Storage Array Encryption Attack Detection Through Bit Density
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Storage arrays are vulnerable to cyber-attacks, particularly encryption-related attacks that encrypt and overwrite data, which current host-based detection methods fail to detect in real-time.
Innovation Solution
Intercept IO write requests, analyze bit density and entropy scores, and implement machine learning to identify and mitigate cyber-attacks by comparing access rates and bit densities against predefined thresholds.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If host-based detection methods are used to monitor storage array access, then detection capability is provided, but real-time detection of encryption attacks is not achieved
Solution Approach 1:
The patent implements preliminary action by establishing baseline access patterns and bit density thresholds before attacks occur. The system pre-configures entropy thresholds and access rate limits that trigger automated responses, enabling detection and mitigation before encryption attacks complete their malicious cycles
Solution Approach 2:
The system implements continuous feedback loops that monitor storage access patterns, bit densities, and entropy scores in real-time. When anomalies are detected, the system immediately feeds this information back to adjust monitoring parameters and trigger mitigation responses, creating a closed-loop detection system that operates without delay
2Quantity of substance
If storage arrays store vast amounts of data without monitoring, then storage capacity is maximized, but vulnerability to cyber-attacks increases
Solution Approach 1:
The patent introduces an intermediary detection layer that sits between the storage array and access requests. This intermediary monitors bit densities, entropy scores, and access patterns without interfering with normal storage operations, detecting malicious patterns while allowing legitimate data storage and access to continue uninterrupted
Solution Approach 2:
The system implements self-service by automatically detecting anomalies and triggering mitigation responses without external intervention. When the monitoring system detects encryption attack patterns, it autonomously initiates response protocols including alerting security systems and potentially blocking suspicious access operations
3Reliability
If IO write requests are intercepted and analyzed, then attack detection capability is improved, but processing overhead increases
Solution Approach 1:
The patent applies local quality by focusing analysis only on specific characteristics of IO requests that indicate potential attacks. Instead of analyzing entire data sets, the system concentrates computational resources on calculating entropy scores and bit density metrics for suspicious access patterns, reducing overall processing overhead while maintaining detection effectiveness
Solution Approach 2:
The system dynamically adjusts monitoring parameters based on observed access patterns and threat levels. When normal operation is detected, monitoring intensity is reduced; when anomalies are detected, the system increases analysis depth and frequency, optimizing processing overhead relative to actual detection needs
Data Source
AI summary
One or more aspects of the present disclosure relate to protecting the integrity of datasets stored by a storage array. In embodiments, one or more IO write requests from an input/output (IO) workload are intercepted. Additionally, a likely cyber-attack event is identified based on a bit density of write data corresponding to the one or more IO requests. Further, the cyber-attack event is mitigated.


