Backup Activity Profiling for Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security appliances, such as IDS and firewalls, often fail to detect and prevent emerging threats, particularly those with narrow scopes or evasive attacks, leading to potential significant damage and resource loss due to the time lag in updating detection rules and patch application issues.

Innovation Solution

Implementing a data protection server that supports continuous data protection (CDP) and near-continuous data protection (NCDP) models, which maintain real-time intelligence on endpoint changes and metadata, enabling anomaly detection and remedial actions through statistical analysis and correlation of data protection events across endpoints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security appliances use traditional detection methods with periodic rule updates, then device complexity remains manageable, but detection precision deteriorates due to time lag in detecting emerging threats

Engineering Contradiction:
Improvedetection precisionVSAvoidtime lag
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces traditional mechanical rule-based detection systems with a statistical analysis system that continuously monitors backup activity patterns. Instead of relying on periodically updated signature rules, the system uses statistical models to detect anomalies in real-time, such as unusual file access patterns, unauthorized modifications, or abnormal backup behavior that indicate emerging threats like worms or targeted attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system implements continuous monitoring of backup activity rather than periodic scanning. By continuously analyzing backup streams and comparing actual backup behavior against expected patterns, the system maintains constant detection capability without the time lag inherent in periodic rule updates, enabling immediate detection of emerging threats as they manifest in backup operations.

Inventive Principle:
Principle #20Continuity of useful action

2Measurement precision

If security appliances implement comprehensive detection rules for all possible threats, then detection precision improves, but device complexity increases making the system harder to maintain

Engineering Contradiction:
Improvedetection precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system automatically learns and adapts to normal backup patterns for each protected system without requiring manual configuration of detection rules. By establishing baseline behavior automatically and detecting deviations from these baselines, the system provides comprehensive threat detection across diverse environments without the complexity of maintaining extensive rule sets. The statistical models self-adjust to accommodate legitimate changes in backup behavior.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Instead of using fixed detection rules, the system employs statistical parameters that dynamically adjust to reflect normal backup patterns. By monitoring variations in backup timing, file selection, data volume, and access patterns, the system adapts its detection thresholds based on observed behavior, maintaining high detection precision while avoiding the complexity of manually configuring and updating extensive rule bases.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If security appliances rely on vendor-provided detection rules, then ease of operation is maintained, but adaptability deteriorates when facing unsupported or narrow-scope threats

Engineering Contradiction:
Improveease of operationVSAvoidadaptability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system automatically adapts to detect threats without requiring vendor-provided rules or manual configuration. By continuously analyzing backup activity patterns and establishing behavioral baselines, the system autonomously detects both known and emerging threats including narrow-scope attacks and unsupported threat types. This self-adapting capability maintains ease of operation while dramatically improving adaptability to diverse and evolving threats.

Inventive Principle:
Principle #25Self-service

4Reliability

If traditional backup systems are used without continuous monitoring, then loss of time in detection is reduced, but reliability of threat detection deteriorates due to lack of real-time intelligence

Engineering Contradiction:
ImprovereliabilityVSAvoiddetection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system continuously monitors backup activity streams in real-time, analyzing each backup operation as it occurs rather than performing periodic scans. This continuous analysis enables immediate detection of threats manifested in backup behavior, such as worms attempting to spread through backup channels or attackers manipulating backup processes. The real-time detection capability maintains minimal detection time while significantly improving reliability through constant surveillance.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system establishes feedback loops where detected anomalies trigger immediate analysis and response actions. By continuously comparing actual backup behavior against expected patterns and immediately identifying deviations, the system provides real-time feedback on system security state. This feedback mechanism enhances detection reliability by confirming threats as they occur rather than relying on periodic assessments that may miss transient malicious activity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8533818B1Profiling backup activity
Publication Date: 2013.09.10 GEN DIGITAL INC
  • US8533818B1 patent drawing
  • US8533818B1 patent drawing
  • US8533818B1 patent drawing

AI summary

Mitigating a network security threat is disclosed. Information associated with a data protection event is received. The received information is evaluated for an indication of a network security threat. One or more remedial actions are performed if it is determined that a potential threat has been indicated. Optionally, the received information is stored.