Block-Based Anomaly Detection for Storage Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current anomaly detection techniques in computer systems are inadequate, as they rely on application or file-specific monitoring, which is computationally intensive, costly, and often fails to detect new threats in a timely manner, leading to significant downtime and data loss.
Innovation Solution
A block-based anomaly response (BBAR) system that operates at the storage device level, using machine learning to generate a signature of normal behavior and detect deviations, allowing for application-agnostic and resource-efficient anomaly detection without the need for constant rule updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If application or file-specific monitoring is used for anomaly detection, then detection accuracy may be improved, but computational resources and cost increase significantly
Solution Approach 1:
The patent segments the storage system into discrete blocks and monitors each block independently for anomalies. Instead of monitoring entire files or applications, the system divides storage into block units that can be individually analyzed, reducing the overall computational burden while maintaining detection capability at the block level.
Solution Approach 2:
The patent transitions from traditional file-system-level monitoring to block-level monitoring, representing a dimensional change in the monitoring granularity. This shift to a lower level (block vs. file/application) enables more efficient resource utilization while providing finer-grained anomaly detection capability.
2Reliability
If application or file-specific monitoring is used for anomaly detection, then detection capability may be improved, but system cost increases
Solution Approach 1:
The system implements self-service through automated machine learning models that continuously learn normal block access patterns and automatically detect anomalies without requiring manual rule updates. This automation reduces operational overhead and costs while maintaining high detection capability through adaptive, intelligent monitoring.
Solution Approach 2:
The patent employs parameter changes by using machine learning models that dynamically adjust detection parameters based on learned patterns of normal behavior. The system adapts its monitoring parameters automatically, reducing the need for expensive manual configuration and rule maintenance while preserving detection effectiveness.
3Measurement precision
If traditional anomaly detection methods are used, then known threats may be detected, but new threats are not detected in a timely manner
Solution Approach 1:
The patent implements dynamics through machine learning models that continuously adapt and update their understanding of normal block access patterns. This dynamic adaptation enables the system to detect new and evolving threats in real-time by comparing current block behavior against learned patterns, rather than relying on static rules that lag behind emerging threats.
Solution Approach 2:
The system incorporates feedback loops where detection results and ongoing block monitoring data continuously refine the machine learning models. This feedback mechanism enables the system to learn from new threats and improve detection accuracy over time, reducing the time to detect and respond to emerging security issues.
4Measurement precision
If application-specific monitoring is implemented, then targeted detection may be achieved, but device complexity increases
Solution Approach 1:
The patent applies universality by creating a block-level monitoring system that serves multiple purposes: it detects anomalies across different files and applications uniformly, provides a foundation for various types of security analysis, and can adapt to monitor different storage configurations. This universal block-based approach reduces system complexity compared to implementing separate monitoring mechanisms for each file or application.
Data Source
AI summary
A plurality of blocks of a first storage device are monitored. The first storage device is related to a computer system. A subset of blocks of the plurality a compared to a first storage signature of the first storage device. Based on the comparing of the subset of blocks to the first storage signature, a security anomaly is determined on the computer system. In response to the security anomaly, a security action is performed. The security action is related to the computer system.


