ST5 to ST10 correspond to the ransomware operation determination step according to the present invention.
[0116] The comparison and analysis program 216 of the storage access monitoring device 100 refers to the logical unit performance information management table 400, compares the latest performance information acquired this time with past performance information, and checks for any abnormalities (step ST5). As past performance information, for example, the immediately preceding performance information acquired previously is referenced.
[0117] The comparison analysis program 216 references the read / write ratio stored in the "Read / Write Ratio" column 470, and compares the newly added read / write ratio with the past read / write ratio. Specifically, area R5 shown in Fig. 10 is referenced. As the past read / write ratio, for example, the read / write ratio from the immediately previous time (the date and time immediately preceding) can be used.
[0118] The read / write ratio represents the balance between reads and writes. In this embodiment, if the balance between reads and writes has changed significantly compared to the immediately preceding operational information, more specifically, if the newly added read / write ratio and the previous read / write ratio have reversed (the magnitude relationship between the number of reads and the number of writes has reversed), it is determined that abnormal behavior is occurring due to the influence of ransomware.
[0119] Furthermore, the comparison analysis program 216 refers to the sequential / random ratio stored in the "Sequential / Random Ratio" column 480, and compares the newly added sequential / random ratio with the past sequential / random ratio. Specifically, area R6 shown in FIG. 10 is referenced. As the past sequential / random ratio, for example, the sequential / random ratio from the immediately previous time (the date and time one day before) can be used.
[0120] The sequential / random ratio represents the balance between sequential write / read and random write / read. In this embodiment, if the balance between sequential write / read and random write / read has changed significantly compared to the immediately previous operation information, more specifically, if the newly added sequential / random ratio and the previous sequential / random ratio have reversed (if the magnitude relationship between the sequential number and the random number has reversed), it is determined that abnormal behavior is occurring due to the influence of ransomware.
[0121] If an abnormality is confirmed in the comparative analysis process in step ST5, specifically, if it is confirmed that the newly added read / write ratio is reversed from the previous read / write ratio, or if it is confirmed that the newly added sequential / random ratio is reversed from the previous sequential / random ratio, the comparative analysis program 216 outputs the corresponding data as data indicating an abnormality ("YES" in step ST6). Note that the comparative analysis program 216 may also output the corresponding data as data indicating an abnormality if both a reversal of the read / write ratio and a reversal of the sequential / random ratio are confirmed. The above steps ST5 and ST6 correspond to the comparative analysis step according to the present invention.
[0122] The pattern comparison program 217 of the storage access monitoring device 100 refers to the file-specific operation information management table 500 and checks whether there is a change pattern (i.e., an abnormal pattern that is different from normal) that is thought to be the result of ransomware in the latest operation information acquired this time (step ST7).
[0123] The pattern comparison program 217 refers to the flag information stored in the "LBA flag" column 503 and checks whether or not flag information "Y" exists. Specifically, area R7 shown in FIG.
[0124] Flag information "Y" indicates that the header portion of the corresponding file has been rewritten. It is known that some ransomware behavior involves rewriting only the header portion of a file and encrypting the data. The pattern comparison program 217 references the operation information at the block address with flag information "Y" and the operation information at the block address with flag information "N" to further confirm whether or not any part other than the header portion of the file whose header portion has been rewritten has been rewritten. Specifically, the program references area R8 shown in FIG. 11. If only the header portion of the file has been rewritten, the program determines that the operation may be an abnormal pattern due to the influence of ransomware.
[0125] If an abnormal pattern is confirmed in the pattern comparison process in step ST7, the pattern comparison program 217 outputs the corresponding data as data that matches the abnormal pattern ("YES" in step ST8). The above steps ST7 and ST8 correspond to the pattern comparison step according to the present invention.
[0126] The trend comparison program 218 of the storage access monitoring device 100 analyzes the trend based on the average value and standard deviation value calculated from the latest operational information acquired this time, and checks whether the trend is clearly different from normal operation (step ST9).
[0127] The average values and standard deviation values stored in the "average value" column 431 and "standard deviation" column 432, "average value" column 441 and "standard deviation" column 442, "average value" column 451 and "standard deviation" column 452, "average value" column 461 and "standard deviation" column 462 calculated in step ST4 represent the normal distribution of the number of sequential reads, the normal distribution of the number of sequential writes, the normal distribution of the number of random reads, and the normal distribution of the number of random writes, respectively.
