Anti-virus Blade Bypassing Protocol Stack
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing anti-virus solutions for storage systems require manufacturers to develop proprietary interfaces and protocols, limiting user choice and slowing down storage system performance due to the need for licensing and protocol translation.
Innovation Solution
A blade-based system that hosts an anti-virus application, using an anti-virus engine to create a 'dummy' file for scanning, with an interceptor module and virtual file filter to intercept I/O requests, allowing the anti-virus application to initiate scans without direct storage system requests, thus eliminating the need for proprietary interfaces and improving performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manufacturers develop proprietary interfaces and protocols for anti-virus solutions, then anti-virus functionality can be provided, but user choice is limited and licensing costs increase
Solution Approach 1:
The storage system is designed with built-in anti-virus scanning capabilities that can work with any anti-virus application through standard interfaces. The system includes an anti-virus filter driver and file system hooks that provide universal anti-virus functionality without requiring proprietary interfaces, allowing users to choose from multiple anti-virus vendors.
Solution Approach 2:
The patent introduces an anti-virus filter driver as an intermediary component between the file system and anti-virus applications. This filter driver acts as a universal interface that can communicate with different anti-virus applications without requiring custom proprietary protocols, thus enabling user choice while maintaining reliable anti-virus functionality.
2Reliability
If proprietary protocols are used for anti-virus communication, then anti-virus scanning can be performed, but storage system performance slows down due to protocol translation
Solution Approach 1:
The patent extracts the anti-virus scanning functionality from the protocol translation layer and integrates it directly into the file system through filter drivers. This eliminates the need for separate protocol translation steps, as the anti-virus filter operates at the file system level where data is already accessible, thereby maintaining virus scanning capability while improving storage system performance.
Solution Approach 2:
The patent replaces the mechanical protocol translation process with a more efficient filter driver approach. Instead of translating protocols between different layers, the anti-virus filter driver directly intercepts file system calls and passes data to anti-virus applications, eliminating the performance overhead associated with protocol translation.
3Reliability
If scan servers are implemented on dedicated servers, then anti-virus requests can be processed, but system complexity increases and deployment becomes difficult
Solution Approach 1:
The patent merges the anti-virus processing capability directly into the storage system through filter drivers and file system hooks. Instead of requiring separate scan servers on dedicated servers, the anti-virus functionality is combined with the storage system itself, reducing system complexity while maintaining the ability to process anti-virus requests.
Solution Approach 2:
The storage system provides self-service anti-virus protection through built-in filter drivers that automatically intercept and process file access requests. This eliminates the need for external scan servers to handle anti-virus requests, simplifying deployment while maintaining reliable virus scanning capability.
Data Source
AI summary
An anti-virus blade provides anti-virus services to a storage system and eliminates the need to develop an interface to initiate a scan operation at the blade. An anti-virus engine executed at the blade receives a request to scan data maintained by the storage system. The anti-virus engine creates a stub file (e.g., a file that has the same name as the Currently Amended file indicated in the request, but does not contain data) and issues an I/O command to the file. A file framework module executed at the blade intercepts the I/O to the dummy file and passes the I/O to an anti-virus application, which is registered with the file framework to receive I/Os from the anti-virus engine. The anti-virus application, in turn, initiates a scan operation by issuing a read request to the stub file, without receiving the request for scanning directly from the storage system.


