Moving Target Defense for Data Storage Virtualization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data storage devices rely on passive security techniques that are inadequate against sophisticated cyberattacks, particularly failing to protect data in transit and storage management interfaces, and are vulnerable to attacks that render devices inaccessible.
Innovation Solution
Implementing a moving target defense system through storage virtualization, which changes the device type to 'unknown', obfuscates command sets, reconfigures communications channels, and statically links interfaces to authorized applications, using techniques like LUN hopping and additional security protocols like CHAP and IPsec to dynamically and randomly alter logical unit numbers and command sets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If passive security techniques (encryption, authentication) are used to protect data storage devices, then data at rest is protected, but data in transit and management interfaces remain vulnerable to sophisticated cyberattacks
Solution Approach 1:
The patent implements moving target defense that dynamically changes device types, obfuscates command sets, and reconfigures communication channels in real-time. This transforms static security configurations into dynamic ones that adapt to threats, making it difficult for attackers to maintain successful attack vectors against data in transit and management interfaces
Solution Approach 2:
The patent combines multiple security mechanisms including device type changes, command set obfuscation, communication channel reconfiguration, and static linking of interface libraries into a composite security system. This layered approach addresses multiple vulnerability vectors simultaneously, providing comprehensive protection beyond what single passive techniques can achieve
2Reliability
If link encryption is implemented to protect data in transit, then data security during transmission is improved, but implementation complexity increases due to interoperability issues on storage networks
Solution Approach 1:
The storage appliance acts as an intermediary between host computers and data storage devices, implementing security functions including device type changes, command set obfuscation, and communication channel reconfiguration. This intermediary approach protects data in transit without requiring complex encryption implementation at each endpoint, simplifying interoperability while maintaining security
3Reliability
If the storage management interface is made more secure, then protection against attacks on device accessibility is improved, but the interface becomes more complex and harder to operate
Solution Approach 1:
The moving target defense system automatically performs device type changes, command set obfuscation, and communication channel reconfiguration without requiring manual intervention. This self-service approach enhances management interface security while maintaining ease of operation, as the security mechanisms operate transparently in the background
Solution Approach 2:
The system dynamically changes parameters such as device types, command sets, and communication channel configurations to enhance security. These parameter changes occur automatically and transparently, providing robust protection against attacks on device accessibility without complicating the user interface or operational procedures
Data Source
AI summary
Systems and methods for actively securing data storage devices utilize the technique of storage virtualization. In embodiments, would-be cyberattackers are presented with many possible “ports” or “channels” by which to communicate over a network with a data storage device. Unknown to the attacker, at any given time, only one of these ports or channels is the “correct,” or “active,” port; all of the other ports are dummies that do not permit communication with the storage device. The active port is dynamically, randomly, and/or continually reconfigured, seriously impeding the ability of the attacker to access the data storage device through the active port.

