Storage Snapshot Malware Scanning in an Isolated Guest OS
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing host-based antivirus solutions in enterprise storage systems are vulnerable to malware attacks, which can disable them, rendering scans ineffective in combating cybersecurity threats.
Innovation Solution
An embedded malware detector within a guest operating system on a storage processor captures snapshots of storage devices, scans them for malware, and outputs detection indications, immune to malware execution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If host-based antivirus solutions are used in enterprise storage systems, then malware detection capability is provided, but the solutions are vulnerable to malware attacks that can disable them
Solution Approach 1:
The patent introduces a sandboxed environment as an intermediary layer between the storage system and the antivirus software. The sandbox isolates the antivirus execution context, preventing malware from attacking or disabling the antivirus solution while maintaining detection capability. This mediator protects the system against harmful factors while preserving the reliability of malware detection.
Solution Approach 2:
The system segments the storage processing functions by separating the antivirus detection workload into a distinct sandboxed guest operating system. This segmentation isolates the antivirus component from the main storage system, allowing it to operate independently and resist attacks that would otherwise compromise system-wide security.
2Reliability
If snapshots are scanned for malware using embedded malware detector, then malware detection is achieved, but performance hits occur due to scanning overhead
Solution Approach 1:
The system performs preliminary actions by creating snapshots of storage devices before scanning them for malware. These snapshots capture the state of data at specific points in time, allowing the malware detector to scan copies rather than live data. This preliminary snapshot creation enables thorough scanning without impacting the performance of the primary storage operations.
Solution Approach 2:
The patent uses copying by creating snapshot copies of storage device data for malware scanning purposes. Instead of scanning the original live data which would impact storage performance, the system scans replicated snapshot copies. This copying approach maintains detection reliability while minimizing performance overhead on the production storage system.
3Productivity
If multiple guest operating systems are executed on a storage processor, then resource utilization is improved, but system complexity increases
Solution Approach 1:
The storage processor is designed with multi-functionality to execute multiple guest operating systems simultaneously. The same hardware platform supports both traditional storage workloads and sandboxed antivirus detection workloads, maximizing resource utilization. This universal approach allows a single processor to handle diverse functions without requiring separate dedicated hardware for each function.
Solution Approach 2:
The system implements nesting by placing a guest operating system containing the malware detector inside the storage processor's virtualization environment. This nested structure allows the antivirus functionality to be embedded within the existing storage processing architecture, managing complexity through hierarchical organization rather than requiring completely separate systems.
Data Source
AI summary
A method, comprising: executing an embedded malware detector, the embedded malware detector being executed inside a first guest operating system, the first guest operating system being executed on a storage processor that is part of a storage system, the storage processor being configured to execute one or more second guest operating systems in addition to the first guest operating system, each of the second guest operating systems being arranged to execute software for reading and/or writing data to one or more storage devices that are provided in the storage system; identifying, by the embedded malware detector, a given one of the storage devices; obtaining, by the embedded malware detector, a snapshot of the given one of the storage devices; mounting, by the embedded malware detector, the snapshot in the first guest operating system; scanning the mounted snapshot for malware.


