Secure Period Data Protection Against After-Hours Destructive Operations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures in computing environments are inadequate during non-business hours, allowing attackers with administrative credentials to initiate destructive data operations, leading to potential data loss when administrators are not monitoring the system.
Innovation Solution
Implementing a data manager that enforces security policies to restrict and catalog destructive data operations during predefined secure periods, using secure periods to prevent such operations regardless of administrator presence, and notifying the customer system of any attempts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security measures limit access to the system during normal business hours with administrator monitoring, then the system can respond to detected potential attacks, but the system remains vulnerable to ransomware attacks outside of business hours when administrators are not actively monitoring
Solution Approach 1:
The system performs preliminary actions by establishing security policies and secure periods in advance. Administrators can define secure periods and associated policies before threats occur, allowing the system to automatically enforce protection during non-business hours without requiring real-time administrator presence. This resolves the contradiction by preparing security measures beforehand that automatically activate when needed.
Solution Approach 2:
The system enables self-service security by automatically monitoring and enforcing security policies during secure periods without requiring continuous administrator intervention. The data manager autonomously detects potential attacks, evaluates them against security policies, and responds appropriately, allowing the system to protect itself during hours when administrators are unavailable.
2Reliability
If administrators manually monitor and respond to attacks during business hours, then they can address potential threats, but destructive operations can still occur during non-business hours without any monitoring
Solution Approach 1:
The system implements periodic action by establishing recurring secure periods that automatically activate during non-business hours and deactivate during business hours. This creates a rhythmic pattern of enhanced security during vulnerable periods while allowing normal operations during monitored periods, ensuring continuous protection without requiring constant administrator attention.
Solution Approach 2:
The system employs feedback mechanisms by continuously monitoring data operations during secure periods and automatically responding to detected threats. When potential attacks are detected, the system evaluates them against security policies and takes appropriate actions, creating a closed-loop feedback system that provides attack response capability without administrator intervention.
3Adaptability or versatility
If the system allows destructive data operations during all hours with proper credentials, then operational flexibility is maintained, but attackers with stolen credentials can destroy data at any time
Solution Approach 1:
The system applies local quality by implementing different security characteristics at different times. During secure periods, the system enforces restrictive policies that block destructive operations regardless of credentials. During non-secure periods, normal operational flexibility is restored. This temporal differentiation of security properties allows the system to maintain both protection and flexibility without compromise.
Solution Approach 2:
The system performs preliminary anti-action by proactively blocking potentially harmful destructive operations before they can execute during secure periods. By evaluating data operations against security policies in advance and preventing those that match attack patterns, the system neutralizes threats before they can cause damage, while still allowing legitimate operations during non-secure periods.
Data Source
AI summary
One or more embodiments relates to a method for protecting a system during non-business hours. The method comprising: initiating, by a data manager and based on a security policy, a secure period; receiving, after the initiating, a first data operation request from a client device on a customer system; making a first determination that the first data operation request specifies a destructive operation of data in a storage system; making a second determination, using the security policy, that the first data operation request is restricted; and restricting, in response to the second determination, destructive operations of data specified in the first data operation request.


