Host Multi-Path Layer IO Analytics for Malware Defense
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Storage systems are vulnerable to attacks involving ransomware and other malware, as it is difficult to determine if an application process running on a host device has been infected with malware, leaving data in logical storage devices at risk.
Innovation Solution
Implementing IO analytics in a multi-path layer of host devices to detect malware and generate alerts, which collaborates with the storage system to implement defensive measures against ransomware and other malware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional storage systems are used without IO analytics, then device complexity is low, but security against malware is insufficient
Solution Approach 1:
The system performs preliminary analysis of IO operations by collecting metadata (process IDs, user IDs, access types) and analyzing access patterns before malware can execute harmful actions. The multi-path layer intercepts and analyzes IO operations proactively, generating alerts before data is compromised
Solution Approach 2:
The patent introduces a multi-path layer as an intermediary component between the host application layer and storage system. This intermediary captures IO operations, performs security analytics, and collaborates with the storage system to implement defensive measures without requiring fundamental changes to existing storage architecture
2Measurement precision
If IO analytics are implemented to detect malware, then security detection capability is improved, but processing overhead increases
Solution Approach 1:
The system extracts only essential metadata from IO operations (process IDs, user IDs, access types, file paths) for analysis, rather than analyzing complete IO data. This selective extraction approach enables effective malware detection while minimizing processing overhead and resource consumption
Solution Approach 2:
The multi-path layer leverages existing system resources and infrastructure to perform security analytics. It utilizes already-collected process and user identification information from the operating system, avoiding redundant data collection and reducing overall processing requirements
Data Source
AI summary
An apparatus comprises at least one processing device configured to implement a multi-path layer in a host device, wherein the multi-path layer controls delivery of input-output (IO) operations from the host device to a storage system over selected ones of a plurality of paths through a network. The multi-path layer is configured, for each of at least a subset of the IO operations, to store at least a process identifier, a user identifier and an access type for the IO operation. The multi-path layer is further configured to perform analytics on the stored process identifiers, user identifiers and access types to detect an access pattern, and responsive to the detected access pattern having one or more designated characteristics associated with malware, to generate an alert. The alert may be generated by inserting security alert indicators into respective ones of the IO operations, for extraction therefrom by the storage system.


