AI Storage Threat Detection Using Segmented Object Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security threat detection methods in storage systems often lack granularity and result in slow or delayed threat detection, operating primarily at the network and application layers.

Innovation Solution

The use of artificial intelligence (AI) techniques to detect security threats at the storage object level by processing historical performance and capacity data to determine supervised datasets, configuring AI models for threat detection, and performing automated actions based on detected threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional security threat detection methods operate at the network layer and/or application layer, then the detection coverage is broad, but the detection granularity is insufficient and detection speed is slow

Engineering Contradiction:
Improvedetection granularityVSAvoiddetection speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The patent segments the storage system into multiple storage objects (e.g., files, directories, blocks) and applies AI-based detection to each individual storage object rather than treating the entire storage system as a single unit. This segmentation enables fine-grained detection at the storage object level while maintaining system-wide coverage, resolving the contradiction between detection granularity and detection speed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of detection by operating at the storage object level rather than only at the network or application layers. This dimensional shift from traditional network-layer monitoring to storage-object-layer analysis enables both high granularity and efficient detection by focusing computational resources on specific storage objects that exhibit suspicious behavior patterns.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If AI techniques are used to detect security threats at the storage object level, then detection granularity is improved, but computational complexity increases

Engineering Contradiction:
Improvedetection granularityVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies AI-based detection selectively to storage objects that exhibit suspicious behavior patterns or meet specific risk criteria, rather than uniformly applying complex AI analysis to all storage objects. This partial action approach maintains high detection granularity for targeted objects while reducing overall computational complexity by avoiding unnecessary analysis of normal storage objects.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary filtering and preprocessing of storage object data before applying complex AI analysis. By pre-identifying storage objects that require detailed analysis based on simpler heuristics or threshold-based rules, the system reduces the volume of data that needs to be processed by computationally intensive AI models, thereby managing computational complexity while maintaining detection precision.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11451574B2Detecting security threats in storage systems using artificial intelligence techniques
Publication Date: 2022.09.20 EMC IP HLDG CO LLC
  • US11451574B2 patent drawing
  • US11451574B2 patent drawing
  • US11451574B2 patent drawing

AI summary

Methods, apparatus, and processor-readable storage media for detecting security threats in storage systems using AI techniques are provided herein. An example computer-implemented method includes obtaining historical performance data and historical capacity data pertaining to one or more storage objects within a storage system; determining supervised datasets pertaining to security threat-related data and non-security threat-related data by processing at least a portion of the obtained data using a first set of AI techniques; configuring a second set of AI techniques based at least in part on the determined supervised datasets; detecting one or more security threats in connection with at least one storage object within the storage system by processing input data from the at least one storage object using the second set of AI techniques; and performing at least one automated action based at least in part on the one or more detected security threats.