[0128] The standard deviation is information that serves as an index showing the dispersion of data and represents the spread of a statistical distribution (normal distribution). The trend comparison program 218 can determine whether the trend related to the current statistics deviates from the trend related to the statistics during normal operation by, for example, checking whether the statistical distribution based on the average value and standard deviation value related to the latest operation information acquired this time is significantly different from the statistical distribution obtained during normal operation. Specifically, the area R8 shown in FIG. 10 is referenced.
[0129] The trend during normal operation used as the judgment criterion can be arbitrarily determined from the average value and standard deviation value obtained in the past. For example, the trend during normal operation can be the statistical distribution obtained from the average value and standard deviation value obtained immediately before (the date and time one day before). Alternatively, the trend during normal operation can be the statistical distribution obtained from the average value and standard deviation value over a specified period in the past. The trend during normal operation represents the trend of the sequential read / write count, sequential read / write count, random read / write count, and random write count when there is no impact from ransomware.
[0130] The trend comparison program 218 uses the trend during normal operation as a reference and checks whether the average value and standard deviation value calculated from the latest acquired operational information deviate beyond a predetermined condition from the trend during normal operation. To determine whether there is a significant deviation from the statistical distribution representing normal operation, for example, if the current average value ± standard deviation value (σ) is outside the range determined by the average value during normal operation ± 2 × standard deviation value (2σ), it can be determined that the behavior is likely to be different from normal operation due to the influence of ransomware. Specifically, if the current value (average value - standard deviation value) is smaller than the (average value - 2 × standard deviation value) during normal operation, or if the current value (average value + standard deviation value) is larger than the (average value + 2 × standard deviation value) during normal operation, it can be determined that there is a possibility that the behavior is different from normal operation.
[0131] If an abnormal trend is discovered in the trend comparison process in step ST9, specifically, if it is confirmed that any of the trends obtained from the statistics of the number of sequential reads, the number of sequential writes, the number of random reads, and the number of random writes deviates from the trend in normal operation, the trend comparison program 218 outputs the corresponding data as data indicating an abnormal trend ("YES" in step ST10). The above steps ST9 and ST10 correspond to the trend comparison step according to the present invention.
[0132] If an abnormality is found in any of the above-mentioned comparison and analysis processing in step ST5, pattern comparison processing in step ST7, or trend comparison processing in step ST9, the abnormality report output program 219 of the storage access monitoring device 100 notifies the administrator of the corresponding data as an abnormality report (step ST11). The abnormality report may include detailed information such as what kind of abnormality was found and in which data the abnormality was found. The abnormality report may be notified via the console, or by email, etc.
[0133] If no abnormality is found in any of the above-mentioned comparison and analysis processing in step ST5, pattern comparison processing in step ST7, and trend comparison processing in step ST9 ("No" in step ST6, "No" in step ST8, and "No" in step ST10), the process returns to step ST1 and continues. Also, even if an abnormality report is notified to the administrator in step ST11, the process may return to step ST1 and continue.
[0134] In the flow diagram shown in Figure 5, if an abnormality is discovered in any of the processes described above, such as the comparison and analysis process in step ST5, the pattern comparison process in step ST7, or the trend comparison process in step ST9, an abnormality report is sent to the administrator. This allows the administrator to be notified even if the impact of ransomware is suspected.
[0135] However, if an abnormality is found in any two processes selected from the comparison analysis process in step ST5, the pattern comparison process in ST7, and the trend comparison process in ST9, or in all three processes, an abnormality report may be sent to the administrator. This makes it possible to reliably detect cases where the impact of ransomware is more likely, and reduce false positives.
[0136] According to the above-described embodiment, by monitoring the operational status of the volumes 40 constituting the storage device 30, it is possible to determine whether ransomware is running on the host 10 that uses data stored in the storage device 30 via the network 50. As a result, even if the ransomware countermeasures on the host 10 are insufficient, for example, if virus check software is not installed on the host 10 or if the latest pattern file is not updated, it is possible to grasp the security status of the host 10 and detect ransomware infection. Furthermore, even if there are multiple hosts 10, the storage access monitoring device 100 can centrally monitor the security statuses of the multiple hosts 10, thereby improving the security level and reducing operational costs.
