Denial-of-service detection via storage metric anomaly analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for detecting denial-of-service attacks in information handling systems are inadequate, particularly in detecting attacks targeting storage systems and require technical expertise and are costly, with existing methods struggling to differentiate between legitimate and malicious traffic effectively.

Innovation Solution

A denial-of-service detection system that utilizes a processing system with a memory component to analyze historical and current storage system data, employing machine learning algorithms to create a multi-variate anomaly detection model, which identifies operating anomalies and performs remediation actions based on time-series similarity analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static rule-based solutions or statistical anomaly-based solutions are used to detect denial-of-service attacks, then detection capability is provided, but the solutions are costly and require technical expertise that less technical users may not have

Engineering Contradiction:
Improvedetection capabilityVSAvoidtechnical expertise requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs self-diagnosis by automatically analyzing storage system operating metrics and comparing them against learned normal patterns. The anomaly detection engine autonomously identifies denial-of-service attacks without requiring user intervention or technical expertise, making the system self-sufficient in security monitoring

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary anomaly detection engine that sits between the storage system and the user/administrator. This intermediary automatically processes raw operating metrics, performs anomaly detection using machine learning models, and translates complex security analysis into actionable insights, eliminating the need for users to possess specialized security knowledge

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If application layer traffic analysis and filtering is used to detect denial-of-service attacks, then IP-based prevention is achieved, but the solutions have difficulties detecting attacks directed to storage systems

Engineering Contradiction:
Improveattack detection accuracyVSAvoidstorage system coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from analyzing network traffic at the application layer (traditional IP-based approach) to analyzing storage system operating metrics at the storage layer. By examining dimensions such as I/O operations per second, latency, and throughput directly from storage devices, the system detects attacks targeting storage systems regardless of the attack vector used at higher network layers

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The anomaly detection engine is designed to be universally applicable to storage systems regardless of the specific attack type or protocol. It monitors multiple operating metrics simultaneously and uses machine learning to identify patterns indicative of denial-of-service attacks, making it versatile against various attack vectors including those directed at storage systems, servers, and network infrastructure

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Speed

If current storage system data is analyzed without historical comparison, then real-time monitoring is achieved, but operating anomalies cannot be effectively identified

Engineering Contradiction:
Improvereal-time monitoring capabilityVSAvoidanomaly identification accuracy
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The system performs preliminary actions by continuously collecting and storing historical operating metrics before attacks occur. This historical data serves as a baseline for comparison, enabling the anomaly detection engine to quickly identify deviations from normal operation in real-time without sacrificing detection accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where historical operating data continuously informs the anomaly detection process. The system compares current metrics against historical patterns, learns from past behavior, and adjusts its understanding of normal operation over time, thereby maintaining both real-time monitoring capability and high anomaly identification accuracy

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11743287B2Denial-of-service detection system
Publication Date: 2023.08.29 DELL PROD LP
  • US11743287B2 patent drawing
  • US11743287B2 patent drawing
  • US11743287B2 patent drawing

AI summary

A denial-of-service detection system includes a denial-of-service detection subsystem coupled to a plurality of storage systems via a network. The denial-of-service detection subsystem receives current first storage system data for each of a plurality of different storage system operating metrics from a first storage system included in the plurality of storage systems. Based on a historical storage system data for each of the plurality of different storage system operating metrics that was previously received from the plurality of storage devices, the denial-of-service subsystem detects an operating anomaly in the current first storage system data for at least one of the plurality of different storage system operating metrics, identifies a time-series similarity in a subset of respective time-series of the current first storage system data for each of the plurality of different storage system operating metrics for which the operating anomaly was detected and, in response, performs a denial-of-service remediation action.