Back-End Virus Scanning for Distributed Storage Arrays

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current front-end virus scanning methods for enterprise class storage systems are inefficient, taking weeks or even years to complete scans due to dependency on client-side resources and only checking a small percentage of files, leaving many files unchecked for latent viruses or malware.

Innovation Solution

Implementing a back-end virus scanning approach that iterates through multiple storage servers, committing file systems to antivirus servers for comprehensive scanning, independent of client software and resources, using custom scripts and high-speed connections to scan all files in a storage array or group of arrays efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If front-end virus scanning methods are used, then client-side resources are utilized for scanning, but scanning efficiency is extremely low and takes weeks or years to complete

Engineering Contradiction:
Improvescanning efficiencyVSAvoidscanning time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent inverts the traditional front-end scanning architecture by implementing back-end scanning. Instead of client devices scanning files before upload (front-end), the storage system itself performs scanning after files are stored (back-end). This inversion transfers scanning workload from client-side resources to server-side resources, enabling comprehensive scanning of all files without depending on client software or resources, thus dramatically improving scanning efficiency and reducing scanning time from weeks/months to hours.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces an intermediary component - a dedicated virus scanning agent or module within the storage system - that acts as a mediator between stored files and antivirus databases. This intermediary enables the storage system to autonomously perform virus scanning without requiring client-side antivirus software, facilitating efficient back-end scanning by leveraging server-side computational resources and centralized antivirus signature databases.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If front-end scanning is implemented, then only a small percentage of files are checked, but this leaves many files unchecked for latent viruses

Engineering Contradiction:
Improvevirus detection coverageVSAvoidscanning speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By inverting the scanning approach from front-end (client-side, selective scanning) to back-end (server-side, comprehensive scanning), the system achieves complete file coverage. The back-end scanning mechanism scans all files stored in the storage system regardless of client configuration, ensuring 100% detection coverage while maintaining high speed through server-side parallel processing capabilities.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The storage system performs virus scanning as a self-service function, autonomously scanning all stored files without requiring client-side antivirus software or user intervention. This self-service capability ensures comprehensive virus detection across all files while leveraging the storage system's own computational resources, achieving both complete coverage and efficient processing speed.

Inventive Principle:
Principle #25Self-service

3Reliability

If comprehensive virus scanning of all files is performed, then all files are checked for viruses, but the scanning process becomes extremely time-consuming

Engineering Contradiction:
Improvecomplete file scanningVSAvoidtotal scanning duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the virus scanning process into manageable units by organizing storage into multiple file systems across multiple storage servers. Each file system is scanned independently and in parallel, allowing comprehensive scanning of all files to be divided into concurrent scanning tasks. This segmentation enables the system to process billions of files across distributed storage infrastructure simultaneously, completing comprehensive scans in hours rather than weeks or months.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds the dimension of parallelism to the scanning process by utilizing multiple storage servers and file systems that can be scanned simultaneously. Instead of sequential scanning of a single file system, the system scans multiple file systems across multiple servers in parallel, dramatically reducing total scanning time while maintaining complete coverage of all stored files.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10885187B1Virus scanning on storage systems comprising multiple storage servers with a plurality of file systems
Publication Date: 2021.01.05 EMC IP HLDG CO LLC
  • US10885187B1 patent drawing
  • US10885187B1 patent drawing
  • US10885187B1 patent drawing

AI summary

A storage system includes at least one processing device comprising a processor coupled to a memory, the at least one processing device being configured to determine two or more storage servers accessible to the storage system and to conduct a virus scan by iterating through the two or more storage servers to scan files stored in a plurality of file systems of the two or more storage servers. Iterating through the two or more storage servers comprises selecting one of the storage servers, identifying the file systems provided by the selected storage server, committing the identified file systems to a plurality of antivirus servers coupled to the storage array, scanning files in the committed file systems utilizing the plurality of antivirus servers, and, responsive to completing the scan of files in the committed file systems, selecting another one of the storage servers and repeating the identifying, committing and scanning.