DCIM Security Scanning Engine for Data Center Infrastructure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern data centers face security risks due to potential infections of viruses or malware in on-board computers of managed infrastructure devices like CRAC units and PDUs, which can disrupt the operation of entire server rows or even the entire data center, highlighting the need for real-time security monitoring and threat detection.
Innovation Solution
A system incorporating a data center infrastructure management (DCIM) system with a remote access appliance, including a complex event processor (CEP) engine, discovery engine, and security detection engine, to monitor and detect security threats, scan for malware, and quarantine or remove infected files or processes from managed infrastructure devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If real-time security scanning is implemented on managed infrastructure devices, then security threat detection capability is improved, but system complexity and resource consumption increase
Solution Approach 1:
The patent introduces a security scanning engine as an intermediary component that operates between the DCIM system and managed infrastructure devices. This engine acts as a mediator that performs security scans on device files and processes without requiring deep integration into the device's core operations, thereby improving security detection while maintaining manageable system complexity through modular architecture
Solution Approach 2:
The security monitoring system is divided into separate functional modules including a security scanning engine, event processing engine, and integration with DCIM components. This segmentation allows each module to perform specific security functions independently, improving overall detection capability while keeping individual components simple and maintainable
2Reliability
If comprehensive security monitoring is deployed across all managed infrastructure devices, then security coverage is improved, but operational overhead and processing time increase
Solution Approach 1:
The system implements periodic security scanning where the security scanning engine performs scans at scheduled intervals rather than continuously monitoring all devices simultaneously. This periodic approach ensures comprehensive security coverage across all managed infrastructure devices while controlling processing time and operational overhead by batching scan operations
Solution Approach 2:
The patent applies security scanning selectively to critical files and processes based on risk assessment, rather than uniformly scanning every byte of data on every device. The event processing engine prioritizes analysis of high-risk events and security-relevant data, achieving effective security coverage with reduced processing time compared to exhaustive scanning of all device data
3Reliability
If security threats are detected and mitigated in real-time, then operational disruption is reduced, but computational resources and energy consumption increase
Solution Approach 1:
The system implements automated response mechanisms where detected security threats are automatically quarantined or mitigated by the security scanning engine without requiring manual intervention. The event processing engine automatically correlates security events and triggers appropriate responses, maintaining operational continuity while reducing the computational overhead associated with human analysis and response actions
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system is disclosed for enhancing detection of a security threat to a managed infrastructure device operating within a data center. The system may have a data center infrastructure management (DCIM) system for monitoring operation of the managed infrastructure device. The DCIM system may include a remote access appliance for communicating with the managed infrastructure device. The managed infrastructure device may include an on-board computer. The remote access appliance may include an engine configured to detect if information to be communicated to the on-board computer poses a security threat to the managed infrastructure device.