Denial-of-service detection via storage metric anomaly analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions for detecting denial-of-service attacks in information handling systems are inadequate, particularly in detecting attacks targeting storage systems and require technical expertise and are costly, with existing methods struggling to differentiate between legitimate and malicious traffic effectively.
Innovation Solution
A denial-of-service detection system that utilizes a processing system with a memory component to analyze historical and current storage system data, employing machine learning algorithms to create a multi-variate anomaly detection model, which identifies operating anomalies and performs remediation actions based on time-series similarity analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static rule-based solutions or statistical anomaly-based solutions are used to detect denial-of-service attacks, then detection capability is provided, but the solutions are costly and require technical expertise that less technical users may not have
Solution Approach 1:
The system performs self-diagnosis by automatically analyzing storage system operating metrics and comparing them against learned normal patterns. The anomaly detection engine autonomously identifies denial-of-service attacks without requiring user intervention or technical expertise, making the system self-sufficient in security monitoring
Solution Approach 2:
The patent introduces an intermediary anomaly detection engine that sits between the storage system and the user/administrator. This intermediary automatically processes raw operating metrics, performs anomaly detection using machine learning models, and translates complex security analysis into actionable insights, eliminating the need for users to possess specialized security knowledge
2Reliability
If application layer traffic analysis and filtering is used to detect denial-of-service attacks, then IP-based prevention is achieved, but the solutions have difficulties detecting attacks directed to storage systems
Solution Approach 1:
The patent transitions from analyzing network traffic at the application layer (traditional IP-based approach) to analyzing storage system operating metrics at the storage layer. By examining dimensions such as I/O operations per second, latency, and throughput directly from storage devices, the system detects attacks targeting storage systems regardless of the attack vector used at higher network layers
Solution Approach 2:
The anomaly detection engine is designed to be universally applicable to storage systems regardless of the specific attack type or protocol. It monitors multiple operating metrics simultaneously and uses machine learning to identify patterns indicative of denial-of-service attacks, making it versatile against various attack vectors including those directed at storage systems, servers, and network infrastructure
3Speed
If current storage system data is analyzed without historical comparison, then real-time monitoring is achieved, but operating anomalies cannot be effectively identified
Solution Approach 1:
The system performs preliminary actions by continuously collecting and storing historical operating metrics before attacks occur. This historical data serves as a baseline for comparison, enabling the anomaly detection engine to quickly identify deviations from normal operation in real-time without sacrificing detection accuracy
Solution Approach 2:
The patent implements a feedback mechanism where historical operating data continuously informs the anomaly detection process. The system compares current metrics against historical patterns, learns from past behavior, and adjusts its understanding of normal operation over time, thereby maintaining both real-time monitoring capability and high anomaly identification accuracy
Data Source
AI summary
A denial-of-service detection system includes a denial-of-service detection subsystem coupled to a plurality of storage systems via a network. The denial-of-service detection subsystem receives current first storage system data for each of a plurality of different storage system operating metrics from a first storage system included in the plurality of storage systems. Based on a historical storage system data for each of the plurality of different storage system operating metrics that was previously received from the plurality of storage devices, the denial-of-service subsystem detects an operating anomaly in the current first storage system data for at least one of the plurality of different storage system operating metrics, identifies a time-series similarity in a subset of respective time-series of the current first storage system data for each of the plurality of different storage system operating metrics for which the operating anomaly was detected and, in response, performs a denial-of-service remediation action.


