Storage Intrusion Detection via Point-in-Time Copy Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional intrusion detection systems for computer storage systems are ineffective in large storage environments, as they require time-consuming and costly signature calculations, are not suitable for file systems where file locations can change, and lack periodic point-in-time copies for recent data recovery.

Innovation Solution

A method and system that create time and space efficient point-in-time copies of logical units, allowing for periodic monitoring of these copies to detect unwanted modifications, independent of the host system, ensuring continuous access to original data without interruption and maintaining a recent 'good' copy for recovery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional intrusion detection methods are used in large storage environments, then intrusion detection capability is provided, but the system becomes time-consuming and costly due to signature calculations

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidtime-consuming signature calculations
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the storage system into multiple storage units and divides the monitoring task accordingly. Each storage unit independently monitors its own data changes, eliminating the need for centralized signature calculations across the entire storage system. This segmentation reduces computational overhead and time consumption while maintaining comprehensive intrusion detection coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by continuously maintaining point-in-time copies of data before potential intrusions occur. These copies are prepared in advance and can be quickly compared against current data to detect intrusions, eliminating the need for time-consuming post-intrusion analysis or recalibration of detection parameters.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If conventional intrusion detection systems are deployed, then intrusion monitoring is enabled, but periodic point-in-time copies are not maintained for recent data recovery

Engineering Contradiction:
Improveintrusion monitoring capabilityVSAvoidlack of recent data recovery capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system proactively creates and maintains point-in-time copies of data at regular intervals before intrusions occur. These preliminary copies are stored and maintained as part of the normal operation, ensuring that recent data states are always available for recovery purposes without needing to wait for or respond to an intrusion event first.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements beforehand cushioning by maintaining multiple historical point-in-time copies of data as a protective buffer against potential intrusions. These cushioning copies serve as safety nets that can restore data to any previous state, providing a buffer against information loss while requiring minimal additional storage overhead through efficient copy management.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Measurement precision

If frequent copies are made for intrusion detection, then detection accuracy improves, but storage space and time overhead increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidstorage space overhead
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent segments the data storage and monitoring into discrete storage units, each managing its own point-in-time copies independently. This segmentation allows the system to maintain copies at an optimal frequency for each unit without unnecessarily duplicating copies across the entire system, reducing overall storage overhead while maintaining detection accuracy at the granular level where it matters most.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements a lifecycle management strategy for point-in-time copies, discarding older copies that are no longer needed for detection purposes and recovering or retaining only those copies necessary for current monitoring needs. This dynamic management of copy retention reduces storage space overhead while maintaining sufficient detection accuracy by keeping relevant historical data available.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS9928384B2Method and system for storage-based instrusion detection and recovery
Publication Date: 2018.03.27 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9928384B2 patent drawing
  • US9928384B2 patent drawing
  • US9928384B2 patent drawing

AI summary

A method (and system) for detecting intrusions to stored data includes creating a point-time-copy of a logical unit, and comparing at least a portion of the point-time-copy with a previous copy of the logical unit. The method (and system) monitors access to a data storage system and detects an intrusion or any other intentional or unintentional, unwanted modification to data stored in the data storage system. The method (and system) also recovers data once an intrusion or other unwanted modification is detected.