Anomaly Detection for Storage Area Network Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current storage area network (SAN) security mechanisms fail to detect anomalous behavior, such as a compromised host causing data corruption or Denial of Service attacks, and do not effectively manage misconfigurations that lead to performance degradation in storage networks.

Innovation Solution

Implement methods and apparatus for detecting anomalies in storage traffic within a SAN, including anomaly types like Read/Write access patterns, excessive login requests, bandwidth usage, configuration changes, and hardware issues, with corresponding actions to mitigate these anomalies, such as logging, re-authentication, disabling access, and traffic rate control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional SAN security mechanisms (hard zoning, LUN zoning, read-only zoning) are used to protect storage resources, then access control is provided for authorized hosts, but they cannot detect or prevent anomalies from compromised trusted hosts causing data corruption or Denial of Service attacks

Engineering Contradiction:
Improvestorage resource protectionVSAvoidanomaly detection capability
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent implements a feedback mechanism by continuously monitoring storage traffic patterns and comparing them against established baselines. The system detects deviations from normal behavior and triggers appropriate responses, enabling the detection of anomalies from compromised hosts while maintaining existing access control mechanisms.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary anomaly detection system that sits between the existing SAN security mechanisms and the storage resources. This intermediary layer analyzes traffic patterns and provides an additional detection capability without disrupting the traditional zoning and access control structures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If storage networks are configured for optimal performance based on usage patterns (e.g., stripe unit size configured based on predominant IO size), then performance is optimized, but any deviation from this configuration due to misconfiguration or application changes leads to significant performance degradation

Engineering Contradiction:
Improvestorage network performanceVSAvoidconfiguration deviation detection
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The system establishes baseline traffic patterns including IO size distributions and monitors actual traffic against these baselines. When deviations occur that indicate misconfiguration or application changes, the system detects them and can trigger alerts or automated responses to restore optimal performance.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7793138B2Anomaly detection for storage traffic in a data center
Publication Date: 2010.09.07 CISCO TECHNOLOGY INC
  • US7793138B2 patent drawing
  • US7793138B2 patent drawing
  • US7793138B2 patent drawing

AI summary

Disclosed are methods and apparatus for detecting anomalies in a storage area network (SAN). Provided are one or more anomaly type(s) and corresponding actions to be performed when the one or more anomaly types are detected. Traffic in the SAN is then inspected in order to detect the one or more provided anomaly type(s). When a one of the provided one or more anomaly type(s) is detected, one or more of the corresponding action(s) is performed. The provided anomaly type(s) may include one or more of the following: a read or write access pattern anomaly, excessive login or control requests, a bandwidth usage anomaly, a configuration anomaly, and a hardware anomaly. The provided corresponding actions may include logging and/or publishing the detected anomaly, enabling capture of the detected anomaly by an analysis device, re-authentication of a host that is responsible for the anomaly, disable access control for a host that is responsible for the anomaly, rate control of an anomalous link, and shut down of an anomalous link.