[0137] Furthermore, according to the above-described embodiment, the operating status of the volume 40 constituting the storage device 30 can be monitored to detect abnormal behavior, thereby making it possible to detect ransomware infections with unknown characteristics that could not be detected by conventional virus check software. Furthermore, because abnormal behavior that may be caused by ransomware can be detected early, data encryption and data exploitation by ransomware can be prevented early. Furthermore, data recovery can be performed quickly, minimizing the impact on business operations.
[0138] (First derivative example) A first variation of this embodiment will be described with reference to Fig. 12. Fig. 12 is a system configuration diagram showing an example of a network system in the first variation of this embodiment.
[0139] 12 is roughly composed of a host 10, a storage device 30, a storage access monitoring device 100, and a storage management device 600. The host 10, the storage device 30, and the storage access monitoring device 100 have the same configurations as those in the above-described embodiment.
[0140] In the first derivative example, a storage device group is formed by a plurality of storage devices 30. The storage management device 600 is a management server that performs integrated management of the plurality of storage devices 30, and is configured to operate in cooperation with the storage access monitoring device 100.
[0141] The storage management device 600 has the function of acquiring the operating status of each volume 40 of each storage device 30 as operating information by executing the storage management application 610, and providing the acquired operating information to the storage access monitoring device 100.
[0142] In the above-described embodiment, the storage access monitoring device 100 acquires operation information related to each volume 40 of the storage device 30 from the storage device 30. On the other hand, in the first derivative example, the storage management device 600 acquires operation information related to each volume 40 of each storage device 30, and the storage access monitoring device 100 is able to acquire operation information related to each volume 40 of the storage device 30 from the storage management device 600.
[0143] According to this configuration, even in a configuration in which multiple storage devices 30 are provided, the storage management device 600 can centrally manage the operation information of each volume 40 of each storage device 30. The storage access monitoring device 100 cooperates with the storage management device 600 to acquire the operation information of each volume 40 of each storage device 30 from the storage management device 600, thereby efficiently and appropriately acquiring the operation information of each volume 40 and detecting abnormal behavior in access to each volume 40 caused by ransomware.
[0144] (Second derivative example) A second variation of this embodiment will be described with reference to Fig. 13. Fig. 13 is a system configuration diagram showing an example of a network system in the second variation of this embodiment.
[0145] 13 is roughly composed of a host 10, a storage device 30, a storage access monitoring device 100, a storage management device 600, and a backup management device 700. The host 10, the storage access monitoring device 100, and the storage management device 600 have the same configuration as in the first derivative example described above.
[0146] In the second derivative example, there are a plurality of storage devices 30, and each storage device 30 has a plurality of backup volumes 46 in a location (Vault area 45) that cannot be accessed from the outside.
[0147] The backup management device 700 is a management server that manages the backup of data stored in each volume 40 of each storage device 30 .
[0148] The backup management device 700 has a function of saving data stored in each volume 40 of each storage device 30 as backup data in the backup volume 46 by executing a backup management application 710. Data backup may be performed periodically, for example, or may be performed immediately whenever data is changed. Backup data is preferably saved across multiple dates and times or generations so that data can be restored from any point in time in the past.
[0149] According to this configuration, it becomes possible to save the data stored in each volume 40 of each storage device 30 as backup data. Furthermore, by centrally managing the backup processing in each storage device 30 using the backup management device 700, it becomes possible to reliably execute backups, thereby improving the safety of backups.
[0150] Furthermore, when the storage access monitoring device 100 detects abnormal behavior in access to each volume 40 caused by ransomware, the presence of ransomware can be discovered early, and data can be restored early using backup data from before the abnormal behavior was detected.
[0151] (Hardware configuration) The above-described host 10, storage device 30, storage access monitoring device 100, storage management device 600, and backup management device 700 can be realized, for example, by a computer 900 having the hardware configuration described below. Fig. 14 is a schematic block diagram showing an example of the configuration of a computer 900 capable of carrying out the processing in the embodiment of the present invention.
[0152] 14 includes, as an example, a processor 910, a memory 920, a storage 930, an input / output interface (input / output I / F) 940, and a communication interface (communication I / F) 950, and these components are connected via a bus 960. The computer 900 can be, for example, a general-purpose computer, a mobile communication terminal, or the like, as appropriate.
