Anomaly Detection for Storage Area Network Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current storage area network (SAN) security mechanisms fail to detect anomalous behavior, such as a compromised host causing data corruption or Denial of Service attacks, and do not effectively manage misconfigurations that lead to performance degradation in storage networks.
Innovation Solution
Implement methods and apparatus for detecting anomalies in storage traffic within a SAN, including anomaly types like Read/Write access patterns, excessive login requests, bandwidth usage, configuration changes, and hardware issues, with corresponding actions to mitigate these anomalies, such as logging, re-authentication, disabling access, and traffic rate control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional SAN security mechanisms (hard zoning, LUN zoning, read-only zoning) are used to protect storage resources, then access control is provided for authorized hosts, but they cannot detect or prevent anomalies from compromised trusted hosts causing data corruption or Denial of Service attacks
Solution Approach 1:
The patent implements a feedback mechanism by continuously monitoring storage traffic patterns and comparing them against established baselines. The system detects deviations from normal behavior and triggers appropriate responses, enabling the detection of anomalies from compromised hosts while maintaining existing access control mechanisms.
Solution Approach 2:
The patent introduces an intermediary anomaly detection system that sits between the existing SAN security mechanisms and the storage resources. This intermediary layer analyzes traffic patterns and provides an additional detection capability without disrupting the traditional zoning and access control structures.
2Productivity
If storage networks are configured for optimal performance based on usage patterns (e.g., stripe unit size configured based on predominant IO size), then performance is optimized, but any deviation from this configuration due to misconfiguration or application changes leads to significant performance degradation
Solution Approach 1:
The system establishes baseline traffic patterns including IO size distributions and monitors actual traffic against these baselines. When deviations occur that indicate misconfiguration or application changes, the system detects them and can trigger alerts or automated responses to restore optimal performance.
Data Source
AI summary
Disclosed are methods and apparatus for detecting anomalies in a storage area network (SAN). Provided are one or more anomaly type(s) and corresponding actions to be performed when the one or more anomaly types are detected. Traffic in the SAN is then inspected in order to detect the one or more provided anomaly type(s). When a one of the provided one or more anomaly type(s) is detected, one or more of the corresponding action(s) is performed. The provided anomaly type(s) may include one or more of the following: a read or write access pattern anomaly, excessive login or control requests, a bandwidth usage anomaly, a configuration anomaly, and a hardware anomaly. The provided corresponding actions may include logging and/or publishing the detected anomaly, enabling capture of the detected anomaly by an analysis device, re-authentication of a host that is responsible for the anomaly, disable access control for a host that is responsible for the anomaly, rate control of an anomalous link, and shut down of an anomalous link.


