Storage Array Ransomware Defense via Automated Snapshot Coordination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ransomware attacks can spread from a single infected host server to storage arrays in data centers, rendering large data sets and multiple host application instances inaccessible, with existing technologies lacking effective automated protection mechanisms.

Innovation Solution

Implementing cyber intrusion detection and data protection systems within storage arrays to detect ransomware attacks, generate alerts, and automatically perform data protection actions such as creating targetless snapshots and modifying snapshot retention schedules to safeguard data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional data protection methods are used, then data can be protected from ransomware, but the response time is slow and automated protection mechanisms are lacking

Engineering Contradiction:
Improvedata protection effectivenessVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring data protection policies, snapshot schedules, and automation rules before a ransomware attack occurs. When an attack is detected, these pre-prepared mechanisms can be activated immediately without delay for configuration or manual intervention.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The data protection system implements self-service automation where the system detects ransomware attacks and executes protection actions autonomously without requiring manual intervention. The automation engine automatically triggers snapshot creation, data isolation, and recovery operations based on detected threats.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual data protection actions are performed, then data can be safeguarded, but system downtime increases and productivity decreases

Engineering Contradiction:
Improvedata protection capabilityVSAvoidsystem operational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system eliminates manual intervention by implementing automated detection and response mechanisms. The automation engine monitors for ransomware indicators, evaluates protection policies, and executes data protection actions autonomously, maintaining continuous system operation without downtime for manual backup or recovery operations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The data protection system operates continuously in the background, monitoring for threats and maintaining protection mechanisms active at all times. This continuous operation ensures that data is protected without interrupting business processes, eliminating the need to stop systems for manual backup or recovery operations.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If comprehensive data protection measures are implemented, then data security improves, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges multiple data protection functions (snapshot management, ransomware detection, data isolation, recovery operations) into a unified integrated platform. This consolidation reduces overall system complexity by eliminating the need for separate tools and processes while maintaining comprehensive protection capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The data protection system is designed as a multi-functional platform that performs various protection tasks through a single integrated architecture. The same system handles snapshot creation, ransomware detection, data isolation, and recovery operations, reducing the need for multiple specialized tools and simplifying administration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250053653A1Coordinating cyber intrustion detection and data protection for responding to ransomware attacks
Publication Date: 2025.02.13 DELL PROD LP
  • US20250053653A1 patent drawing
  • US20250053653A1 patent drawing
  • US20250053653A1 patent drawing

AI summary

Cyber intrusion detection (CID) and data protection (DP) are coordinated within a storage node to enable the capabilities of DP to be automatically and quickly utilized in response to detected threats to help protect data. CID sends an alert message to DP in response to detection of a ransomware attack or other threat. DP responds to the alert message by implementing at least one countermeasure, such as: generating new targetless snapshots of the storage objects under attack, the version data group of which the storage objects are members, or all storage objects maintained by the storage array; securing and/or preserving some of the targetless snapshots that existed before the infection; changing the targetless snapshot generation and retention schedule; and temporarily halting generation of new targetless snapshots.