[0153] The processor 910 is hardware that executes various instructions written in a program and realizes and controls various functions in the computer 900. The processor 910 may be, for example, a CPU, a DSP (Digital Signal Processor) or GPU (Graphics Processing Unit) that performs data processing specialized for a specific purpose, or an FPGA (Field Programmable Gate Array) that has a high degree of design freedom.
[0154] The memory 920 is a volatile memory that temporarily stores programs and data executed by the computer 900, and is a main storage device such as a RAM (Random Access Memory).
[0155] The storage 930 is, for example, an auxiliary storage device such as a magnetic disk such as an HDD (Hard Disk Drive), a semiconductor memory such as an SSD (Solid State Drive), a magneto-optical disk, or an optical disk. The storage 930 may be connected via an input / output interface 940, or may be located in a position accessible via a communication interface 950. The storage 930 may also constitute each of the volumes 40 described above.
[0156] The storage 930 is capable of storing programs and data in which the processing procedures of this embodiment are written as program instructions. The processor 910 reads the programs of this embodiment from the storage 930, expands them on the memory 920, and executes the program instructions, thereby enabling the computer 900 to implement the functions of this embodiment. For example, the agent program running on the host 10, the various programs of the system management application 200 running on the storage access monitoring device 100, the storage management application 610 running on the storage management device 600, and the backup management application 710 operated on the backup management device 700 are all created in advance as executable programs, and the processor 910 reads the programs from the storage 930, expands them on the memory 920, and executes the program instructions, thereby realizing the desired functions.
[0157] The input / output interface 940 has a function of receiving input from the outside and a function of outputting information to the outside. The input / output interface 940 is configured to be able to connect, as necessary, user input devices represented by a mouse 941 and a keyboard 942, information collection devices such as a camera 943 and a microphone 944, and information output devices such as a display 945 and a speaker 946.
[0158] The communication interface 950 has a function that enables the computer 900 to communicate with other computers. The communication interface 950 may be configured to enable the computer 900 to access other computers via a network 50. Examples of the network 50 include a LAN (Local Area Network), a WAN (Wide Area Network), and the Internet. The communication interface 950 may also be configured to enable direct communication with other computers. There are no particular limitations on the communication method used by the communication interface 950, and either a packet communication method or a circuit switching method may be used, and either wired communication or wireless communication may be used.
[0159] (Action of this embodiment) The operation of this embodiment will be described below.
[0160] The storage access monitoring method in this embodiment is a storage access monitoring method implemented by a computer 900, and includes an operation information acquisition step (step ST1) for acquiring, as operation information, the operation status of a volume 40 constituting a storage device 30 from which a host 10, which is an endpoint, can read / write data via a network 50; a ransomware operation determination step (steps ST5 to ST10) for determining whether or not ransomware is likely to be operating in the host 10 based on the operation information of the volume 40; and an abnormality report notification step (step ST11) for outputting an abnormality report if there is a possibility that ransomware is operating.
[0161] The ransomware behavior determination step includes a comparison analysis step (steps ST5 and ST6) that determines that the behavior related to the latest operation information is abnormal by comparing the latest operation information with past operation information, a pattern comparison step (steps ST7 and ST8) that determines that the behavior related to the latest operation information is abnormal by determining whether or not there is a behavior pattern in the latest operation information that may be influenced by ransomware, and a trend comparison step (steps ST9 and ST10) that determines that the behavior related to the latest operation information is abnormal by determining whether or not the behavior related to the latest operation information is different from the normal behavior related to past operation information.
[0162] If it is determined that the behavior of the latest operating information is abnormal in one or more of the above-mentioned comparison analysis step, pattern comparison step, and trend comparison step, it is determined that there is a possibility that ransomware is operating on the host 10.
[0163] According to the above process, by monitoring the operational status of the volumes 40 that constitute the storage device 30, it is possible to determine whether ransomware is running on the host 10 that uses data stored in the storage device 30 via the network 50. Therefore, even if the endpoint host 10 does not have virus check software installed or is not updated with the latest pattern file, it is possible to grasp the security status of the host 10 and detect ransomware infection. Furthermore, even if there are multiple hosts 10, the storage access monitoring device 100 can centrally monitor the security status, thereby improving the security level and reducing operational costs.
