DCIM Security Scanning Engine for Data Center Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern data centers face security risks due to potential infections of viruses or malware in on-board computers of managed infrastructure devices like CRAC units and PDUs, which can disrupt the operation of entire server rows or even the entire data center, highlighting the need for real-time security monitoring and threat detection.

Innovation Solution

A system incorporating a data center infrastructure management (DCIM) system with a remote access appliance, including a complex event processor (CEP) engine, discovery engine, and security detection engine, to monitor and detect security threats, scan for malware, and quarantine or remove infected files or processes from managed infrastructure devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real-time security scanning is implemented on managed infrastructure devices, then security threat detection capability is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity threat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security scanning engine as an intermediary component that operates between the DCIM system and managed infrastructure devices. This engine acts as a mediator that performs security scans on device files and processes without requiring deep integration into the device's core operations, thereby improving security detection while maintaining manageable system complexity through modular architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security monitoring system is divided into separate functional modules including a security scanning engine, event processing engine, and integration with DCIM components. This segmentation allows each module to perform specific security functions independently, improving overall detection capability while keeping individual components simple and maintainable

Inventive Principle:
Principle #1Segmentation

2Reliability

If comprehensive security monitoring is deployed across all managed infrastructure devices, then security coverage is improved, but operational overhead and processing time increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic security scanning where the security scanning engine performs scans at scheduled intervals rather than continuously monitoring all devices simultaneously. This periodic approach ensures comprehensive security coverage across all managed infrastructure devices while controlling processing time and operational overhead by batching scan operations

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent applies security scanning selectively to critical files and processes based on risk assessment, rather than uniformly scanning every byte of data on every device. The event processing engine prioritizes analysis of high-risk events and security-relevant data, achieving effective security coverage with reduced processing time compared to exhaustive scanning of all device data

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If security threats are detected and mitigated in real-time, then operational disruption is reduced, but computational resources and energy consumption increase

Engineering Contradiction:
Improveoperational continuityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system implements automated response mechanisms where detected security threats are automatically quarantined or mitigated by the security scanning engine without requiring manual intervention. The event processing engine automatically correlates security events and triggers appropriate responses, maintaining operational continuity while reducing the computational overhead associated with human analysis and response actions

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2788913B1Data center infrastructure management system incorporating security for managed infrastructure devices
Publication Date: 2019.10.23 VERTIV IT SYST INC
  • EP2788913B1 patent drawingFigure 1
  • EP2788913B1 patent drawingFigure 2
  • EP2788913B1 patent drawingFigure 3

AI summary

A system is disclosed for enhancing detection of a security threat to a managed infrastructure device operating within a data center. The system may have a data center infrastructure management (DCIM) system for monitoring operation of the managed infrastructure device. The DCIM system may include a remote access appliance for communicating with the managed infrastructure device. The managed infrastructure device may include an on-board computer. The remote access appliance may include an engine configured to detect if information to be communicated to the on-board computer poses a security threat to the managed infrastructure device.