Moving Target Defense for Data Storage Virtualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data storage devices rely on passive security techniques that are inadequate against sophisticated cyberattacks, particularly failing to protect data in transit and storage management interfaces, and are vulnerable to attacks that render devices inaccessible.

Innovation Solution

Implementing a moving target defense system through storage virtualization, which changes the device type to 'unknown', obfuscates command sets, reconfigures communications channels, and statically links interfaces to authorized applications, using techniques like LUN hopping and additional security protocols like CHAP and IPsec to dynamically and randomly alter logical unit numbers and command sets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If passive security techniques (encryption, authentication) are used to protect data storage devices, then data at rest is protected, but data in transit and management interfaces remain vulnerable to sophisticated cyberattacks

Engineering Contradiction:
Improvesecurity protectionVSAvoidvulnerability to cyberattacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements moving target defense that dynamically changes device types, obfuscates command sets, and reconfigures communication channels in real-time. This transforms static security configurations into dynamic ones that adapt to threats, making it difficult for attackers to maintain successful attack vectors against data in transit and management interfaces

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent combines multiple security mechanisms including device type changes, command set obfuscation, communication channel reconfiguration, and static linking of interface libraries into a composite security system. This layered approach addresses multiple vulnerability vectors simultaneously, providing comprehensive protection beyond what single passive techniques can achieve

Inventive Principle:
Principle #40Composite materials

2Reliability

If link encryption is implemented to protect data in transit, then data security during transmission is improved, but implementation complexity increases due to interoperability issues on storage networks

Engineering Contradiction:
Improvedata in transit protectionVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The storage appliance acts as an intermediary between host computers and data storage devices, implementing security functions including device type changes, command set obfuscation, and communication channel reconfiguration. This intermediary approach protects data in transit without requiring complex encryption implementation at each endpoint, simplifying interoperability while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the storage management interface is made more secure, then protection against attacks on device accessibility is improved, but the interface becomes more complex and harder to operate

Engineering Contradiction:
Improvemanagement interface securityVSAvoidinterface usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The moving target defense system automatically performs device type changes, command set obfuscation, and communication channel reconfiguration without requiring manual intervention. This self-service approach enhances management interface security while maintaining ease of operation, as the security mechanisms operate transparently in the background

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically changes parameters such as device types, command sets, and communication channel configurations to enhance security. These parameter changes occur automatically and transparently, providing robust protection against attacks on device accessibility without complicating the user interface or operational procedures

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10558802B2Moving target defenses for data storage devices
Publication Date: 2020.02.11 NEXITECH INC
  • US10558802B2 patent drawing
  • US10558802B2 patent drawing

AI summary

Systems and methods for actively securing data storage devices utilize the technique of storage virtualization. In embodiments, would-be cyberattackers are presented with many possible “ports” or “channels” by which to communicate over a network with a data storage device. Unknown to the attacker, at any given time, only one of these ports or channels is the “correct,” or “active,” port; all of the other ports are dummies that do not permit communication with the storage device. The active port is dynamically, randomly, and/or continually reconfigured, seriously impeding the ability of the attacker to access the data storage device through the active port.