Failover System Hardening During Cyberattack
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current failover systems experience prolonged downtime during cyberattacks, and standby equipment can also be compromised, leading to uninterrupted service disruptions and potential data loss.
Innovation Solution
The system detects ongoing cyberattacks and proactively performs failover by identifying and hardening a mirror site, redirecting client requests, and determining an anticipated completion time to minimize downtime and prevent the attack from affecting the failover device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional failover is performed after a cyberattack completes, then the standby system can take over, but the downtime is prolonged (multiple hours) and the standby system may also be compromised
Solution Approach 1:
The system performs preliminary hardening of the failover device by making it read-only and updating access control lists before the cyberattack completes, so that when failover occurs, the standby system is already protected and ready to immediately accept traffic without being compromised
Solution Approach 2:
The system applies counter-measures (hardening the failover device) in advance to offset or reduce the harmful effects of the cyberattack before it can affect the standby system, thereby preventing the attack from propagating to the failover target
2Reliability
If the failover device is hardened to prevent cyberattack effects, then the failover device is protected, but this requires additional time and configuration steps
Solution Approach 1:
The system automatically performs hardening operations on the failover device including making it read-only and updating access control lists without manual intervention, allowing the system to self-protect against the cyberattack while reducing operational complexity
Data Source
AI summary
Disclosed herein are systems and method for performing failover during a cyberattack. In one exemplary aspect, a method comprises monitoring a computing device for the cyberattack and detecting that the cyberattack is in progress. While the cyberattack is in progress, the method comprises identifying a failover device that corresponds to the computing device, hardening the failover device to prevent the cyberattack from affecting the failover device, and performing failover by switching from the computing device to the failover device.


