Read-Only Backup Storage Ransomware Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for protecting backup storage devices from ransomware attacks are inadequate, as they can be vulnerable to malicious software viruses, especially during data recovery processes, which may lead to lengthy recovery times and increased business disruption.

Innovation Solution

A backup storage system that operates primarily in a read-only mode, taking snapshots of data volumes during scheduled read/write periods and switching to read/write mode only during designated backup windows, ensuring data immutability and independence from primary storage servers, thereby reducing the risk of attack and enabling rapid data recovery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If backup storage devices operate in read/write mode to accept data backups, then backup functionality is enabled, but vulnerability to ransomware attacks increases

Engineering Contradiction:
Improvebackup functionalityVSAvoidransomware vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The backup storage device dynamically switches between read-only and read/write modes based on operational requirements. During normal operation, the device remains in read-only mode to prevent ransomware attacks. During scheduled backup windows, it temporarily transitions to read/write mode to accept backups, then immediately returns to read-only mode, minimizing exposure time to potential attacks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements periodic backup operations where the backup storage device alternates between read-only state and read/write state at predetermined intervals. This periodic switching allows the system to maintain security while enabling necessary backup functionality at scheduled times.

Inventive Principle:
Principle #19Periodic action

2Object-affected harmful factors

If backup storage devices remain in read-only mode to prevent ransomware attacks, then security is improved, but backup capability is reduced

Engineering Contradiction:
Improveransomware protectionVSAvoidbackup capability
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The backup storage device transitions from a static read-only state to a dynamic state that allows temporary read/write access during scheduled backup windows. This dynamic behavior maintains security while enabling backup capability when needed, resolving the contradiction between protection and functionality.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the write-protection parameter of the backup storage device temporarily during scheduled backup operations. By dynamically adjusting this parameter from protected to unprotected and back, the system enables backup capability while maintaining security during non-backup periods.

Inventive Principle:
Principle #35Parameter changes

3Loss of time

If frequent snapshots are taken during backup operations, then data recovery speed is improved, but system complexity increases

Engineering Contradiction:
Improverecovery timeVSAvoidsnapshot management
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system takes snapshots of the backup storage device at predetermined intervals during backup operations, preparing recovery points in advance. This preliminary action ensures that if ransomware attacks occur, the system can quickly restore to the most recent snapshot without extensive recovery time, while the automation keeps complexity manageable.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11829257B2Secondary storage protection
Publication Date: 2023.11.28 SPECTRA LOGIC CORP
  • US11829257B2 patent drawing
  • US11829257B2 patent drawing
  • US11829257B2 patent drawing

AI summary

Due to the threat of virus attacks and ransom ware, an apparatus and methods for protecting backup storage devices from malicious software virus attacks is explored. An independent backup storage system is connected to a primary storage server over an undiscoverable communications line. The backup storage system is a read-only backup storage system most of the time buffering the backup storage system from a virus or attack on the primary storage server. The backup storage system changes from a read-only backup storage system to a read/write backup storage system only during a backup window of time where data is backed up to the backup storage system. A snapshot of the backup data is maintained in the backup storage system and can be made available at numerous points of time in the past if the data primary storage server becomes corrupted.