Block-Based Anomaly Detection for Storage Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anomaly detection techniques in computer systems are inadequate, as they rely on application or file-specific monitoring, which is computationally intensive, costly, and often fails to detect new threats in a timely manner, leading to significant downtime and data loss.

Innovation Solution

A block-based anomaly response (BBAR) system that operates at the storage device level, using machine learning to generate a signature of normal behavior and detect deviations, allowing for application-agnostic and resource-efficient anomaly detection without the need for constant rule updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If application or file-specific monitoring is used for anomaly detection, then detection accuracy may be improved, but computational resources and cost increase significantly

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent segments the storage system into discrete blocks and monitors each block independently for anomalies. Instead of monitoring entire files or applications, the system divides storage into block units that can be individually analyzed, reducing the overall computational burden while maintaining detection capability at the block level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from traditional file-system-level monitoring to block-level monitoring, representing a dimensional change in the monitoring granularity. This shift to a lower level (block vs. file/application) enables more efficient resource utilization while providing finer-grained anomaly detection capability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If application or file-specific monitoring is used for anomaly detection, then detection capability may be improved, but system cost increases

Engineering Contradiction:
Improvesecurity anomaly detection capabilityVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system implements self-service through automated machine learning models that continuously learn normal block access patterns and automatically detect anomalies without requiring manual rule updates. This automation reduces operational overhead and costs while maintaining high detection capability through adaptive, intelligent monitoring.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent employs parameter changes by using machine learning models that dynamically adjust detection parameters based on learned patterns of normal behavior. The system adapts its monitoring parameters automatically, reducing the need for expensive manual configuration and rule maintenance while preserving detection effectiveness.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If traditional anomaly detection methods are used, then known threats may be detected, but new threats are not detected in a timely manner

Engineering Contradiction:
Improvethreat detection accuracyVSAvoiddetection response time for new threats
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements dynamics through machine learning models that continuously adapt and update their understanding of normal block access patterns. This dynamic adaptation enables the system to detect new and evolving threats in real-time by comparing current block behavior against learned patterns, rather than relying on static rules that lag behind emerging threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops where detection results and ongoing block monitoring data continuously refine the machine learning models. This feedback mechanism enables the system to learn from new threats and improve detection accuracy over time, reducing the time to detect and respond to emerging security issues.

Inventive Principle:
Principle #23Feedback

4Measurement precision

If application-specific monitoring is implemented, then targeted detection may be achieved, but device complexity increases

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a block-level monitoring system that serves multiple purposes: it detects anomalies across different files and applications uniformly, provides a foundation for various types of security analysis, and can adapt to monitor different storage configurations. This universal block-based approach reduces system complexity compared to implementing separate monitoring mechanisms for each file or application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11562069B2Block-based anomaly detection
Publication Date: 2023.01.24 KYNDRYL INC
  • US11562069B2 patent drawing
  • US11562069B2 patent drawing
  • US11562069B2 patent drawing

AI summary

A plurality of blocks of a first storage device are monitored. The first storage device is related to a computer system. A subset of blocks of the plurality a compared to a first storage signature of the first storage device. Based on the comparing of the subset of blocks to the first storage signature, a security anomaly is determined on the computer system. In response to the security anomaly, a security action is performed. The security action is related to the computer system.