Backup Metadata Differencing for Directory Service Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage systems face challenges in efficiently managing backups of specialized directory service assets, particularly in recovering critical information and detecting cyber-security anomalies, due to the complexity of managing multiple schedules, policies, and the need for comprehensive scanning of large data sets.

Innovation Solution

Implementing a system that utilizes file-based backup metadata to enable intelligent sub-asset creation with differential retention and tiering, predictive recovery of specialized directory service data, and delta anomaly detection for cyber-security management, leveraging FBB metadata for efficient scanning and recovery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If comprehensive scanning of large data sets is performed for cyber-security anomaly detection, then detection thoroughness is improved, but resource utilization increases and scanning time extends

Engineering Contradiction:
Improveanomaly detection thoroughnessVSAvoidresource utilization
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent segments the backup data into individual file metadata elements, allowing the anomaly detection system to process only relevant files rather than scanning entire data sets. The file-based backup metadata enables selective extraction and analysis of specific files based on change detection, reducing the volume of data requiring comprehensive security scanning while maintaining detection thoroughness.

Inventive Principle:
Principle #1Segmentation

2Productivity

If file-based backup metadata is used to enable intelligent sub-asset creation, then backup management efficiency is improved, but system complexity increases

Engineering Contradiction:
Improvebackup management efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-processing backup data into structured file-based metadata during the backup process itself. This preliminary organization of data into manageable sub-assets with associated metadata enables efficient subsequent operations such as selective recovery and anomaly detection without requiring complex real-time processing, thereby improving management efficiency while controlling system complexity.

Inventive Principle:
Principle #10Preliminary action

3Speed

If predictive recovery of specialized directory service data is implemented, then recovery speed is improved, but the scope of data management increases

Engineering Contradiction:
Improverecovery speedVSAvoiddata management scope
Core Design Contradiction:
SpeedVSQuantity of substance

Solution Approach 1:

The patent applies local quality by treating different types of data assets with different management approaches. Specialized directory service assets are identified and separated from general file data, receiving tailored predictive recovery capabilities. This allows the system to optimize recovery speed for critical directory service data while managing the overall data scope through selective application of advanced recovery techniques only where needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12566853B2Delta anomaly detection for backups of specialized directory service assets
Publication Date: 2026.03.03 DELL PROD LP
  • US12566853B2 patent drawing
  • US12566853B2 patent drawing
  • US12566853B2 patent drawing

AI summary

A method for managing access to a file based backup (FBB) includes generating, at a first point-in-time, a first FBB at a first point-in-time, wherein the first FBB comprises a first set of files of an asset at the first point-in-time, generating, at a second point-in-time after the first point-in-time, a second FBB at a second point-in-time, wherein the second FBB comprises a second set of files of the asset at the second point-in-time, performing an asset analysis on the first FBB metadata file and a second FBB metadata file associated with the second FBB to generate a differencing FBB metadata file, performing an anomaly analysis on the second FBB using the differencing FBB metadata file to obtain a anomaly report, and performing a remediation of the second FBB based on the anomaly report.