[0164] The above process monitors the operating status of volumes 40 that make up storage device 30 and detects abnormal behavior, making it possible to detect ransomware infections with unknown characteristics that cannot be detected by conventional virus check software. Furthermore, because abnormal behavior that may be caused by ransomware can be detected early, data encryption and data exploitation by ransomware can be prevented early. Furthermore, data recovery can be performed quickly, minimizing the impact on business operations.
[0165] Furthermore, in the above-described storage access monitoring method, the operational information may include the number of sequential reads, the number of sequential writes, the number of random reads, and the number of random writes for each logical unit of the volume 40, as well as the number of sequential reads, the number of sequential writes, the number of random reads, and the number of random writes for each logical block address of the logical unit.
[0166] This makes it possible to determine whether ransomware is operating on the host 10 by monitoring the operating status of the volumes 40 that make up the storage device 30, such as the number of sequential reads, sequential writes, random reads, and random writes for each logical unit of the volume 40, as well as the number of sequential reads, sequential writes, random reads, and random writes for each logical block address of the logical unit.
[0167] Furthermore, the above storage access monitoring method includes a ratio calculation step (step ST4) for calculating a read / write ratio, which is the ratio between the sum of the number of sequential reads and the number of random reads and the sum of the number of sequential writes and the number of random writes, and a sequential / random ratio, which is the ratio between the sum of the number of sequential reads and the number of sequential writes and the sum of the number of random reads and the number of random writes; and in the comparison and analysis step, if the read / write ratio for the latest operation information is reversed and the read / write ratio for the past operation information, or if it is determined that the sequential / random ratio for the latest operation information is reversed and the sequential / random ratio for the past operation information is reversed, it may be determined that the behavior related to the latest operation information is abnormal.
[0168] This makes it possible to determine that ransomware is running on the host 10 when the read / write ratio reverses over time and the sequential / random ratio reverses over time.
[0169] Furthermore, the above-mentioned storage access monitoring method may include a file information acquisition step of acquiring information relating to the reading / writing of files in the volume 40 by the host 10 as file information, and a mapping step (step ST3) of mapping the file information with the logical block address of the logical unit, and if it is determined in the pattern comparison step that only the header portion of the file has been rewritten, it may be determined that the behavior relating to the latest operating information is abnormal.
[0170] This makes it possible to determine that ransomware is running on the host 10 if behavior occurs that suggests that only the header portion of the file has been rewritten.
[0171] Furthermore, the above-described storage access monitoring method may include a statistical quantity calculation step (step ST4) for calculating average values and standard deviation values for the latest operation information and average values and standard deviation values for past operation information, and if it is determined in the trend comparison step that the statistical distribution obtained from the average values and standard deviation values for the latest operation information deviates beyond a predetermined condition from the statistical distribution obtained from the average values and standard deviation values for past operation information, it may be determined that the behavior of the latest operation information is abnormal.
[0172] This makes it possible to determine that ransomware is operating on the host 10 if the operating status of the volume 40 deviates from normal operation that is not affected by ransomware.
[0173] Furthermore, in the above-described storage access monitoring method, if the average value ± standard deviation value for the latest operational information is outside the range determined by the average value ± 2 × standard deviation value for past operational information, it may be determined that the behavior of the latest operational information is abnormal.
[0174] According to the above processing, the average value and standard deviation value representing the operating status of the volume 40 are calculated, and if the average value and standard deviation value exceed predetermined conditions, it can be determined that ransomware is operating on the host 10.
[0175] Furthermore, in the above-described storage access monitoring method, if it is determined that the behavior of the latest operational information is abnormal in all steps of the comparison analysis step, the pattern comparison step, and the trend comparison step, it may be determined that ransomware may be operating on the host 10.
[0176] According to the above process, if abnormal behavior is detected in all steps of the comparison analysis step, pattern comparison step, and trend comparison step, it is determined that ransomware is operating on the host 10, thereby reliably detecting cases where the impact of ransomware is more likely and reducing false positives.
