Storage Controller Deep Packet Inspection for Critical Data Threats

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing storage systems face challenges in efficiently identifying and protecting sensitive or critical data across multiple storage islands, leading to inefficiencies and increased risk from cyber threats due to the dynamic and unstructured nature of data generation and lack of effective classification mechanisms.

Innovation Solution

Implementing a method that uses deep packet inspection and machine learning techniques to extract metadata, classify data based on security types, and prioritize threat detection and response using a Security Information and Event Management (SIEM) system, enabling proactive protection measures such as encryption and immutability for critical data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep packet inspection is performed on all data to extract metadata for security classification, then security threat detection accuracy is improved, but processing time and computational resources increase significantly

Engineering Contradiction:
Improvesecurity threat detection accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial action by performing deep packet inspection selectively rather than on all data. The system extracts metadata from file requests and performs classification only on data that exhibits suspicious characteristics or matches known threat patterns, rather than inspecting every byte of all stored data. This reduces processing time while maintaining detection accuracy for actual threats.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent segments the security inspection process into multiple stages: initial metadata extraction from file requests, preliminary classification based on extracted metadata, and then deeper inspection only for data flagged as potentially sensitive or critical. This segmented approach divides the large task of comprehensive security scanning into manageable portions, reducing overall processing time while maintaining thorough security coverage.

Inventive Principle:
Principle #1Segmentation

2Reliability

If comprehensive metadata extraction and classification is performed on all stored data, then security coverage is improved, but computational resources and processing overhead increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs comprehensive metadata extraction and classification only for data that exhibits characteristics of sensitivity or criticality, rather than processing all stored data uniformly. By applying security analysis selectively to relevant data portions, the system maintains broad security coverage while significantly reducing computational resource consumption compared to universal processing.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements local quality by applying different levels of inspection intensity to different data portions. High-security inspection is applied locally to identified sensitive or critical data, while standard or minimal inspection is applied to other data. This localized approach ensures comprehensive security coverage for important data while conserving computational resources on less critical data.

Inventive Principle:
Principle #3Local quality

3Speed

If real-time security classification is implemented for all incoming data, then threat response time is improved, but system performance and data throughput decrease

Engineering Contradiction:
Improvethreat response timeVSAvoiddata throughput
Core Design Contradiction:
SpeedVSProductivity

Solution Approach 1:

The system implements real-time security classification partially, focusing computational efforts on data that shows signs of being sensitive or critical based on initial metadata extraction. By applying intensive classification only to relevant data portions rather than all incoming data, the system maintains fast threat response times for actual security concerns while preserving overall data throughput and system performance.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent applies skipping by rapidly processing and classifying data that clearly exhibits security concerns, while giving less intensive processing to data that appears benign. Suspicious data is rushed through accelerated classification paths to enable rapid threat response, while normal data flows through standard processing channels, maintaining overall system throughput while ensuring fast response to actual threats.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS12438895B2Detecting security threats to data on a storage controller
Publication Date: 2025.10.07 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12438895B2 patent drawing
  • US12438895B2 patent drawing

AI summary

Storage network with controller that includes using deep packet inspection to determine whether a computer file or computer object is sensitive and/or critical, and then, if it is sensitive or critical, applying an artificial intelligence algorithm to determine whether there is a potential threat that is represented by the file or object. If there is a potential threat, then a cyber-resiliency workflow is performed to eliminate or at least mitigate the potential threat.