Data Protection Optimization System for Automated Threat Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data protection technologies face challenges in automating operations across complex, multi-domain, and multi-cloud environments, struggling to dynamically adjust and optimize data protection infrastructure in response to changing conditions and best practices, leading to inefficiencies and security exposures.

Innovation Solution

A data protection automatic optimization system that continuously analyzes metrics, events, and conditions in a computer network, automatically adjusts data collection and storage, and optimizes infrastructure and operations based on detected events, such as ransomware attacks, using an analytics engine and manager application to implement dynamic reconfiguration and remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data protection operations are manually managed in complex multi-domain environments, then operational control and decision-making are maintained, but operational efficiency decreases and security exposures increase due to inability to dynamically respond to threats

Engineering Contradiction:
Improveoperational efficiencyVSAvoidenvironment complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system enables self-service through automated threat detection, analysis, and response mechanisms. The analytics engine continuously monitors data protection operations across multi-domain environments, automatically detects security threats, and executes remediation actions without manual intervention, allowing the system to serve itself in managing complex operations

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring response protocols and maintaining readiness to execute automated remediation. When threats are detected, pre-established playbooks and response procedures are immediately activated, enabling rapid response before threats can propagate across the environment

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If traditional data protection systems are used, then basic data storage and backup functions are provided, but dynamic adjustment to threats and optimization of infrastructure cannot be achieved

Engineering Contradiction:
Improvedynamic responsivenessVSAvoidsecurity reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements continuous feedback loops where the analytics engine monitors data protection operations, detects security threats, analyzes their impact, and automatically adjusts infrastructure configuration and operations in response. This closed-loop feedback mechanism enables dynamic adaptation while maintaining security reliability through automated remediation

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system transitions from static data protection configurations to dynamic ones by enabling real-time adjustment of data collection levels, storage operations, and infrastructure configuration based on detected threats and conditions, allowing the system to adapt its behavior dynamically while maintaining reliability

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If comprehensive data collection is performed continuously, then complete monitoring coverage is achieved, but system resource consumption and operational costs increase

Engineering Contradiction:
Improvemonitoring accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The system applies partial action by collecting comprehensive data only when threats are detected or during critical events, rather than continuously. During normal operations, data collection is reduced to essential monitoring, achieving adequate monitoring accuracy while minimizing resource consumption through selective data gathering

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3684027B1Data protection automatic optimization system and method
Publication Date: 2023.08.16 COBALT IRON
  • EP3684027B1 patent drawingFigure 1
  • EP3684027B1 patent drawingFigure 2
  • EP3684027B1 patent drawingFigure 3

AI summary

A system includes a memory and at least one processor to continually analyze at least one of metrics, events, and conditions in a computer network, under normal operating conditions in the computer network, obtain a first level of data from at least one hardware device in the computer network, detect that one of a condition and an event has occurred in the computer network, automatically transmit an instruction to modify the first level of data obtained from the at least one hardware device to a second level of data more robust than the first level of data when one of the condition and the event has occurred, collect the second level of data from the at least one hardware device, and store the second level of data obtained from the at least one hardware device.