[0177] Furthermore, in order to achieve the above object, the storage access monitoring device 100 according to the present invention includes an operation information acquisition unit that acquires, as operation information, the operation status of a volume 40 that constitutes a storage device 30 from which a host 10 serving as an endpoint can read / write data via a network 50; a ransomware operation determination unit that determines whether or not there is a possibility that ransomware is operating in the host 10 based on the operation information of the volume 40; and an abnormality report notification unit that outputs an abnormality report when there is a possibility that ransomware is operating. The ransomware operation determination unit compares the latest operation information with past operation information to determine whether or not there is a possibility that ransomware is operating. The host 10 is configured to execute a comparative analysis process that determines that behavior related to the information is abnormal, a pattern comparison process that determines that behavior related to the latest operation information is abnormal by determining whether or not there is a behavior pattern in the latest operation information that may be influenced by ransomware, and a trend comparison process that determines that behavior related to the latest operation information is abnormal by determining whether the behavior related to the latest operation information is different from normal behavior related to past operation information.If the comparative analysis process, pattern comparison process, and trend comparison process determine that behavior related to the latest operation information is abnormal, it is determined that there is a possibility that ransomware is operating on the host 10.
[0178] According to the above configuration, by monitoring the operational status of the volumes 40 that constitute the storage device 30, it is possible to determine whether ransomware is running on the host 10 that uses data stored in the storage device 30 via the network 50. Therefore, even if the endpoint host 10 does not have virus check software installed or is not updated with the latest pattern file, it is possible to grasp the security status of the host 10 and detect ransomware infection. Furthermore, even if there are multiple hosts 10, the security status can be centrally monitored by the storage access monitoring device 100, thereby improving security and reducing operational costs.
[0179] The above configuration monitors the operating status of the volumes 40 that make up the storage device 30 and detects abnormal behavior, making it possible to detect ransomware infections with unknown characteristics that cannot be detected by conventional virus check software. Furthermore, because abnormal behavior that may be caused by ransomware can be detected early, data encryption and data exploitation by ransomware can be prevented early. Furthermore, data can be recovered quickly, minimizing the impact on business operations.
[0180] The above-described embodiments are described to facilitate understanding of the present invention, and are not intended to limit the present invention. The components and processing steps disclosed in the above-described embodiments are intended to include all design modifications and equivalents that fall within the technical scope of the present invention. [Industrial Applicability]
[0181] The present invention can be applied to ransomware detection technology, as it can detect ransomware infection at an endpoint early and prevent data encryption and data exploitation, even if sufficient ransomware countermeasures are not implemented at the endpoint. [Explanation of symbols]
[0182] 10 Host (host device) 11 Agent 30 Storage Devices 40 volumes 45 Vault area 46 Backup volumes 50 Network 100 Storage access monitoring device 110, 910 processors 120, 950 Communication interface (Communication I / F) 130, 940 Input / Output Interface (Input / Output I / F) 140,920 memory 150 Storage 160, 960 buses 200 System Management Applications 211 Operation Information Acquisition Program 212 Management table update program 213 File information acquisition program 214 Mapping Program 215 Numerical Analysis Program 216 Comparative Analysis Program 217 Pattern Comparison Program 218 Trend Comparison Program 219 Abnormality report output program 300 Management Table 400 Logical unit operation information management table 401, 501 "Logical Unit Name" column 402, 505 "Acquisition date and time" column 410, 510 "Acquired Data" column 411, 511 "Sequential Read Count" column 412, 512 "Number of Sequential Writes" column 413, 513 "Random Read Count" column 414, 514 "Random Write Count" column 420 "Analysis" column 430 "Sequential Read Statistics" column 440 "Sequential Write Statistics" column 450 "Random Read Statistics" column 460 "Random Write Statistics" column 431, 441, 451, 461 "Average" column 432, 442, 452, 462 "Standard Deviation" column 470 "Read / Write Ratio" column 480 "Sequential / Random Ratio" column 500 File-specific operation information management table 502 "File name" column 503 "LBA Flag" column 504 "Block Address" column 600 Storage Management Device 610 Storage Management Applications 700 Backup Management Device 710 Backup Management Application 900 Computers 930 Storage 941 Mouse 942 keyboard 943 Camera 944 Mike 945 Display 946 Speaker
Claims
1. 1. A computer-implemented method for monitoring storage access, comprising: an operation information acquisition step of acquiring, as operation information, operation statuses of volumes constituting a storage device that allows a host device to read / write data via a network; a ransomware operation determination step of determining whether or not there is a possibility that ransomware is operating in the host device based on the operation information of the volume; an abnormality report notification step of outputting an abnormality report when there is a possibility that the ransomware is operating, The ransomware behavior determination step includes: a comparison and analysis step of comparing latest operation information with past operation information to determine that behavior related to the latest operation information is abnormal; a pattern comparison step of determining whether or not there is a behavior pattern in the latest operation information that may be affected by the ransomware, thereby determining that the behavior related to the latest operation information is abnormal; a trend comparison step of determining whether the behavior related to the latest operation information is abnormal by determining whether the behavior related to the latest operation information is different from a normal behavior related to the past operation information, A storage access monitoring method characterized by determining that the ransomware may be operating on the host device if the behavior related to the latest operating information is determined to be abnormal in one or more of the comparison analysis step, the pattern comparison step, and the trend comparison step.
