I/O Relationship Anomaly Detection in Storage Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional storage systems face inefficiencies in data management and security, particularly in detecting and responding to potential security threats, and in optimizing storage operations across multiple flash drives without redundant processes.

Innovation Solution

The implementation of a storage system architecture that includes dual storage array controllers with a midplane connection, utilizing non-volatile random access memory (NVRAM) for quick data buffering, and a direct-mapped flash storage system that initiates and controls storage operations at the operating system level, reducing redundant processes and enhancing reliability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional storage systems use multiple controllers and redundant processes for data management, then reliability is improved, but device complexity and operational inefficiency worsen

Engineering Contradiction:
Improvestorage system reliabilityVSAvoidcontroller architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security monitoring function from the traditional controller architecture and implements it as a separate I/O relationship detection mechanism. This allows the storage system to maintain reliability through dedicated security detection without adding complexity to the controller architecture, as the detection operates independently by monitoring I/O relationships between storage devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent makes the storage devices serve multiple functions: they perform both data storage operations and security threat detection through I/O relationship monitoring. The same I/O paths used for normal data operations are also monitored for security threats, eliminating the need for separate dedicated detection hardware and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional storage systems implement comprehensive security monitoring, then security threat detection capability is improved, but processing time and operational overhead worsen

Engineering Contradiction:
Improvesecurity threat detection capabilityVSAvoidprocessing time for security monitoring
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The storage devices perform self-monitoring of their own I/O relationships without requiring external security controllers or complex monitoring software. Each storage device autonomously tracks its I/O interactions with other devices and detects security threats through predefined relationship validation, eliminating the need for separate security processing infrastructure and reducing overall processing overhead.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The security monitoring is integrated into the continuous I/O operations of the storage system. As data operations continuously occur between storage devices, the security detection continuously monitors these same operations in real-time without requiring separate processing cycles or interrupting normal operations, thus maintaining both security capability and operational efficiency.

Inventive Principle:
Principle #20Continuity of useful action

3Measurement precision

If storage systems use complex I/O relationship tracking for security detection, then security monitoring accuracy is improved, but productivity and data management efficiency worsen

Engineering Contradiction:
Improvesecurity threat detection accuracyVSAvoiddata management efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent uses the existing I/O paths and data flow between storage devices as intermediaries for security monitoring. Instead of implementing complex separate tracking mechanisms, the system leverages the natural I/O relationships that already exist during normal data operations to detect security threats, maintaining detection accuracy while avoiding additional processing overhead that would reduce productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11720714B2Inter-I/O relationship based detection of a security threat to a storage system
Publication Date: 2023.08.08 PURE STORAGE INC
  • US11720714B2 patent drawing
  • US11720714B2 patent drawing
  • US11720714B2 patent drawing

AI summary

An illustrative method includes a data protection system identifying one or more input operations and one or more output operations performed between a source and a storage system, identifying an anomaly in a relationship between the one or more input operations and the one or more output operations, and determining, based on the identifying of the anomaly, that the storage system is possibly being targeted by a security threat.