Storage Controller Deep Packet Inspection for Critical Data Threats
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing storage systems face challenges in efficiently identifying and protecting sensitive or critical data across multiple storage islands, leading to inefficiencies and increased risk from cyber threats due to the dynamic and unstructured nature of data generation and lack of effective classification mechanisms.
Innovation Solution
Implementing a method that uses deep packet inspection and machine learning techniques to extract metadata, classify data based on security types, and prioritize threat detection and response using a Security Information and Event Management (SIEM) system, enabling proactive protection measures such as encryption and immutability for critical data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deep packet inspection is performed on all data to extract metadata for security classification, then security threat detection accuracy is improved, but processing time and computational resources increase significantly
Solution Approach 1:
The patent applies partial action by performing deep packet inspection selectively rather than on all data. The system extracts metadata from file requests and performs classification only on data that exhibits suspicious characteristics or matches known threat patterns, rather than inspecting every byte of all stored data. This reduces processing time while maintaining detection accuracy for actual threats.
Solution Approach 2:
The patent segments the security inspection process into multiple stages: initial metadata extraction from file requests, preliminary classification based on extracted metadata, and then deeper inspection only for data flagged as potentially sensitive or critical. This segmented approach divides the large task of comprehensive security scanning into manageable portions, reducing overall processing time while maintaining thorough security coverage.
2Reliability
If comprehensive metadata extraction and classification is performed on all stored data, then security coverage is improved, but computational resources and processing overhead increase
Solution Approach 1:
The system performs comprehensive metadata extraction and classification only for data that exhibits characteristics of sensitivity or criticality, rather than processing all stored data uniformly. By applying security analysis selectively to relevant data portions, the system maintains broad security coverage while significantly reducing computational resource consumption compared to universal processing.
Solution Approach 2:
The patent implements local quality by applying different levels of inspection intensity to different data portions. High-security inspection is applied locally to identified sensitive or critical data, while standard or minimal inspection is applied to other data. This localized approach ensures comprehensive security coverage for important data while conserving computational resources on less critical data.
3Speed
If real-time security classification is implemented for all incoming data, then threat response time is improved, but system performance and data throughput decrease
Solution Approach 1:
The system implements real-time security classification partially, focusing computational efforts on data that shows signs of being sensitive or critical based on initial metadata extraction. By applying intensive classification only to relevant data portions rather than all incoming data, the system maintains fast threat response times for actual security concerns while preserving overall data throughput and system performance.
Solution Approach 2:
The patent applies skipping by rapidly processing and classifying data that clearly exhibits security concerns, while giving less intensive processing to data that appears benign. Suspicious data is rushed through accelerated classification paths to enable rapid threat response, while normal data flows through standard processing channels, maintaining overall system throughput while ensuring fast response to actual threats.
Data Source
AI summary
Storage network with controller that includes using deep packet inspection to determine whether a computer file or computer object is sensitive and/or critical, and then, if it is sensitive or critical, applying an artificial intelligence algorithm to determine whether there is a potential threat that is represented by the file or object. If there is a potential threat, then a cyber-resiliency workflow is performed to eliminate or at least mitigate the potential threat.

