I/O Relationship Anomaly Detection in Storage Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional storage systems face inefficiencies in data management and security, particularly in detecting and responding to potential security threats, and in optimizing storage operations across multiple flash drives without redundant processes.
Innovation Solution
The implementation of a storage system architecture that includes dual storage array controllers with a midplane connection, utilizing non-volatile random access memory (NVRAM) for quick data buffering, and a direct-mapped flash storage system that initiates and controls storage operations at the operating system level, reducing redundant processes and enhancing reliability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional storage systems use multiple controllers and redundant processes for data management, then reliability is improved, but device complexity and operational inefficiency worsen
Solution Approach 1:
The patent extracts the security monitoring function from the traditional controller architecture and implements it as a separate I/O relationship detection mechanism. This allows the storage system to maintain reliability through dedicated security detection without adding complexity to the controller architecture, as the detection operates independently by monitoring I/O relationships between storage devices.
Solution Approach 2:
The patent makes the storage devices serve multiple functions: they perform both data storage operations and security threat detection through I/O relationship monitoring. The same I/O paths used for normal data operations are also monitored for security threats, eliminating the need for separate dedicated detection hardware and reducing overall system complexity.
2Reliability
If traditional storage systems implement comprehensive security monitoring, then security threat detection capability is improved, but processing time and operational overhead worsen
Solution Approach 1:
The storage devices perform self-monitoring of their own I/O relationships without requiring external security controllers or complex monitoring software. Each storage device autonomously tracks its I/O interactions with other devices and detects security threats through predefined relationship validation, eliminating the need for separate security processing infrastructure and reducing overall processing overhead.
Solution Approach 2:
The security monitoring is integrated into the continuous I/O operations of the storage system. As data operations continuously occur between storage devices, the security detection continuously monitors these same operations in real-time without requiring separate processing cycles or interrupting normal operations, thus maintaining both security capability and operational efficiency.
3Measurement precision
If storage systems use complex I/O relationship tracking for security detection, then security monitoring accuracy is improved, but productivity and data management efficiency worsen
Solution Approach 1:
The patent uses the existing I/O paths and data flow between storage devices as intermediaries for security monitoring. Instead of implementing complex separate tracking mechanisms, the system leverages the natural I/O relationships that already exist during normal data operations to detect security threats, maintaining detection accuracy while avoiding additional processing overhead that would reduce productivity.
Data Source
AI summary
An illustrative method includes a data protection system identifying one or more input operations and one or more output operations performed between a source and a storage system, identifying an anomaly in a relationship between the one or more input operations and the one or more output operations, and determining, based on the identifying of the anomaly, that the storage system is possibly being targeted by a security threat.