2. 2. The storage access monitoring method according to claim 1, wherein the operational information includes the number of sequential reads, the number of sequential writes, the number of random reads, and the number of random writes for each logical unit of the volume, as well as the number of sequential reads, the number of sequential writes, the number of random reads, and the number of random writes for each logical block address of the logical unit.
3. a ratio calculation step of calculating a read / write ratio, which is the ratio between the sum of the number of sequential reads and the number of random reads and the sum of the number of sequential writes and the number of random writes, and a sequential / random ratio, which is the ratio between the sum of the number of sequential reads and the number of sequential writes and the sum of the number of random reads and the number of random writes; 3. The storage access monitoring method according to claim 2, wherein, in the comparison and analysis step, if the read / write ratio for the latest operational information and the read / write ratio for the past operational information are reversed, and if it is determined that the sequential / random ratio for the latest operational information and the sequential / random ratio for the past operational information are reversed, it is determined that the behavior related to the latest operational information is abnormal.
4. a file information acquisition step of acquiring information related to reading / writing of files in the volume by the host device as file information; a mapping step of mapping the file information to the logical block addresses of the logical units, The storage access monitoring method according to claim 2, characterized in that if it is determined in the pattern comparison step that only the header portion of the file has been rewritten, it is determined that the behavior related to the latest operation information is abnormal.
5. a statistical quantity calculation step of calculating an average value and a standard deviation value related to the latest operation information and an average value and a standard deviation value related to the past operation information, 3. The storage access monitoring method according to claim 2, wherein, in the trend comparison step, if it is determined that the statistical distribution obtained from the average value and standard deviation values for the latest operational information deviates beyond a predetermined condition from the statistical distribution obtained from the average value and standard deviation values for the past operational information, it is determined that the behavior related to the latest operational information is abnormal.
6. The storage access monitoring method described in claim 5, characterized in that if the average value ± standard deviation value for the latest operation information is outside the range determined by the average value ± 2 × standard deviation value for the past operation information, it is determined that the behavior related to the latest operation information is abnormal.
7. The storage access monitoring method according to claim 1, characterized in that if the behavior related to the latest operating information is determined to be abnormal in all steps of the comparison analysis step, the pattern comparison step, and the trend comparison step, it is determined that the ransomware may be operating in the host device.
8. A storage access monitoring device, an operation information acquisition unit that acquires, as operation information, the operation status of a volume that constitutes a storage device that allows a host device to read / write data via a network; a ransomware operation determination unit that determines whether or not there is a possibility that ransomware is operating in the host device based on the operation information of the volume; an abnormality report notification unit that outputs an abnormality report when there is a possibility that the ransomware is operating; The ransomware behavior determination unit a comparison and analysis process for comparing latest operation information with past operation information to determine that behavior related to the latest operation information is abnormal; a pattern comparison process for determining whether or not there is a behavior pattern in the latest operation information that may be affected by the ransomware, and thereby determining that the behavior related to the latest operation information is abnormal; a tendency comparison process for determining whether the behavior related to the latest operation information is abnormal by determining whether the behavior related to the latest operation information is different from a normal behavior related to the past operation information, A storage access monitoring device characterized by determining that the ransomware may be operating on the host device when one or more of the comparison analysis process, the pattern comparison process, and the trend comparison process determine that the behavior related to the latest operating information is abnormal.
Citation Information
Patent Citations
File access monitoring method, program, and system
WO2019073720A1