Storage Array Ransomware Defense via Automated Snapshot Coordination
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Ransomware attacks can spread from a single infected host server to storage arrays in data centers, rendering large data sets and multiple host application instances inaccessible, with existing technologies lacking effective automated protection mechanisms.
Innovation Solution
Implementing cyber intrusion detection and data protection systems within storage arrays to detect ransomware attacks, generate alerts, and automatically perform data protection actions such as creating targetless snapshots and modifying snapshot retention schedules to safeguard data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional data protection methods are used, then data can be protected from ransomware, but the response time is slow and automated protection mechanisms are lacking
Solution Approach 1:
The system performs preliminary actions by pre-configuring data protection policies, snapshot schedules, and automation rules before a ransomware attack occurs. When an attack is detected, these pre-prepared mechanisms can be activated immediately without delay for configuration or manual intervention.
Solution Approach 2:
The data protection system implements self-service automation where the system detects ransomware attacks and executes protection actions autonomously without requiring manual intervention. The automation engine automatically triggers snapshot creation, data isolation, and recovery operations based on detected threats.
2Reliability
If manual data protection actions are performed, then data can be safeguarded, but system downtime increases and productivity decreases
Solution Approach 1:
The system eliminates manual intervention by implementing automated detection and response mechanisms. The automation engine monitors for ransomware indicators, evaluates protection policies, and executes data protection actions autonomously, maintaining continuous system operation without downtime for manual backup or recovery operations.
Solution Approach 2:
The data protection system operates continuously in the background, monitoring for threats and maintaining protection mechanisms active at all times. This continuous operation ensures that data is protected without interrupting business processes, eliminating the need to stop systems for manual backup or recovery operations.
3Reliability
If comprehensive data protection measures are implemented, then data security improves, but device complexity increases
Solution Approach 1:
The system merges multiple data protection functions (snapshot management, ransomware detection, data isolation, recovery operations) into a unified integrated platform. This consolidation reduces overall system complexity by eliminating the need for separate tools and processes while maintaining comprehensive protection capabilities.
Solution Approach 2:
The data protection system is designed as a multi-functional platform that performs various protection tasks through a single integrated architecture. The same system handles snapshot creation, ransomware detection, data isolation, and recovery operations, reducing the need for multiple specialized tools and simplifying administration.
Data Source
AI summary
Cyber intrusion detection (CID) and data protection (DP) are coordinated within a storage node to enable the capabilities of DP to be automatically and quickly utilized in response to detected threats to help protect data. CID sends an alert message to DP in response to detection of a ransomware attack or other threat. DP responds to the alert message by implementing at least one countermeasure, such as: generating new targetless snapshots of the storage objects under attack, the version data group of which the storage objects are members, or all storage objects maintained by the storage array; securing and/or preserving some of the targetless snapshots that existed before the infection; changing the targetless snapshot generation and retention schedule; and temporarily halting generation of new targetless snapshots.


