Host Multi-Path Layer IO Analytics for Malware Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Storage systems are vulnerable to attacks involving ransomware and other malware, as it is difficult to determine if an application process running on a host device has been infected with malware, leaving data in logical storage devices at risk.

Innovation Solution

Implementing IO analytics in a multi-path layer of host devices to detect malware and generate alerts, which collaborates with the storage system to implement defensive measures against ransomware and other malware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional storage systems are used without IO analytics, then device complexity is low, but security against malware is insufficient

Engineering Contradiction:
Improvesecurity against malwareVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary analysis of IO operations by collecting metadata (process IDs, user IDs, access types) and analyzing access patterns before malware can execute harmful actions. The multi-path layer intercepts and analyzes IO operations proactively, generating alerts before data is compromised

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a multi-path layer as an intermediary component between the host application layer and storage system. This intermediary captures IO operations, performs security analytics, and collaborates with the storage system to implement defensive measures without requiring fundamental changes to existing storage architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If IO analytics are implemented to detect malware, then security detection capability is improved, but processing overhead increases

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidprocessing overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system extracts only essential metadata from IO operations (process IDs, user IDs, access types, file paths) for analysis, rather than analyzing complete IO data. This selective extraction approach enables effective malware detection while minimizing processing overhead and resource consumption

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The multi-path layer leverages existing system resources and infrastructure to perform security analytics. It utilizes already-collected process and user identification information from the operating system, avoiding redundant data collection and reducing overall processing requirements

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12299118B2Host multi-path layer with IO analytics for malware defense
Publication Date: 2025.05.13 DELL PROD LP
  • US12299118B2 patent drawing
  • US12299118B2 patent drawing
  • US12299118B2 patent drawing

AI summary

An apparatus comprises at least one processing device configured to implement a multi-path layer in a host device, wherein the multi-path layer controls delivery of input-output (IO) operations from the host device to a storage system over selected ones of a plurality of paths through a network. The multi-path layer is configured, for each of at least a subset of the IO operations, to store at least a process identifier, a user identifier and an access type for the IO operation. The multi-path layer is further configured to perform analytics on the stored process identifiers, user identifiers and access types to detect an access pattern, and responsive to the detected access pattern having one or more designated characteristics associated with malware, to generate an alert. The alert may be generated by inserting security alert indicators into respective ones of the IO operations, for extraction therefrom by the storage system.